Cybersecurity Specialist
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cybersecurity Specialist (SOC): Monitor and triage security alerts from SIEM/XDR tools, investigate incidents with log analysis and basic forensics, and coordinate containment and remediation with an accent on Microsoft security tooling and SOC operations. Focus on optimizing detection and response through playbooks, automation, threat hunting, and continuous improvements while maintaining accurate incident tracking and reporting.
Location: Montreal, QC (Hybrid)
Company
is a game and software company operating a Security Operations Centre (SOC).
What you will do
- Monitor and triage security alerts from SIEM/XDR tools, ensuring correct prioritization, documentation, and escalation.
- Investigate security incidents using log analysis, event correlation, and basic forensics; coordinate containment and remediation.
- Run SOC operations including ticketing, incident tracking, reporting, and lessons learned.
- Analyze phishing and suspicious activity and communicate directly with users when needed.
- Maintain and optimize security tools (Microsoft Defender, Sentinel, Intune), including configurations and log ingestion.
- Improve SOC capabilities via detection rules, playbooks, threat hunting, automation, performance metrics, audits, and collaboration.
Requirements
- Degree/diploma in cybersecurity or computer science, or equivalent experience, with at least 2 years in IT/security.
- Hands-on experience with SIEM (preferably Microsoft Sentinel) and EDR/XDR tools.
- Strong understanding of networking, Windows/Linux systems, and identity/access (Entra ID) plus core security principles.
- Knowledge of scripting (Python, PowerShell, KQL) and cloud environments (Azure/AWS).
- Familiarity with security frameworks (MITRE ATT&CK, NIST), log analysis, and SOAR concepts (asset).
- Relevant certifications (e.g., Security+, SC-200, AZ-500) and flexibility for shifts or extended hours.
Culture & Benefits
- Hybrid workplace based in Montreal, QC.
- Shift flexibility and extended-hours readiness for SOC coverage.
- Collaboration across cybersecurity, IT, and production teams to keep defenses and response times strong.
- Continuous improvement focus through automation, detection tuning, and SOC performance metrics.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →