Назад
Company hidden
1 день назад

Senior Security Analyst (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Analyst (Cybersecurity): Investigating and responding to complex security incidents across SIEM, EDR/XDR, cloud, identity, network, and endpoint environments with an accent on advanced threat analysis, detection engineering, and SOC mentoring. Focus on correlating security data, applying the MITRE ATT&CK framework, optimizing detection rules, and escalating confirmed incidents to the Security Incident Response Team.

Location: Montreal, Canada; hybrid work with work from home up to 2 days per week

Company

hirify.global develops technology and communication solutions for airports, airlines, borders, and the global air travel industry.

What you will do

  • Act as the primary escalation point for junior SOC analysts and provide expert guidance during investigations.
  • Lead complex security incident investigations, validating alert classification, severity, scope, and escalation decisions.
  • Perform advanced threat analysis and correlate data across SIEM, EDR/XDR, cloud, identity, network, and endpoint environments.
  • Develop and optimize detection rules, correlation logic, SOC use cases, investigation playbooks, and alert tuning activities.
  • Identify detection gaps and false-positive trends using the MITRE ATT&CK framework, while mentoring SOC analysts and improving SOC standards.
  • Support vulnerability validation, risk prioritization, remediation coordination, reporting, tabletop exercises, and post-incident reviews.

Requirements

  • Advanced experience investigating and responding to security events with SIEM and EDR/XDR platforms.
  • Strong knowledge of incident investigation, triage, escalation, enterprise security environments, and common cyberattack techniques.
  • Experience analyzing logs from endpoints, cloud services, identity platforms, networks, firewalls, proxies, VPNs, and applications.
  • Proficiency with KQL, Lucene, EQL, Sigma, and scripting with PowerShell and/or Python.
  • Technical knowledge of Windows, Linux, Active Directory, Microsoft 365, Azure/AWS, networking, and the MITRE ATT&CK framework.
  • Bachelor’s degree in information technology, cybersecurity, computer science, or a related field, plus 3–5 years of SOC L2 or equivalent security operations experience.

Nice to have

  • SC-200, GCIH, GCIA, CySA+, ECIH, or another recognized cybersecurity certification.

Culture & Benefits

  • Flex Week: work from home up to 2 days per week, depending on team needs.
  • Flex Day: adjust the workday to suit personal plans.
  • Flex Location: work from any location in the world for up to 30 days per year.
  • Access to a 24/7 employee assistance program and Champion Health platform.
  • Professional development through LinkedIn Learning and internal training programs.
  • Benefits are designed according to the employee’s country and contract type.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →