Talent.com
Tech Talent International
Computer Security Incident Response ExpertTech Talent International • Montreal, QC, Canada
Computer Security Incident Response Expert

Computer Security Incident Response Expert

Tech Talent International • Montreal, QC, Canada
30+ days ago
Job type
  • Full-time
  • Permanent
  • Quick Apply
Job description

Tech Talent International (SI) supplies technical talent to a variety of clients ranging from Fortune 100/500/1000 companies to small and mid-sized organizations in Canada/US and Europe.

We currently have a role as a CyberSecurity Incident Response Expert with our large consulting client on a long term project with a major financial services client in the downtown Montreal area.

This role can either be a fulltime, perm role or a long term C2C contract.

Role: Cybersecurity - Computer Security Incident Response Expert

Type: Permanent or Contract 40 hrs/week

Location: Hybrid - Downtown Montreal, QC -(roles starts off 5 days in office for 1st 3 months, then turns into hybrid setup 3 days onsite, 2 days from home)

Salary: $110,000 - $120,000 + 9% bonus + 3-5 weeks paid vacation + RRSP contribution + benefits + sick/personal days

Contract Rate Option: $100 - $105/hr C2C


The Production CSIRT Purple Team Expert position will provide security expertise to the 24x7 Security

Operation Center (SOC). The primary purpose of this position is to develop, implement and assist on the continuous evolution of security use cases and correlation rules which assist on detecting, preventing, and responding to cyber threats against our group's infrastructure. It provides critical support to the firm - wide cybersecurity program via partnerships in the region with our peer s globally and within our diverse lines of business as well as externally with client s, partners and regulators.

As a Production Security Purple Team Expert , you are not only responsible for the continuous use case and correlation rule development and enhancement but also expected to participate in Threat Hunting and participate in cybersecurity investigations which will enhance the 24x7 Security Opera tion Center (SOC) capabilities as the first line of defense to identify potential information security incidents.

MAIN RESPONS IBILITIES

Responsibilities include but are not limited to:

  • Provide analysis and trending of security log data from many heterogeneous security devices
  • Responsible for use - case development and validation
  • Develop threat hunting program and capabilities
  • Investigate, document and report on information security issues and emerging trends
  • Perform threat hunting to identify potential adversaries within the network as well as participate in exercises with the AMER Purple Team to detect and remediate any potential gaps or use case
    defects.
  • Provide support and /or research any security related questions or incidents.
  • Perform tasks independently with some oversight
  • Integrate and share information with other analysts and other teams.
  • Follow incident - specific procedures to perform triage of potential security incidents to validate and
    determine needed mitigation and maintain said procedures up to date.
  • Escalate potential security incidents to Level IV engineers, implements countermeasures in response
    to others, and recommend operational improvements
  • Maintaining awareness of the bank's technology architecture, known weaknesses, the architecture
    of the security solutions used for monitoring, imminent and pervasive threats as identified by client
    threat intelligence, and recent security incidents
  • Continuously improve the service by identifying and correcting issues or gaps in knowledge (analysis
    procedures, plays, client network models), false positive tuning, identifying, and recommending new or updated use cases , content, countermeasures, scripts.

Classification : Internal

  • Serve as a subject matter expert in at least one security - related area ( e.g., specific malware solution, python programming, etc.)
  • Actively seek self - improvement through continuous learning and pursuing advancement to a Level IV Analyst
  • Adhere to internal operational security and other policies
  • Regular interactions with local AMER CSIRT Teams ( CTI, Purple) as well as with EMEA and APAC
    regions.
  • Perform light project work as assigne
  • REQUIREMENTS, TRAINING AND OCCUPATIONAL EXPERIENCE
  • Experience in IT Security Incident management at level 3 or multiple years (
  • In- depth technical knowledge of methods used by malware and APTs
  • Extended culture on Cybersecurity
  • Knowledge of security concerning the network infrastructure, UNIX and Windows environments,
    databases, package deployment tools, security tools (USB port control, hard drive encryption)
  • Script writing in shell, Python, Java, PowerShell, Ansible, SQL
  • 5+ years of experience with the following technologies: SIEM, ELK, IDS/IPS, network -
    and host - based firewalls, data leakage protection (DLP)
  • Direct experience with anti - virus software, endpoint detection response (EDR), firewalls and content
    filtering
  • experience with networ phishing
  • Experience or demonstrable knowledge in Incident response, log analysis and PCAP analysis
  • Good level of knowledge in network fundamentals, for example, OSI Stack, TCP/IP, DNS, HTTP(S), SMTP
  • Good level of understanding in the approach threat actors take to attacking a
    port scanning, web application attacks, DDoS, lateral movement
  • Passion to learn and to contribute to the ongoing development of the team
  • Certifications like GCFA, GCIH, OSCP, or similar are good to have


Skills/Behaviors Preferred:


  • Ability to demonstrate the right approach to investigating alerts and/or indicators and document your findings in a manner that both peer and executive level colleagues can understand
  • Appreciation of the wider roles of interconnecting Cyber Security teams and collaboration with each of those ( i.e., Forensics / Threat Intelligence / Penetration Testing / Vulnerability Management / "Purple Teaming" etc.)
  • Ability to handle fluctuating workloads, conflicting
  • Analytical skills
  • Strategic vision
  • Rigor & Accuracy
  • Flexibility
  • Communication skills
  • Collaboration
  • Self - driven

Create a job alert for this search

Computer Security Incident Response Expert • Montreal, QC, Canada

Similar jobs

Security Operations Incident Response Analyst

CAE IncMontreal
Full-time

Join as a Security Operations Incident Response Analyst focusing on timely incident resolution.Support the security team by analyzing alerts and enhancing incident response capabilities across the ... Show more

 • Promoted

Senior DevOps Engineer with Expertise in Cloud and Incident Management

RipplingMontreal (administrative region), QC, CA
Full-time

Advance your career as a Senior DevOps Engineer, focusing on optimizing corporate IT through security and automation.This role emphasizes autonomy within cloud-native environments while significant... Show more

 • Promoted

Architectural Security Specialist in Cyber

PowerToFlyMontreal (administrative region), QC, CA
Full-time

Shape the future of security architecture at Morgan Stanley as a Senior Security Architecture Specialist.This hybrid position is designed to position compliance at the heart of development practice... Show more

 • Promoted

Senior Security Architect - Remote, Equity, Impact

CliniaMontreal
Remote
Full-time

A digital health company is seeking a Senior Security Specialist in Montreal to lead security architecture and manage incidents across cloud environments.Responsibilities include developing securit... Show more

 • Promoted

Security Analyst (SOC)

Bedard ResourcesLaval (administrative region), QC, CA
Full-time

Our client is looking for a Junior Cybersecurity Analyst to assist with the daily management of a simulation platform, support the onboarding of new clients, and contribute to analyses related to a... Show more

 • Promoted

Expert en Cybersécurité chez PwC Canada

PwC CanadaMontreal (administrative region), QC, CA
Full-time

Cherchez-vous un rôle stimulant chez PwC Canada en tant qu'Expert en Cybersécurité? Protégez les clients contre les cybermenaces en analysant, identifiant et proposant des solutions améliorées.Le p... Show more

 • Promoted

Information Security Consultant

ExperisMontreal (administrative region), QC, CA
Full-time

This range is provided by Experis.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.Direct message the job poster from Experis.IT Security Consult... Show more

 • Promoted

Expert Security Analyst Focusing on Tool Utilization and Threat Intelligence

Prosperity Workforce SolutionsMontreal (administrative region), QC, CA
Full-time

Join as a Security Analyst to enhance your organization’s cybersecurity.Focus on fine-tuning detection systems, optimizing endpoint protection, and enhancing the security toolset’s effectiveness in... Show more

 • Promoted

BRP Cyber Security Cloud Expert

BRPMontreal
Full-time

Become a Cyber Security Cloud Expert at BRP, safeguarding vital systems and information against cyber threats.Your expertise in cloud technologies and security frameworks is essential for success.I... Show more

 • Promoted

Senior Security Engineer Focused on Detection and Response Frameworks

1PasswordMontreal (administrative region), QC, CA
Full-time

Join as a Senior Security Engineer to strengthen detection and incident response frameworks.Lead initiatives that optimize security measures and enhance organizational resilience in a remote enviro... Show more

 • Promoted

Strategic Information Security Architect

ColliersMontreal (administrative region), QC, CA
Full-time

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Show more

 • Promoted

Remote IT Security Risk Analyst: Governance & Risk

Onico SolutionsMontreal (administrative region), QC, CA
Remote
Permanent

A leading IT security firm in Richmond Hill is looking for an IT Security Risk Analyst to support their Information Security Risk Management programs.The role requires expertise in risk assessments... Show more

 • Promoted

Senior Level 3 IT Support Technician | Complex Incident Expert

MontechnicienMontreal (administrative region), QC, CA
Full-time

A well-established IT company in Montreal seeks a Level 3 Support Technician to guide teams through complex incident resolutions and improve support practices.This role involves ownership of escala... Show more

 • Promoted

Remote Cloud Security Architect: DevSecOps & Risk Leader

Intuitive.aiMontreal (administrative region), QC, CA
Remote
Full-time

A leading cybersecurity solutions company is seeking a Cybersecurity Specialist (GCP) to enhance their Cybersecurity Program.The role involves developing comprehensive security strategies in cloud ... Show more

 • Promoted

Senior Incident Response Consultant at CrowdStrike

CrowdStrikeMontreal (administrative region), QC, CA
Full-time

Join CrowdStrike as a Senior Incident Response Consultant and play a critical role in modern cybersecurity.This position allows you to shape responses to sophisticated cyber threats.We are looking ... Show more

 • Promoted

Senior Application Security Specialist

EXFOMontreal
Full-time

A leading telecom solutions provider is seeking an experienced Application Security Specialist in Montreal, Canada.This role focuses on driving application security strategies, performing risk asse... Show more

 • Promoted

Remote Information Risk & Security Analyst

DexianMontreal (administrative region), QC, CA
Remote
Full-time

A leading IT services firm is seeking an Information Control Testing Specialist to manage information risk and ensure compliance with security policies.You will work on global initiatives, conduct ... Show more

 • Promoted

Architecte Cloud OCI avec Expertise en Sécurité et Performance

Jesta I.S.Montreal (administrative region), QC, CA
Full-time

Rejoignez une équipe dynamique comme Architecte OCI pour façonner l'avenir du cloud.Ce rôle clé consiste à architecturer et sécuriser des infrastructures OCI critiques.En tant qu'Architecte, vous s... Show more

 • Promoted

Lasso Informatics Cloud Infrastructure Lead

Lasso Informatics Inc Lasso Informatique IncMontreal (administrative region), QC, CA
Full-time

Become a Cloud Infrastructure Lead with Lasso Informatics, focusing on AWS and GCP in a hybrid setting.Drive system observability and security enhancements for scientific research.In this full-time... Show more

 • Promoted

Game Security Engineer: Anti-Cheat & Integrity

Jobs for HumanityMontreal
Full-time

A leading gaming company in Montreal is seeking a Game Security Programmer to develop and maintain security features in games.In this role, you will integrate anti-cheat systems, secure communicati... Show more