1 день назад
Senior Security Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Analyst (Cybersecurity): Investigating and responding to complex security incidents across SIEM, EDR/XDR, cloud, identity, network, and endpoint environments with an accent on advanced threat analysis, detection engineering, and SOC mentoring. Focus on correlating security data, applying the MITRE ATT&CK framework, optimizing detection rules, and escalating confirmed incidents to the Security Incident Response Team.
Location: Montreal, Canada; hybrid work with work from home up to 2 days per week
Company
develops technology and communication solutions for airports, airlines, borders, and the global air travel industry.
What you will do
- Act as the primary escalation point for junior SOC analysts and provide expert guidance during investigations.
- Lead complex security incident investigations, validating alert classification, severity, scope, and escalation decisions.
- Perform advanced threat analysis and correlate data across SIEM, EDR/XDR, cloud, identity, network, and endpoint environments.
- Develop and optimize detection rules, correlation logic, SOC use cases, investigation playbooks, and alert tuning activities.
- Identify detection gaps and false-positive trends using the MITRE ATT&CK framework, while mentoring SOC analysts and improving SOC standards.
- Support vulnerability validation, risk prioritization, remediation coordination, reporting, tabletop exercises, and post-incident reviews.
Requirements
- Advanced experience investigating and responding to security events with SIEM and EDR/XDR platforms.
- Strong knowledge of incident investigation, triage, escalation, enterprise security environments, and common cyberattack techniques.
- Experience analyzing logs from endpoints, cloud services, identity platforms, networks, firewalls, proxies, VPNs, and applications.
- Proficiency with KQL, Lucene, EQL, Sigma, and scripting with PowerShell and/or Python.
- Technical knowledge of Windows, Linux, Active Directory, Microsoft 365, Azure/AWS, networking, and the MITRE ATT&CK framework.
- Bachelor’s degree in information technology, cybersecurity, computer science, or a related field, plus 3–5 years of SOC L2 or equivalent security operations experience.
Nice to have
- SC-200, GCIH, GCIA, CySA+, ECIH, or another recognized cybersecurity certification.
Culture & Benefits
- Flex Week: work from home up to 2 days per week, depending on team needs.
- Flex Day: adjust the workday to suit personal plans.
- Flex Location: work from any location in the world for up to 30 days per year.
- Access to a 24/7 employee assistance program and Champion Health platform.
- Professional development through LinkedIn Learning and internal training programs.
- Benefits are designed according to the employee’s country and contract type.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior Security Engineer (AI)
150 000 - 190 000CAD
CrowdStrike
1 день назад
Sr. Analyst, Falcon Complete (Cybersecurity)
125 000 - 200 000CAD
4 дня назад
Senior Security Engineer (AI)
2 дня назад
Cyber Security Analyst
100 000 - 130 000$
2 дня назад
Security Platform Engineer (SIEM)
65 000 - 105 000CAD
2 дня назад
Senior Security Analyst (Cybersecurity)
118 600 - 163 075CAD