WHAT IS THE OPPORTUNITY?
The role of the Security Analyst, Triage is to provide technical security expertise and support for the threat monitoring & triage team within the Global Security Operations Center (GSOC). This is an important role supporting mission critical enterprise networks and IT services protection for RBC and its subsidiaries, including but not exclusive to City National Bank - CNB. This role will provide technical expertise and analysis to the proactive and reactive responses to information security threats against RBC’s global environment. The successful candidate will be performing first line investigation and response actions, including the triaging of security detections and escalation of security incidents. The Security Analyst, Triage will also maintain awareness of emerging/advanced threats and assist in driving efficient security solutions to address the evolving threat landscape. This role partners with RBC Global Security to further the organization's Intelligence-led Security and Resilient Services objectives.
WHAT WILL YOU DO?
- Global accountability to respond to critical security incidents/events providing accurate and timely reporting to GSOC and Global Security leadership.
- Provide support for high risk security incidents escalated from Managed Security Services (MSS), GSOC peers, Global Security and other lines of business.
- Perform investigation and triage activities of security related events that are deemed high risk or pose a significant threat to the organization.
- Detailed technical research and analysis of relevant security events, often complex in design and their potential impact to the organization.
- Escalation of threats against the organization to management and Incident Response team as required based on severity level of threats.
- Develop, distribute and present technical findings with regards to threats, attack vectors and mitigation techniques including the creation and tracking of security metrics.
- Proactive searching activities to look for unknown threats and suspicious behavior within the environment.
- Collaborate with partner groups for tuning of monitoring rules and automation of security tasks to keep GSOC's monitoring capabilities relevant and up to date with a minimal level of false positives.
WHAT DO YOU NEED TO SUCCEED?
Must have:
- Experience in performing investigation and triage activities of security related events
- Experience in all aspects of Security Operations Center and how the organization supports/adds value to the rest of the organization
- Strong platform knowledge including Microsoft Windows and Unix/Linux Operating Systems and scripting languages (bash, python, regex, PowerShell, etc..)
- Thorough understanding of SIEM technology and security related controls(IDS/IPS, WAF, NDR/EDR, etc..)
- Experience with SOAR product
- Knowledge of cybersecurity frameworks (Cyber Kill Chain, NIST, MITRE ATT&CK, etc..)
- Availability for rotating pager duty support for after hours, holidays
Nice-to-have:
- Experience with malware analysis
- Strong Networking knowledge with TCP/IP packet level knowledge
- Bachelor’s degree in Computer Science or related field
- Industry recognized certifications (ISC2, SANS, ISACA, etc..)
What’s in it for you?
We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.
- A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
- Leaders who support your development through coaching and managing opportunities
- Ability to make a difference and lasting impact
- Work in a dynamic, collaborative, progressive, and high-performing team
- A world-class training program in financial services
- Flexible work/life balance options
- Opportunities to do challenging work
#LI-HYBRID
#LI-POST
Job Skills
Confidentiality, Cyber Security Management, Decision Making, Detail-Oriented, Encryption Software, Group Problem Solving, High Impact Communication, Information Security Management, Information Technology Security
Additional Job Details
745 THURLOW ST:VANCOUVER
Vancouver
Canada
37.5
Full time
TECHNOLOGY AND OPERATIONS
Regular
Salaried
2026-04-14
2026-04-30
Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date above
Our Employment Opportunities
At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.
Join our Talent Community
Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.
Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at jobs.rbc.com.
RBC is presently inviting candidates to apply for this existing vacancy. Applying to this posting allows you to express your interest in this current career opportunity at RBC. Qualified applicants may be contacted to review their resume in more detail.