Назад
Company hidden
7 дней назад

Senior Analyst – Operations and Assurance (Cybersecurity)

105 000 - 115 000CAD
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Analyst – Operations and Assurance (Cybersecurity) (Zscaler/Microsoft Security): Investigating and resolving complex security alerts and incidents while administering enterprise security platforms, identity controls, vulnerability management, email security, and AI-security controls with an accent on incident response, security operations, and risk-based remediation. Focus on coordinating containment, securing AI applications, managing critical vulnerabilities, and maintaining security controls across a complex enterprise environment.

Location: hirify.global Place, 181 Bay Street, Toronto, Ontario, Canada

Salary: C$105K–C$115K per year

Company

hirify.global’s Technology Services organization delivers enterprise infrastructure, applications, and end-user technology services across its business groups.

What you will do

  • Investigate and resolve security alerts and incidents from Microsoft Sentinel, Microsoft Defender XDR, endpoint tools, and other monitoring platforms.
  • Administer Zscaler Internet Access, Zscaler Private Access, Client Connector, Microsoft security platforms, email-security controls, identity controls, and access-management configurations.
  • Operate the vulnerability-management lifecycle, including validation, risk-based prioritization, remediation coordination, exception management, escalation, and reporting.
  • Review AI applications and use cases for security, privacy, identity, data-protection, retention, third-party, and shadow-AI risks.
  • Lead phishing simulations and security-awareness activities, and execute legal hold and eDiscovery requests using Microsoft Purview.
  • Conduct third-party risk assessments, maintain operational documentation and dashboards, and participate in a scheduled after-hours security on-call rotation.

Requirements

  • At least five years of progressive experience in information security, security operations, incident response, or a related discipline.
  • Hands-on experience investigating alerts, managing incidents through ServiceNow or an equivalent platform, and working within formal escalation and on-call procedures.
  • Experience with Zscaler, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Exchange Online security controls, or comparable technologies.
  • Knowledge of vulnerability management, email-security controls, SPF, DKIM, DMARC, identity controls, access reviews, and security awareness.
  • Working knowledge of AI-security risks, generative AI, shadow-AI monitoring, data protection, and secure AI-enabled security capabilities.
  • Strong analytical, documentation, communication, independent-working, and cross-functional coordination skills.

Nice to have

  • Experience with vulnerability platforms such as Microsoft Defender Vulnerability Management, Tenable, Qualys, or Rapid7.
  • Experience with cloud-security monitoring across Microsoft Azure, Amazon Web Services, or comparable environments.
  • Knowledge of SOX, IT general controls, evidence-based control testing, or the NIST AI Risk Management Framework.
  • PowerShell, Python, API, or workflow-automation experience.
  • Security+, SC-200, AZ-500, CISSP, GCIH, or equivalent certification; post-secondary education in cybersecurity, IT, computer science, or a related field.

Culture & Benefits

  • Full-time employment within a collaborative, entrepreneurial, and disciplined environment.
  • Challenging assignments and exposure to diverse business groups.
  • Participation in a scheduled after-hours on-call rotation for significant incidents and critical vulnerabilities.
  • Commitment to a safe, respectful, inclusive, and accessible workplace.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →