Cyber Incident Response Consultant (On-Call Advisory – Supplemental Employment)
7806952438

Remote
•10 hours ago
•No application
About
Cyber Incident Response Consultant (Supplemental, On-Call Advisory)
Location: Remote – Anywhere in Canada
Compensation: Up to $70/hour
Type: Supplemental / Secondary Employment – On-Call Advisory (Keep Your Full-Time Job)
Client: A leading Canadian professional services firm
A Flexible, Supplemental Cyber Role You Can Add to Your Current Job
We are partnering with a leading Canadian professional services firm to build an elite on-call Cyber Incident Response advisory roster.
This is supplemental employment — perfect for seasoned incident response professionals who want extra paid work without leaving their current job.
You remain in your full-time or contract role.
You only work when an incident occurs and only if you are available.
What Makes This Role Unique
- Fully on-call, ad hoc, event-driven
- Zero conflict with your current full-time role
- No guaranteed hours — work happens only when major incidents occur
- Minimum 20 hours/month availability outside business hours
- 100% remote anywhere in Canada
- Paid up to $70/hour depending on experience & engagement type
This is advisory-focused crisis work, not operational SOC work.
What You’ll Do (High-Level Overview)
As part of the on-call roster, you may be activated during high-severity cyber events such as:
- Ransomware attacks
- Business email compromise
- Data breaches
- Network intrusions
- Cloud security events
- Fraud or high-impact cyber investigations
Your role will be to advise and support clients during the most critical phases of an incident:
- Provide Incident Commander–level triage and leadership
- Guide clients on containment, remediation, and recovery
- Analyze and interpret findings using CrowdStrike Falcon (mandatory)
- Collaborate with the firm’s IR & DFIR teams during live events
- Communicate with senior leadership and help them navigate decisions in real time
This is crisis consulting — short-duration, high-intensity advisory work on an as-needed basis.
What You Must Bring (Non-Negotiable)
We are looking for candidates who have:
- Recent (within 12 months) hands-on incident response experience
- Multiple ransomware investigations under their belt
- Mandatory CrowdStrike Falcon expertise in real-world IR contexts
- Experience as an Incident Commander / IR Lead
- Strong communication skills under pressure
- Experience advising enterprise organizations in Canada
- Ability to work nights, weekends, and short notice during major incidents
- Legal right to work in Canada, located anywhere nationally
Not a fit:
General security analysts, SOC-only backgrounds, or offshore-outsourcing profiles.
Nice-to-Have Skills
- DFIR tools: Magnet, EnCase, FTK, Velociraptor, X-Ways
- Other EDRs: SentinelOne, Defender for Endpoint, Carbon Black
- SIEM experience: Sentinel, Splunk, ELK, ArcSight
- Experience with cloud IR (Azure, AWS, GCP)
- IR certifications (GCFA, GCIH, GCFE, GREM, EnCE, etc.)
- Prior consulting experience
Who Thrives in This Role
This supplemental advisory role is ideal for:
- Senior IR/DFIR professionals wanting additional consulting income
- Cybersecurity leaders with flexible schedules
- Incident Commanders who excel during high-severity crisis events
- Professionals who want exposure to a top-tier Canadian consulting environment
Availability & Engagement Model
- This is supplemental, on-call, advisory-only work
- You keep your existing full-time/contract position
- Minimum 20 hours/month availability outside business hours
- Activation depends entirely on incident volume
- Initial contract: 6 months, strong likelihood of extension
How to Apply
Please send:
- Your resume with clear IR experience
- A short overview of:
- Recent ransomware and Falcon experience
- Your current job & your supplemental availability
- Your desired hourly rate (up to $70/hr)
- Confirmation you are open to on-call, supplemental advisory work
Candidates who have held roles in the folllowing areas may be a good fit! Cyber Incident Response Consultant, Incident Commander, Ransomware Response, CrowdStrike Falcon, DFIR Consultant, Cybersecurity Consultant, On-Call Cyber Response, Supplemental Cyber Work, Remote Cyber Jobs Canada, Cybersecurity Advisor, Digital Forensics, Incident Response Canada, After-Hours Cybersecurity, High-Severity Incident Response, Ransomware Recovery Specialist, Canadian Cyber Consulting, IR Lead, Senior Incident Responder, Cyber Crisis Advisor.
Job Types: Casual, Freelance
Pay: $70.00 per hour
Application question(s):
- Are you willing and able to complete a full background check (criminal, identity, employment verification)?
- Have you ever failed, been denied, or withdrawn from a background check process?
- Can you pass a criminal record check with no convictions that would prevent you from working in cyber incident response?
- Are you willing to complete a credit check if required for client onboarding? AND Do you have no outstanding legal or financial issues that would prevent onboarding with a professional services firm?
- Are you able to sign strict NDAs and confidentiality agreements required for accessing sensitive client incident data?
- Are you able to work in an environment requiring secure handling of client data (e.g., encrypted devices, controlled workspace)?
- Do you have active Incident Response experience within the last 12 months?
- Have you led or participated in multiple real ransomware investigations (not tabletop exercises)?
- Do you have experience supporting enterprise-level organizations within Canada?
- Can you reliably provide at least 20 hours per month of after-hours and weekend availability for on-call work?
Work Location: Remote




