Senior Cyber Security Analyst responsible for Level 2 and Level 3 SOC operations. Involves identifying risks, managing incidents, and supporting Cyber Security initiatives.
Responsibilities
Provides Level 2/3 SOC triage and investigations on escalated security incidents to identify root cause and mitigate control gaps
Escalates and leads major cyber security incident response
Provides oversight and backup to the Level 1 SOC operations
Included in on-call rotations and assists other team members with afterhours incident response and resolution if required
Assists with the design, management and execution of cross-organization project plans that involve the cyber security team
Collaborates with project work stream leads to ensure cyber and information technology security risks are identified, raised, and prioritized
Identifies and closes information and cyber security gaps within project plans by proactively pursuing details from key stakeholders
Assists in monitoring Tru Cooperative Bank’s networks for security breaches and/or incidents and investigates any violations
Prepares reports that document security incidents and control gaps
Supports external consultant engagements in support of Cyber Security initiatives
Senior level advisor to the standard and advanced configurations of security systems and controls
Assists in the implementation of configuration changes where required
Senior level interface to security vendor relationships
Provides management support in the creation of management and executive reporting products
Assists in the creation and maintenance of Cyber Security strategies where required
Maintains up-to-date detailed knowledge of the information security industry including awareness of new or revised security solutions, improved security processes and the development of new attacks and threat vectors.
Requirements
Bachelor’s Degree in Technology or a related field preferred or a combination of education and experience
CISSP or CISM an asset
5 years information/cyber security related work experience required
5 years information technology related work experience required
Experience in an OSFI regulated environment an asset
Proven ability to communicate effectively both verbally, and in writing, with a wide variety of people
Demonstrated ability to work independently or as part of a collaborative team
Demonstrated time management, organizational and prioritization skills
Strong working experience with deploying and securing Cloud deployments including PAAS, IAAS and SAAS – Microsoft Azure an asset
Strong experience with Cyber Security incident handling and SOC operations
Working understanding of the following control and program frameworks: NIST Cyber Security Framework, OWASP Top 10, and CIS Critical Security Control
Strong working technical knowledge of log management platforms including Syslog and at least one enterprise class SIEM – MS Azure Sentinel an asset
Strong understanding of IP, TCP/IP, and other common network protocols
Experience with two or more scripting languages including Python and PowerShell
Displays an understanding of risk and risk ownership by being able to demonstrate adherence to policies and procedures.
Benefits
Mental health coverage and resources
Customizable health benefits, as well as topped-up parental leave
Performance-based compensation, employee banking advantages and group RRSP matching
Vacation time and flexible work arrangements to support your lifestyle
Threat Intelligence Analyst investigating telecom security threats and customer deployment data for Enea, a global telecom and cybersecurity software company. Supporting client security reviews and threat intelligence operations.
Information Security Analyst governing End - User Computing risks, controls, and remediation for TD, a major North American bank. Advising stakeholders and supporting governance reporting, audits, and regulatory requirements.
IT Security Analyst II coordinating cybersecurity monitoring, MSP oversight, audits, and incident follow - up. Supporting Veristat’s global life - sciences services and regulated technology environments.
Security Analyst protecting GitLab’s DevSecOps platform through vulnerability triage and CVE operations. Coordinating researchers, customers, and internal teams on secure software response.
SIEM/SOAR cybersecurity analyst monitoring threats, building alerts, and measuring controls. Supporting Wepoint’s digital transformation work for businesses and public sector organizations.
SIEM/SOAR information security analyst supporting Wepoint’s digital transformation services. Developing cybersecurity monitoring cases, alerts, dashboards, and security - control documentation.
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.