Talent.com
Tech Talent International
Cybersecurity - Operations and Threat Detection AnalystTech Talent International • Montréal, QC, Canada
No longer accepting applications
Cybersecurity - Operations and Threat Detection Analyst

Cybersecurity - Operations and Threat Detection Analyst

Tech Talent International • Montréal, QC, Canada
30+ days ago
Job type
  • Full-time
  • Permanent
  • Quick Apply
Job description

Tech Talent International (SI) supplies technical talent to a variety of clients ranging from Fortune 100/500/1000 companies to small and mid-sized organizations in Canada/US and Europe.

We currently have a role as a Cybersecurity - Operations and Threat Detection Analyst with our large consulting client on a long term project with a major financial services client in the downtown Montreal area.

This role can either be a fulltime, perm role or a long term C2C contract.

Role: Cybersecurity - Operations and Threat Detection Analyst

Type: Permanent or Contract 40 hrs/week

Location: Hybrid - Downtown Montreal, QC -(roles starts off 5 days in office for 1st 3 months, then turns into hybrid setup 3 days onsite, 2 days from home)

Salary: $110,000 - $120,000 + 9% bonus + 3-5 weeks paid vacation + RRSP contribution + benefits + sick/personal days

Contract Rate Option: $100 - $105/hr C2C

Position Overview


The Production CSIRT Purple Team Expert position will provide security expertise to the 24x7 Security

Operation Center (SOC). The primary purpose of this position is to develop, implement and assist on the continuous evolution of security use cases and correlation rules which assist on detecting, preventing, and responding to cyber threats against our group's infrastructure. It provides critical support to the firm - wide cybersecurity program via partnerships in the region with our peer s globally and within our diverse lines of business as well as externally with client s, partners and regulators.

As a Production Security Purple Team Expert , you are not only responsible for the continuous use case and correlation rule development and enhancement but also expected to participate in Threat Hunting and participate in cybersecurity investigations which will enhance the 24x7 Security Opera tion Center (SOC) capabilities as the first line of defense to identify potential information security incidents.

MAIN RESPONSIBILITIES

Responsibilities include but are not limited to:

  • Provide analysis and trending of security log data from many heterogeneous security devices
  • Responsible for use - case development and validation
  • Develop threat hunting program and capabilities
  • Investigate, document and report on information security issues and emerging trends
  • Perform threat hunting to identify potential adversaries within the network as well as participate in exercises with the AMER Purple Team to detect and remediate any potential gaps or use case
    defects.
  • Provide support and /or research any security related questions or incidents.
  • Perform tasks independently with some oversight
  • Integrate and share information with other analysts and other teams.
  • Follow incident - specific procedures to perform triage of potential security incidents to validate and
    determine needed mitigation and maintain said procedures up to date.
  • Escalate potential security incidents to Level IV engineers, implements countermeasures in response
    to others, and recommend operational improvements
  • Maintaining awareness of the bank's technology architecture, known weaknesses, the architecture
    of the security solutions used for monitoring, imminent and pervasive threats as identified by client
    threat intelligence, and recent security incidents
  • Continuously improve the service by identifying and correcting issues or gaps in knowledge (analysis
    procedures, plays, client network models), false positive tuning, identifying, and recommending new or updated use cases , content, countermeasures, scripts.

Classification : Internal

  • Serve as a subject matter expert in at least one security - related area ( e.g., specific malware solution, python programming, etc.)
  • Actively seek self - improvement through continuous learning and pursuing advancement to a Level IV Analyst
  • Adhere to internal operational security and other client policies
  • Regular interactions with local AMER CSIRT Teams ( CTI, Purple) as well as with EMEA and APAC
    regions.
  • Perform light project work as assigned

REQUIREMENTS
TRAINING AND OCCUPATIONAL EXP ERIENCE

  • Experience in IT Security Incident management at level 3 or multiple years (
  • In- depth technical knowledge of methods used by malware and APTs
  • Extended culture on Cybersecurity
  • Knowledge of security concerning the network infrastructure, UNIX and Windows environments,
    databases, package deployment tools, security tools (USB port control, hard drive encryption)
  • Script writing in shell, Python, Java, PowerShell, Ansible, SQL
  • Knowledge o f 5+ years of experience with the following technologies: SIEM, ELK, IDS/IPS, network -
    and host - based firewalls, data leakage protection (DLP)
  • Direct experience with anti - virus software, endpoint detection response (EDR), firewalls and content
    filtering
  • Experience or demonstrable knowledge in Incident response, log analysis and PCAP analysis
  • Good level of knowledge in network fundamentals, for example, OSI Stack, TCP/IP, DNS, HTTP(S)
  • Experience detecting and tracking and preventing network phishing


SMTP

  • Good level of understanding in the approach threat actors take to attacking a
    port scanning, web application attacks, DDoS, lateral movement
  • Passion to learn and to contribute to the ongoing development of the team
  • Certifications like GCFA, GCIH, OSCP, or similar are good to have


Skills/Behaviors Preferred:

  • Ability to demonstrate the right approach to investigating alerts and/or indicators and document your findings in a manner that both peer and executive level colleagues can understand
  • Appreciation of the wider roles of interconnecting Cyber Security teams and collaboration with each of those ( i.e., Forensics / Threat Intelligence / Penetration Testing / Vulnerability Management / "Purple Teaming" etc.)
  • Ability to handle fluctuating workloads, conflicting
  • Analytical skills
  • Strategic vision
  • Rigor & Accuracy
  • Flexibility
  • Communication skills
  • Collaboration
  • Self - driven
  • Ability to track various priorities and concurrent activities



Create a job alert for this search

Cybersecurity - Operations and Threat Detection Analyst • Montréal, QC, Canada

Similar jobs

Analyste en Sécurité Cybernétique

ALTENMontreal (administrative region), QC, CA
Full-time

Devenez Analyste en Gestion des Vulnérabilités chez ALTEN Canada, situé à Montréal.Ce rôle clé nécessite une expertise en gestion des vulnérabilités et en cybersécurité.Avec près de 3 à 8 ans d’exp... Show more

 • Promoted

Senior Threat Detection & Response Engineer

1PasswordMontreal (administrative region), QC, CA
Full-time

A leading cybersecurity company in Canada seeks a Senior Security Engineer to enhance threat detection and response capabilities.You will design systems for threat detection, lead incident response... Show more

 • Promoted

Senior Analyst - Security Operations

Cirque du Soleil Entertainment GroupMontreal
Full-time +1

Senior Analyst – Security Operations.Review security events to detect and prevent potential information security incidents.Analyze threats and identify strategies to contain and prevent them.Partic... Show more

 • Promoted

Analyste Cybersécurité SOC (Télétravail)

Workin GroupMontreal, Quebec, Canada
Remote
Full-time

Vous restez basé et résident dans votre pays actuel, et vous travaillez à distance pour un client canadien.Si votre objectif est de vous installer au Canada, ce poste ne correspond pas à votre proj... Show more

Remote Security & DevOps Engineer for SaaS/IoT Cloud

KeycafeMontreal (administrative region), QC, CA
Remote
Full-time

A leading technology firm in Canada is seeking a passionate Security & DevOps Engineer to enhance its cloud environments and ensure high security across its global IoT platform.You'll manage applic... Show more

 • Promoted

Cybersecurity Analyst Role Focusing on Security Monitoring and Awareness

NOVIPROMontreal (administrative region), QC, CA
Full-time

Exciting opportunity for a Cybersecurity Analyst to join a security-focused team remotely.Play a crucial role in identifying vulnerabilities and enhancing the security framework through best practi... Show more

 • Promoted

Workday Security Analyst

neteffectsMontreal (administrative region), QC, CA
Full-time

Remote from the UK - to work for an International US-based company.Workday security area – focusing on Workday HR user, domain, business process, and integrations security, privacy, audit, controls... Show more

 • Promoted

Threat Modeling Analyst

nugget.aiMontréal, Montreal (administrative region), Canada
Full-time

The Threat Modeling Analyst is responsible for identifying threats and vulnerabilities across company systems and communicating the issues with the appropriate team – infrastructure, IT, risk, DLP,... Show more

 • Promoted

Cyber Security Analyst

MindlanceMontreal, Montreal (administrative region), CA
Full-time

This range is provided by Mindlance.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.Subject Matter Expert - Recruitment at Mindlance.Job Role: I... Show more

 • Promoted

Analyste Cybersécurité SOC – Horaires 24/7

Tower Research CapitalMontreal (administrative region), QC, CA
Full-time

Une société de négociation à haute fréquence à Montréal recherche un Analyste en sécurité de l’information pour améliorer la posture de sécurité.Le candidat idéal possède un baccalauréat en informa... Show more

 • Promoted

Ecosystem Security Data Analyst at Epic Games

Epic Games, Inc.Montreal
Full-time

Improve online safety at Epic Games as an Ecosystem Security Data Analyst.This role focuses on leveraging data analytics to address security threats in the gaming community.Epic Games is on the loo... Show more

 • Promoted

Senior DFIR Consultant for Complex Cybersecurity Investigations

New Value SolutionsMontreal (administrative region), QC, CA
Full-time

Become a pivotal force in cybersecurity as a Senior DFIR Consultant.Lead forensic investigations and incident responses in a contract capacity across enterprise systems.This senior role requires yo... Show more

 • Promoted

Operational Technology Cybersecurity Expert

WSP in CanadaMontreal
Full-time

Join as an Operational Technology Cybersecurity Expert, focusing on safeguarding energy systems.Leverage your expertise in cybersecurity to enable safe digital transformation in critical infrastruc... Show more

 • Promoted

Operational Risk Specialist Elevating Portfolio Integration Strategies

Infotree Global SolutionsMontreal
Full-time

As a Senior Operational Risk Advisor, you will play a critical role in integrating portfolios and enhancing risk management practices.Leverage your expertise to drive innovation while addressing op... Show more

 • Promoted

Compliance Risk Assessment Specialist

SynechronMontreal (administrative region), QC, CA
Full-time

Synechron est un cabinet mondial de conseil de premier plan en transformation numérique, spécialisé dans les services financiers et les organisations technologiques.Nos expertises couvrent l’intell... Show more

 • Promoted • New!

Remote Cloud Security Architect: DevSecOps & Risk Leader

Intuitive.aiMontreal (administrative region), QC, CA
Remote
Full-time

A leading cybersecurity solutions company is seeking a Cybersecurity Specialist (GCP) to enhance their Cybersecurity Program.The role involves developing comprehensive security strategies in cloud ... Show more

 • Promoted

Senior Bilingual Analyst for Fraud Detection

CAA Club GroupWestmount
Full-time

Take on a critical role as a Senior Bilingual Analyst in the Special Investigations Unit at Echelon Insurance.Focus on developing fraud detection strategies and ensuring compliance in a collaborati... Show more

 • Promoted

CAE Cybersecurity and DevOps Expert

CAEMontreal
Full-time

Advance your career at CAE as a Cybersecurity and DevOps Integration Specialist, focusing on dynamic security solutions.Collaborate in a high-performance environment committed to global safety.In t... Show more

 • Promoted

Security Analyst

360 IT ProfessionalsMontreal (administrative region), QC, CA
Full-time

IT Professionals is a Software Development Company based in Fremont, California that offers complete technology services in Mobile development, Web development, Cloud computing and IT staffing.Merg... Show more

 • Promoted

Senior L3 SOC Analyst & Incident Response Lead (Hybrid)

act digitalMontreal
Full-time

A technology consulting firm in Montreal is seeking an experienced L3 SOC Analyst to lead incident response efforts and enhance threat detection capabilities.In this role, you will monitor security... Show more