L3 SOC Analyst / Incident Responder (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
L3 SOC Analyst / Incident Responder (Cybersecurity): Leading advanced threat detection and incident response activities with an accent on forensic analysis, threat hunting, and security operations optimization. Focus on mitigating complex security incidents, mentoring junior analysts, and strengthening the overall security posture through proactive threat intelligence and playbook development.
Location: Must be based in Montréal, Canada (Hybrid: 3 days on-site, 2 days remote).
Company
is an international technology consulting firm specializing in cybersecurity, architecture, and digital transformation with a global presence.
What you will do
- Lead incident response efforts including investigation, containment, and recovery.
- Perform in-depth forensic analysis on compromised systems and network traffic.
- Proactively hunt for hidden threats using behavioral analysis and threat intelligence.
- Optimize SIEM rules and develop custom scripts to enhance detection capabilities.
- Mentor junior SOC analysts and share best practices for incident response.
- Prepare detailed post-incident reports and root cause analysis for stakeholders.
Requirements
- 5+ years of experience in a SOC environment with a focus on incident response.
- Expertise in SIEM platforms, IDS/IPS, firewalls, and EDR tools.
- Proficiency in Python or PowerShell for automation.
- Strong understanding of network protocols, malware analysis, and frameworks like MITRE ATT&CK and NIST.
- Excellent problem-solving skills and ability to work under pressure.
- Must be able to work on-site in Montréal 3 days per week.
Culture & Benefits
- Flex Office environment to foster collaboration.
- Annual training and certification opportunities.
- Communities of experts for knowledge sharing.
- Local HR support and project management guidance.
- Opportunities for international mobility and intrapreneurship.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →