Talent.com
Tech Talent International
Computer Security Incident Response ExpertTech Talent International • Montreal, QC, Canada
Computer Security Incident Response Expert

Computer Security Incident Response Expert

Tech Talent International • Montreal, QC, Canada
3 days ago
Job type
  • Full-time
  • Permanent
  • Quick Apply
Job description

Tech Talent International (SI) supplies technical talent to a variety of clients ranging from Fortune 100/500/1000 companies to small and mid-sized organizations in Canada/US and Europe.

We currently have a role as a CyberSecurity Incident Response Expert with our large consulting client on a long term project with a major financial services client in the downtown Montreal area.

This role can either be a fulltime, perm role or a long term C2C contract.

Role: Cybersecurity - Computer Security Incident Response Expert

Type: Permanent or Contract 40 hrs/week

Location: Hybrid - Downtown Montreal, QC -(roles starts off 5 days in office for 1st 3 months, then turns into hybrid setup 3 days onsite, 2 days from home)

Salary: $110,000 - $120,000 + 9% bonus + 3-5 weeks paid vacation + RRSP contribution + benefits + sick/personal days

Contract Rate Option: $100 - $105/hr C2C


The Production CSIRT Purple Team Expert position will provide security expertise to the 24x7 Security

Operation Center (SOC). The primary purpose of this position is to develop, implement and assist on the continuous evolution of security use cases and correlation rules which assist on detecting, preventing, and responding to cyber threats against our group's infrastructure. It provides critical support to the firm - wide cybersecurity program via partnerships in the region with our peer s globally and within our diverse lines of business as well as externally with client s, partners and regulators.

As a Production Security Purple Team Expert , you are not only responsible for the continuous use case and correlation rule development and enhancement but also expected to participate in Threat Hunting and participate in cybersecurity investigations which will enhance the 24x7 Security Opera tion Center (SOC) capabilities as the first line of defense to identify potential information security incidents.

MAIN RESPONS IBILITIES

Responsibilities include but are not limited to:

  • Provide analysis and trending of security log data from many heterogeneous security devices
  • Responsible for use - case development and validation
  • Develop threat hunting program and capabilities
  • Investigate, document and report on information security issues and emerging trends
  • Perform threat hunting to identify potential adversaries within the network as well as participate in exercises with the AMER Purple Team to detect and remediate any potential gaps or use case
    defects.
  • Provide support and /or research any security related questions or incidents.
  • Perform tasks independently with some oversight
  • Integrate and share information with other analysts and other teams.
  • Follow incident - specific procedures to perform triage of potential security incidents to validate and
    determine needed mitigation and maintain said procedures up to date.
  • Escalate potential security incidents to Level IV engineers, implements countermeasures in response
    to others, and recommend operational improvements
  • Maintaining awareness of the bank's technology architecture, known weaknesses, the architecture
    of the security solutions used for monitoring, imminent and pervasive threats as identified by client
    threat intelligence, and recent security incidents
  • Continuously improve the service by identifying and correcting issues or gaps in knowledge (analysis
    procedures, plays, client network models), false positive tuning, identifying, and recommending new or updated use cases , content, countermeasures, scripts.

Classification : Internal

  • Serve as a subject matter expert in at least one security - related area ( e.g., specific malware solution, python programming, etc.)
  • Actively seek self - improvement through continuous learning and pursuing advancement to a Level IV Analyst
  • Adhere to internal operational security and other BNP Paribas policies
  • Regular interactions with local AMER CSIRT Teams ( CTI, Purple) as well as with EMEA and APAC
    regions.
  • Perform light project work as assigne
  • REQUIREMENTS, TRAINING AND OCCUPATIONAL EXPERIENCE
  • Experience in IT Security Incident management at level 3 or multiple years (
  • In- depth technical knowledge of methods used by malware and APTs
  • Extended culture on Cybersecurity
  • Knowledge of security concerning the network infrastructure, UNIX and Windows environments,
    databases, package deployment tools, security tools (USB port control, hard drive encryption)
  • Script writing in shell, Python, Java, PowerShell, Ansible, SQL
  • 5+ years of experience with the following technologies: SIEM, ELK, IDS/IPS, network -
    and host - based firewalls, data leakage protection (DLP)
  • Direct experience with anti - virus software, endpoint detection response (EDR), firewalls and content
    filtering
  • experience with networ phishing
  • Experience or demonstrable knowledge in Incident response, log analysis and PCAP analysis
  • Good level of knowledge in network fundamentals, for example, OSI Stack, TCP/IP, DNS, HTTP(S), SMTP
  • Good level of understanding in the approach threat actors take to attacking a
    port scanning, web application attacks, DDoS, lateral movement
  • Passion to learn and to contribute to the ongoing development of the team
  • Certifications like GCFA, GCIH, OSCP, or similar are good to have


Skills/Behaviors Preferred:


  • Ability to demonstrate the right approach to investigating alerts and/or indicators and document your findings in a manner that both peer and executive level colleagues can understand
  • Appreciation of the wider roles of interconnecting Cyber Security teams and collaboration with each of those ( i.e., Forensics / Threat Intelligence / Penetration Testing / Vulnerability Management / "Purple Teaming" etc.)
  • Ability to handle fluctuating workloads, conflicting
  • Analytical skills
  • Strategic vision
  • Rigor & Accuracy
  • Flexibility
  • Communication skills
  • Collaboration
  • Self - driven

Create a job alert for this search

Computer Security Incident Response Expert • Montreal, QC, Canada

Similar jobs

Security Operations Incident Response Analyst

CAE IncMontreal
Full-time

Join as a Security Operations Incident Response Analyst focusing on timely incident resolution.Support the security team by analyzing alerts and enhancing incident response capabilities across the ... Show more

 • Promoted

Intact Security Advisor - Cyber Incident Management

Intact Financial CorporationMontreal
Full-time

Join Intact as a Security Advisor Specialist, focusing on Cyber Incident Management.Ensure optimal responses to security incidents while supporting a culture of continuous improvement in a hybrid w... Show more

 • Promoted

Senior L3 SOC Analyst & Incident Response Lead (Hybrid)

act digitalMontreal (administrative region), QC, CA
Full-time

A technology consulting firm in Montreal is seeking an experienced L3 SOC Analyst to lead incident response efforts and enhance threat detection capabilities.In this role, you will monitor security... Show more

 • Promoted

Cybersecurity Specialist in SOC Incident Response

GenetecMontreal
Full-time

Drive cybersecurity initiatives as a Cybersecurity Specialist in a SOC.Utilize your skills in incident response and investigations to safeguard organizational assets.In this pivotal role, you will ... Show more

 • Promoted

Information Security Specialist - Application Security

WawanesaMontreal
Full-time +2

Information Security Specialist - Application Security.This role is considered a head-office role and will be required to communicate with internal and external stakeholders across Canada where the... Show more

 • Promoted

Senior Security Engineer Incident Response

AffirmMontreal (administrative region), QC, CA
Full-time

Become part of Affirm's mission as a Senior Security Operations Engineer focusing on Incident Response.This remote role emphasizes hands-on security incident management and proactive measures.Affir... Show more

 • Promoted

Remote Senior SOC Analyst for Threat Detection and Incident Management

TreantlyMontreal (administrative region), QC, CA
Remote
Full-time

Shape cybersecurity efforts as a Senior SOC Analyst, proficient in threat detection and incident response.Lead remote operations to tackle complex security challenges while mentoring junior analyst... Show more

 • Promoted

Expert en Incidents Cybersécurité Intact

IntactMontreal
Full-time

Devenez Expert en Incidents de Cybersécurité au sein de l'équipe d'Intact.Ce poste hybride met l'accent sur l'analyse, la résolution de problèmes et la gestion proactive des menaces.Nous sommes à l... Show more

 • Promoted

M365 Security Expert

LGI Healthcare SolutionsMontreal (administrative region), QC, CA
Full-time

With 40 years of expertise, LGI Healthcare Solutions develops technological software for the healthcare network.We specialize in providing solutions for clinical, financial and material management,... Show more

 • Promoted

Threat hunting practise Leader - laval

National Banklaval, qc, ca
Full-time

A career as a leader or practise leader in the threat Identification team at National Bank means acting as an expert in cybersecurity and proactive threat detection.This position allows you to have... Show more

 • Promoted

IBM X-Force Incident Response Consultant

IBMMontreal (administrative region), QC, CA
Full-time

Advance your career as an IBM Consultant Associate in X-Force Incident Response, starting September 2026 in Calgary, Toronto, Ottawa, Montreal, or Vancouver.This role focuses on threat hunting and ... Show more

 • Promoted

ComputerTalk Incident Manager Role

Computer Talk Technology Inc.Montreal
Full-time

Become the Incident Manager at ComputerTalk, where your role will be critical in maintaining service continuity during incidents.This position emphasizes team coordination and customer communicatio... Show more

 • Promoted

ITSM Senior Specialist Incident Management

Canada Mortgage and Housing CorporationMontreal (administrative region), QC, CA
Permanent

Elevate your career with CMHC as a Senior Specialist in Incident Management within ITSM.This permanent role is perfect for those passionate about ServiceNow enhancements.As part of Infrastructure a... Show more

 • Promoted

Senior Level 3 IT Support Technician | Complex Incident Expert

MontechnicienMontreal (administrative region), QC, CA
Full-time

A well-established IT company in Montreal seeks a Level 3 Support Technician to guide teams through complex incident resolutions and improve support practices.This role involves ownership of escala... Show more

 • Promoted

Expert Cloud Security Architect Specializing in Azure Solutions

Elits Canada Inc.Montreal (administrative region), QC, CA
Full-time

Elevate cloud security as an expert Cloud Security Architect, designing secure infrastructures using Microsoft Azure and Microsoft 365 services.Lead initiatives in identity management and complianc... Show more

 • Promoted

L3 SOC Analyst / Incident Responder

ALTER SOLUTIONSMontreal
Full-time

Job Description We are looking for an experienced L3 SOC Analyst / Incident Responder to join our cybersecurity team.In this role, you will be responsible for leading advanced threat detection,... Show more

 • Promoted

Remote Security Operations Lead | Ai-Driven Incident Response

ApolloRivière-Des-Prairies-Pointe-Aux-Trembles, Canada
Remote
Full-time

A leading SaaS company is seeking a Security Operations Manager to oversee and enhance security incident response and operations.This role requires a strong leader with over 5 years of experience i... Show more

 • Promoted

L3 SOC Analyst / Incident Responder Role

Act-DigitalMontreal (administrative region), QC, CA
Full-time

Enhance cybersecurity resiliency at Act Digital Canada as an L3 SOC Analyst / Incident Responder based in Montreal.Focus on incident response and advanced threat detection with a hybrid work model.... Show more

 • Promoted

Security Specialist – SIEM & Cyber Incident Response

Arobas PersonnelMontreal
Full-time

Join Arobas Personnel as a Security Specialist focused on PCSIRT and SIEM in a hybrid model from Montreal.Leverage your expertise to enhance SOC capabilities and monitor security environments effec... Show more

 • Promoted

Lead, Cyber Defense & Incident Response

Crédit Agricole GroupMontreal (administrative region), QC, CA
Full-time

A leading financial services provider in Quebec seeks an experienced Cybersecurity Incident Response Team Lead.This role involves leading the bank’s Security Operations strategy, overseeing inciden... Show more