Threat Analyst monitoring, investigating, and responding to cyber threats for Sophos’s MDR cybersecurity service. Conducting threat hunting, incident response, and customer case management.
Responsibilities
Monitor, investigate, and respond to alerts generated by the Sophos security stack, including EDR/XDR capabilities
Mentor junior analysts through escalated cases
Perform end-to-end analysis of suspicious activity to assess scope, impact, and risk
Identify and respond to cyber threats across customer environments using approved playbooks and tooling
Document findings, investigative steps, and outcomes in the MDR case management platform
Conduct threat hunting across the MDR customer base
Investigate phishing emails, suspicious binaries, and behavioral anomalies
Support detection tuning by identifying recurring false positives and suggesting improvements
Research threat actor behaviors, MITRE ATT&CK techniques, threat intelligence, emerging IOCs, active exploits, and vulnerabilities
Contribute to internal knowledge bases, documentation, and continuous improvement initiatives
Participate in shift rotations and provide detailed handovers between global teams
Support active security incidents
Create cases, track progress, and follow up with clients until resolution
Engage with clients via chat, phone, and tickets
Help develop and refine Security Operations processes, playbooks, and tooling
Requirements
3+ years of hands-on experience in a Security Operations Center (SOC), Managed Detection and Response (MDR) environment, or cybersecurity-focused IT role
Proficient in endpoint and network security tools, including EDR, IDS/IPS, and malware detection platforms
Working knowledge of Windows workstations and servers, plus Linux or macOS environments
Ability to interpret and analyze Windows event logs and other telemetry data
Understanding of TCP/IP, protocols, routing, and traffic analysis
Experience contributing to real-time incident response and threat investigations
Exposure to threat hunting methodologies and attacker behavior patterns
Experience with containment, mitigation, and recovery during security incidents
Familiarity with persistence, privilege escalation, lateral movement, and defense evasion techniques
Familiarity with incident response workflows and security operations processes
Strong analytical thinking, troubleshooting, and attention to detail
Excellent communication skills for technical and non-technical audiences
Customer-first mindset and professionalism
Bachelor's degree in information technology, Computer Science, Cybersecurity or related field, or equivalent practical experience
Willingness to participate in shift work including nights, weekends, and holidays
Legal authorization to work in Canada without employer sponsorship
Transactions Closing Analyst closing Canadian real estate transactions in EZMax, Broker Wolf, and TRX. Supporting agents with documentation, splits, funding eligibility, and transaction status updates.
Rate Analyst pricing air and ocean freight for Livingston International, a global customs brokerage and freight forwarding company. Maintaining carrier rates, quoting clients, and supporting Sales and Operations.
BOM Analyst managing aerospace manufacturing BOMs and product data for Expleo in Montreal. Coordinating ERP/PLM changes across engineering, manufacturing, supply chain, and quality teams.
IT Senior Analyst supporting Saputo’s global dairy business through WorkforceSoftware time and attendance solutions. Integrating HR, payroll, and enterprise applications across hybrid teams.
M&A Analyst supporting search, due diligence, and execution of software acquisitions. Partner One invests in and grows successful enterprise software companies.
Saputo IT analyst developing and supporting Workday HCM integrations for a global dairy processor. Translating HR requirements into enterprise application solutions across Canada and North America.
IAM Analyst II managing identity systems, access governance, and security operations for Best Buy’s technology retail business. Improving automation, compliance, and access controls in Vancouver’s remote - first model.