Talent.com
Tech Talent International
Cybersecurity - Operations and Threat Detection AnalystTech Talent International • Montréal, QC, Canada
No longer accepting applications
Cybersecurity - Operations and Threat Detection Analyst

Cybersecurity - Operations and Threat Detection Analyst

Tech Talent International • Montréal, QC, Canada
30+ days ago
Job type
  • Full-time
  • Permanent
  • Quick Apply
Job description

Tech Talent International (SI) supplies technical talent to a variety of clients ranging from Fortune 100/500/1000 companies to small and mid-sized organizations in Canada/US and Europe.

We currently have a role as a Cybersecurity - Operations and Threat Detection Analyst with our large consulting client on a long term project with a major financial services client in the downtown Montreal area.

This role can either be a fulltime, perm role or a long term C2C contract.

Role: Cybersecurity - Operations and Threat Detection Analyst

Type: Permanent or Contract 40 hrs/week

Location: Hybrid - Downtown Montreal, QC -(roles starts off 5 days in office for 1st 3 months, then turns into hybrid setup 3 days onsite, 2 days from home)

Salary: $110,000 - $120,000 + 9% bonus + 3-5 weeks paid vacation + RRSP contribution + benefits + sick/personal days

Contract Rate Option: $100 - $105/hr C2C

Position Overview


The Production CSIRT Purple Team Expert position will provide security expertise to the 24x7 Security

Operation Center (SOC). The primary purpose of this position is to develop, implement and assist on the continuous evolution of security use cases and correlation rules which assist on detecting, preventing, and responding to cyber threats against our group's infrastructure. It provides critical support to the firm - wide cybersecurity program via partnerships in the region with our peer s globally and within our diverse lines of business as well as externally with client s, partners and regulators.

As a Production Security Purple Team Expert , you are not only responsible for the continuous use case and correlation rule development and enhancement but also expected to participate in Threat Hunting and participate in cybersecurity investigations which will enhance the 24x7 Security Opera tion Center (SOC) capabilities as the first line of defense to identify potential information security incidents.

MAIN RESPONSIBILITIES

Responsibilities include but are not limited to:

  • Provide analysis and trending of security log data from many heterogeneous security devices
  • Responsible for use - case development and validation
  • Develop threat hunting program and capabilities
  • Investigate, document and report on information security issues and emerging trends
  • Perform threat hunting to identify potential adversaries within the network as well as participate in exercises with the AMER Purple Team to detect and remediate any potential gaps or use case
    defects.
  • Provide support and /or research any security related questions or incidents.
  • Perform tasks independently with some oversight
  • Integrate and share information with other analysts and other teams.
  • Follow incident - specific procedures to perform triage of potential security incidents to validate and
    determine needed mitigation and maintain said procedures up to date.
  • Escalate potential security incidents to Level IV engineers, implements countermeasures in response
    to others, and recommend operational improvements
  • Maintaining awareness of the bank's technology architecture, known weaknesses, the architecture
    of the security solutions used for monitoring, imminent and pervasive threats as identified by client
    threat intelligence, and recent security incidents
  • Continuously improve the service by identifying and correcting issues or gaps in knowledge (analysis
    procedures, plays, client network models), false positive tuning, identifying, and recommending new or updated use cases , content, countermeasures, scripts.

Classification : Internal

  • Serve as a subject matter expert in at least one security - related area ( e.g., specific malware solution, python programming, etc.)
  • Actively seek self - improvement through continuous learning and pursuing advancement to a Level IV Analyst
  • Adhere to internal operational security and other client policies
  • Regular interactions with local AMER CSIRT Teams ( CTI, Purple) as well as with EMEA and APAC
    regions.
  • Perform light project work as assigned

REQUIREMENTS
TRAINING AND OCCUPATIONAL EXP ERIENCE

  • Experience in IT Security Incident management at level 3 or multiple years (
  • In- depth technical knowledge of methods used by malware and APTs
  • Extended culture on Cybersecurity
  • Knowledge of security concerning the network infrastructure, UNIX and Windows environments,
    databases, package deployment tools, security tools (USB port control, hard drive encryption)
  • Script writing in shell, Python, Java, PowerShell, Ansible, SQL
  • Knowledge o f 5+ years of experience with the following technologies: SIEM, ELK, IDS/IPS, network -
    and host - based firewalls, data leakage protection (DLP)
  • Direct experience with anti - virus software, endpoint detection response (EDR), firewalls and content
    filtering
  • Experience or demonstrable knowledge in Incident response, log analysis and PCAP analysis
  • Good level of knowledge in network fundamentals, for example, OSI Stack, TCP/IP, DNS, HTTP(S)
  • Experience detecting and tracking and preventing network phishing


SMTP

  • Good level of understanding in the approach threat actors take to attacking a
    port scanning, web application attacks, DDoS, lateral movement
  • Passion to learn and to contribute to the ongoing development of the team
  • Certifications like GCFA, GCIH, OSCP, or similar are good to have


Skills/Behaviors Preferred:

  • Ability to demonstrate the right approach to investigating alerts and/or indicators and document your findings in a manner that both peer and executive level colleagues can understand
  • Appreciation of the wider roles of interconnecting Cyber Security teams and collaboration with each of those ( i.e., Forensics / Threat Intelligence / Penetration Testing / Vulnerability Management / "Purple Teaming" etc.)
  • Ability to handle fluctuating workloads, conflicting
  • Analytical skills
  • Strategic vision
  • Rigor & Accuracy
  • Flexibility
  • Communication skills
  • Collaboration
  • Self - driven
  • Ability to track various priorities and concurrent activities



Create a job alert for this search

Cybersecurity - Operations and Threat Detection Analyst • Montréal, QC, Canada

Similar jobs

Operational Technology Cybersecurity Expert

WSP in Canadamontreal (administrative region), qc, Canada
Full-time

Join as an Operational Technology Cybersecurity Expert, focusing on safeguarding energy systems.Leverage your expertise in cybersecurity to enable safe digital transformation in critical infrastruc... Show more

 • Promoted

Security Operations Analyst at MaintainX

MaintainXMontreal (administrative region), QC, CA
Full-time

Elevate your career at MaintainX as a Security Operations Analyst in a hybrid role based out of Raleigh or Montreal.Drive security initiatives focused on vulnerability management and compliance sup... Show more

 • Promoted

Senior Threat Detection & Response Engineer

1PasswordMontreal (administrative region), QC, CA
Full-time

A leading cybersecurity company in Canada seeks a Senior Security Engineer to enhance threat detection and response capabilities.You will design systems for threat detection, lead incident response... Show more

 • Promoted

Security Engineer

LanceSoft, Inc.montreal, montreal (administrative region), Canada
Full-time

Direct message the job poster from LanceSoft, Inc.Needs local as in-person is Mandate for the role.Privileged Access Management Senior Engineer to support implementation, enterprise rollout and ope... Show more

 • Promoted

CAE Cybersecurity and DevOps Expert

CAEMontreal (administrative region), QC, CA
Full-time

Advance your career at CAE as a Cybersecurity and DevOps Integration Specialist, focusing on dynamic security solutions.Collaborate in a high-performance environment committed to global safety.In t... Show more

 • Promoted

Cybersecurity Analyst Role Focusing on Security Monitoring and Awareness

NOVIPROMontreal (administrative region), QC, CA
Full-time

Exciting opportunity for a Cybersecurity Analyst to join a security-focused team remotely.Play a crucial role in identifying vulnerabilities and enhancing the security framework through best practi... Show more

 • Promoted

Cyber Operations Specialist in Defense

Canadian Armed Forces | Forces armées canadiennesMontreal (administrative region), QC, CA
Full-time

Protect national interests as a Cyber Operator.Conduct critical cyber operations while analyzing vulnerabilities and ensuring secure military communications for various forces.In this impactful rol... Show more

 • Promoted

Security Analyst (SOC)

Bedard ResourcesLaval (administrative region), QC, CA
Full-time

Our client is looking for a Junior Cybersecurity Analyst to assist with the daily management of a simulation platform, support the onboarding of new clients, and contribute to analyses related to a... Show more

 • Promoted

Contract Security Analyst for Cyber Defense

Fluid - Solutions de Talents/Workforce SolutionsMontreal (administrative region), QC, CA
Full-time

Strengthen our cybersecurity initiatives as a Security Analyst.Focus on optimizing threat detection systems, endpoint security configuration, and vulnerability management across critical platforms ... Show more

 • Promoted

cybersecurity analyst

Orange Cyberdefense Canada Inc.Montreal (administrative region), QC, CA
Full-time +1

Salary: 90,000 to 100,000 annually (To be negotiated) / 40 hours per week.Terms of employment: Permanent employment, Full time.Education: College, CEGEP or other non-university certificate or diplo... Show more

 • Promoted

L3 Cybersecurity Analyst at Major Bank

QUANTEAM - North America (RAINBOW PARTNERS Group)Montreal (administrative region), QC, CA
Full-time

Enhance security measures at a leading bank as an L3 Cybersecurity Analyst, facilitated by Quanteam in Montreal.Focus on incident management and advanced malware response strategies.Quanteam is in ... Show more

 • Promoted

Senior Analyst - Security Operations

Cirque du Soleil Entertainment GroupMontreal (administrative region), QC, CA
Permanent

Senior Analyst – Security Operations.Review security events to detect and prevent potential information security incidents.Analyze threats and identify strategies to contain and prevent them.Partic... Show more

 • Promoted

Senior Analyst, Cybersecurity Incident Response

CynergyIQ GroupMontreal (administrative region), QC, CA
Full-time

Lead incident response efforts as a Senior Analyst within a dedicated SOC team, focusing on advanced security tools like Palo Alto CORTEX.Provide top-notch service to enterprise clients.In this key... Show more

 • Promoted

Specialist, Cyber Operations

Air CanadaDorval, QC, CA
Full-time

Being part of Air Canada is to become part of an iconic Canadian symbol, recently ranked the best Airline in North America.Let your career take flight by joining our diverse and vibrant team at the... Show more

 • Promoted

Cybersecurity Analyst - Hybrid Role

Orange Cyberdefense Canada Inc.Montreal (administrative region), QC, CA
Full-time +1

Elevate your career as a Cybersecurity Analyst in a hybrid work environment.This role focuses on safeguarding information systems while collaborating with clients and ensuring robust security measu... Show more

 • Promoted

Security Analyst

Prosperity Workforce SolutionsMontreal (administrative region), QC, CA
Temporary

We are seeking a highly skilled.This temporary position will focus on fine-tuning threat detection models, ensuring best practices in endpoint protection, and improving the utilization of our secur... Show more

 • Promoted

Security Operations Incident Response Analyst

CAE IncMontreal (administrative region), QC, CA
Full-time

Join as a Security Operations Incident Response Analyst focusing on timely incident resolution.Support the security team by analyzing alerts and enhancing incident response capabilities across the ... Show more

 • Promoted

Cybersecurity Analyst Focusing on Threat Detection and Incident Response

Hamilton Barnes Associates LimitedMontreal (administrative region), QC, CA
Full-time

Become a vital part of a cutting-edge cybersecurity team actively detecting threats and responding to incidents.Leverage your expertise to enhance security measures in a hybrid working environment.... Show more

 • Promoted

Analyste principal(e) - Contrôles et indicateurs de cybersécurité | Cybersecurity Controls & Metrics

NTT DATA North Americamontreal (administrative region), qc, Canada
Full-time

NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us.If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.... Show more

 • Promoted

Cyber Defense Engineer: Threat Detection & Response

Yeah! GlobalMontreal (administrative region), QC, CA
Full-time

A dynamic technology company in Montreal is looking for a skilled Cyber Security Engineer to protect their computer systems, networks, and data from cyber threats.The role involves designing and ma... Show more