SOC Analyst L2 & L3 needed in Mississauga, ON for hybrid contract role. Must have SIEM, SOAR, and EDR experience.
Responsibilities
Ability to work with very large and complex network. Self-motivated individual and creative thinker who will take ownership of tasks and projects, able to work with the team, and manages tasks effectively and has a proven track record of consistent and organized outputs. The ideal candidate will demonstrate an eagerness to understand complex problems and requirements, an aptitude for translating these problems into workable designs and solutions, and will possess a keen eye for detail. Responsibilities include reviewing SIEM escalated incidents, qualifying true positives, providing monthly trend and security analysis summary reports, performing advanced triages, liaising between cross-functional teams, and advocating protection and mitigation strategies.
Requirements
4+ years for L2 and 8+ years for L3. Knowledge/experience on any SIEM tool (preferably SPLUNK) and SOAR tools (preferably TINES). Exposure to Mitre framework. Hands-on experience in EDR platforms (CROWDSTRIKE) and threat analysis, threat hunting/incident response. Experience in analyzing security incidents and responding methodically. Knowledge in Network security/System Security/Endpoint Security. Experience in event monitoring, analysis, and escalations. Provide inputs for content management. Experience on monthly, weekly, and daily reporting. Willing to work on 24/7 operations. Strong knowledge of Windows, Linux, and MAC operating systems. Strong understanding of cyber security threats and recent trends. Experience in creating rules in SIEM. Understanding of AI usage in cyber security. Good verbal/written communication skills. Client-facing technical analysis report and presentation skills.
Cyber Defender protecting Ontinue’s AI - powered MXDR customers through SOC threat detection and response. Investigating threats across identity, endpoint, network, and cloud environments.
Security Operations Team Lead building Safe Software’s cybersecurity operations for FME, its enterprise data integration platform. Leading incident response, security tooling, compliance, and team growth.
SOC cybersecurity analyst monitoring and responding to cyber threats for Wepoint’s digital transformation clients. Improving 24×7 detection, investigation, and incident response capabilities.
SOC analyst monitoring and responding to cyber threats for Wepoint’s digital transformation clients. Investigating escalated alerts and improving 24×7 security operations.
Senior Security Operations Engineer monitoring incidents and leading forensics for Samsara’s IoT - connected operations platform. Building security automation and supporting insider - threat investigations.
Senior SOC analyst leading threat detection, investigations, and incident response for Financeit, a Canadian point - of - sale financing provider. Building its new SOC’s automation, AI - threat coverage, and operational standards.