Intermediate Security Operations Centre Analyst at Long View managing security incidents and working with IT systems. Engaging with teams across Canada in a dynamic IT environment.
Responsibilities
Actively participate in 24x7 operations of the Long View Security Operations Centre
Monitor, identify and validate security events generated from Security Information Event Management (SIEM) tools
Actively work in monitoring, event and incident management tools like Sentinel and ServiceNow
Respond to critical business impacting situations and coordinate the efforts required to engage the proper resources to remediate the issue
Coordinate major security incident situations and provide internal communications via email in a timely manor
Provide general support for Security Information Event Management (SIEM) tool changes, tweaks, additions and updates within Sentinel and any additional tools leveraged by Long View
Provide security guidance to team members across the organization how to best identify, contain and remediate security related incidents
Understand complex issues across on-premise, public and private cloud solutions and articulate the impact to higher tier team members
Follow and establish process documentation for receipt of security alerts for monitored devices, acknowledge the receipt of the event, opening and/or updating service desk tickets to track the handling of events to resolution and closure, assignment of the ticket to the appropriate owner
Work with cloud technologies like Azure, AWS and Google Cloud Platform
Fulfill reporting requests that can be pulled from Long View tools
Requirements
3+ years of professional experience in incident detection and response, malware analysis, or cyber forensics
SC-200 Certification
Experience working with MS Defender
Extensive experience evaluating, interpreting, and integrating relevant data sources for the purpose of merging network attack analyses with counterintelligence and law enforcement investigations
Experience with various IT service management tools including performance monitoring and ITSM solutions
Experience with Security Information Event Management platforms like Sentinel, Splunk and Sumo Logic
Experience working with incident, problem, change and service requests that follow ITIL framework standards
Experience provisioning new client services and working through customer onboarding tasks
Proven ability to troubleshoot and resolve technical and procedural issues
Strong verbal and written communication which will allow you to communicate effectively to customers in non-technical terms
Ability to react quickly and professionally with a sense of urgency
Ability and desire to work on an on-call rotation for 24-hour support
Security Operations Team Lead building Safe Software’s cybersecurity operations for FME, its enterprise data integration platform. Leading incident response, security tooling, compliance, and team growth.
SOC analyst monitoring and responding to cyber threats for Wepoint’s digital transformation clients. Investigating escalated alerts and improving 24×7 security operations.
SOC cybersecurity analyst monitoring and responding to cyber threats for Wepoint’s digital transformation clients. Improving 24×7 detection, investigation, and incident response capabilities.
Senior Security Operations Engineer monitoring incidents and leading forensics for Samsara’s IoT - connected operations platform. Building security automation and supporting insider - threat investigations.
Senior SOC analyst leading threat detection, investigations, and incident response for Financeit, a Canadian point - of - sale financing provider. Building its new SOC’s automation, AI - threat coverage, and operational standards.