Sibylline is a leading intelligence and strategic risk consultancy in the security sector. Since 2010 we have supported businesses, governments and NGOs through the provision of high-quality risk analysis, due diligence and consultancy services.
The firm provides an innovative, entrepreneurial and fast-growing working environment, offering employees ever greater exposure to high profile clients and challenges. Sibylline offers fantastic opportunities for career progression within a successful company, and we aim to help our employees to build their own personal profiles as well-regarded analysts within the broader industry.
Key attributes of Sibylline employees are:
Expected Compensation: C$65,000 – C$85,000 per year
Location: Onsite, Toronto, ON
PTO: 20 days per annum
Sick: 5 paid days per annum
Vacancy Status: Existing Vacancy
This role will close for applications at 0900 EDT on Monday 14 September 2026.
We are looking for a GSOC Junior Intelligence Analyst to join a newly established 24/7 Global Security Operations Centre (GSOC) for a multinational e-commerce client. This role will focus on continuous monitoring of incidents, alerts, and systems, triage and escalation, and incident response. You will also support horizon scanning to monitor geopolitical and security events that may impact the client’s employees, assets, reputation, and operations, producing timely and actionable intelligence briefings to inform decision making where required.
You will act as a central point for escalation, coordination, and communication during times of crisis, and you will engage with various business functions, ensuring a holistic approach to addressing their needs, expectations, and concerns. The GSOC team will have some onsite physical security responsibilities, including alarm and CCTV monitoring, and access control.
This role would require you to work 5x8-hour shifts, rotating early, late and nights to cover 24/7 including weekends with flexibility to cover gaps where required. The role is fully onsite at the client’s Toronto office.
Essential Functions / Responsibilities
Continuous monitoring of incidents, alerts, and systems
Act as central point for initial triage, verification, and classification of events
Communicate, escalate, and coordinate incidents with relevant stakeholders as per established Standard Operating Procedures (SOPs)
Adhere strongly to GSOC SOPs, and execute response playbooks and escalation protocols
Complete incident logging and real-time documentation
Horizon scan for geopolitical, security, reputational, and operational risks that may impact the client
Conduct open-source intelligence (OSINT) collection and analysis to identify early warning indicators and proactively warn of threats to the client’s operations
Support incident response through production of intelligence products, threat assessments and impact analysis
Produce timely and actional intelligence reports and briefings where required
Provide monitoring and management of security operations, including CCTV feeds, access control and door alarms
Other duties as assigned
Knowledge, Skills, and Abilities
Experience, knowledge, and interest in current affairs, international relations, and emerging security threats
Excellent written and spoken communication with a high attention to detail
Experience in utilising OSINT and social media intelligence (SOCMINT) platforms, tools, and methodologies
Ability to absorb and analyse large amounts of data to summarise events accurately and concisely
Ability to work independently and as part of a collaborative team
Ability to prioritise and manage multiple scheduled tasks, requests, and sources of information in an organised way
Eagerness to learn and support all aspects of GSOC operations, including following SOPs related to physical and asset security, securing access points and alarm response
At least 1+ years of experience working in a corporate setting or similar public or private sector environments
Fluent written and spoken English
Preferred experience with GSOC tools, including threat monitoring, OSINT, and SOCMINT platforms
Preferred Undergraduate or Postgraduate qualifications in International Security, Intelligence, Risk, Geopolitics or other related disciplines, or equivalent professional experience
Work Environment/Physical Requirements
This position is moderately self-directed and requires understanding and compliance with company policies, procedures, and values. While performing the duties of this job, the employee is regularly required to interact collaboratively with the team and stakeholders, and communicate via phone, videophone, or text messaging. The position may require travel up to 5%.
Interview Process
Artificial Intelligence: Not used in candidate screening
Research indicates that certain groups are less likely to apply for a position unless they meet every single requirement. If you feel you meet some of the requirements and can offer a unique perspective to this role, we strongly encourage you to apply—you might be the perfect fit we're looking for!
Sibylline is committed to the recruitment and selection of candidates without regard for sexual orientation, gender, ethnicity, age, political beliefs, culture, and lifestyle. We are committed to fostering a business culture that reflects these values and promotes equal opportunity.

Sibylline is the world’s leading private consultancy for geopolitical risk, intelligence, and strategic insight, dedicated to helping leaders and organisations anticipate change, manage risk, and build resilience.
Since 2010 we have supported businesses, governments and NGOs through the provision of high quality risk analysis and due diligence services. We do not believe in one-size-fits-all solutions. Instead, our global source network, professional intelligence analysis processes and specialist expertise allows us to produce high-quality, insightful work that has direct relevance to our clients’ business.
We strive to offer clients actionable assessments that go beyond the obvious and offer implications of geopolitical events in the regions they operate.
Our flagship product, the World Risk Register, provides both written and quantifiable analysis on world events, by region. Our proprietary software gives clients the ability to gain any level numerical data on world-wide locations as needed, in tandem with an overall rating system and backed up by written analysis with predictions of how events will unfold and impact business.
Our services and experience include fully-run in-house GSOCs, virtual GSOCs, embedded analysts, consultation and training for existing security operations with insight for improvement, project work, regular reporting, social media monitoring and due diligence services.
As subject matter experts, our analysts are frequently called upon for speaking engagements, media interviews and in-house corporate presentations.
We are always looking over the horizon to keep clients’ personnel, sites, assets and supply chains safe.