Tech Talent International logo
Tech Talent InternationalPosted 1 month ago

Computer Security Incident Response Expert

$110,000–$120,000 year

On-siteMontréal, Quebec, Canada

Full TimeSmall

Job Summary

Conduct daily analysis and trending of security log data from heterogeneous devices while developing and validating use cases and correlation rules for the 24x7 Security Operations Center. Lead threat hunting programs to identify adversaries, investigate information security incidents, and document findings for executive and peer review. Perform triage of potential security incidents, implement countermeasures, and recommend operational improvements based on client threat intelligence and emerging trends. Collaborate with AMER, EMEA, and APAC CSIRT teams to share information and maintain awareness of network architecture, known weaknesses, and pervasive threats. Continuously improve analysis procedures, false positive tuning, and scripts in Python, PowerShell, and shell to enhance detection capabilities.

Required Qualifications

  • Experience in IT Security Incident management at level 3 or multiple years
  • In-depth technical knowledge of methods used by malware and APTs
  • Extended culture on Cybersecurity
  • Knowledge of security concerning the network infrastructure, UNIX and Windows environments, databases, package deployment tools, security tools (USB port control, hard drive encryption)
  • Script writing in shell, Python, Java, PowerShell, Ansible, SQL
  • 5+ years of experience with the following technologies: SIEM, ELK, IDS/IPS, network- and host-based firewalls, data leakage protection (DLP)
  • Direct experience with anti-virus software, endpoint detection response (EDR), firewalls and content filtering
  • Experience or demonstrable knowledge in Incident response, log analysis and PCAP analysis
  • Good level of knowledge in network fundamentals, for example, OSI Stack, TCP/IP, DNS, HTTP(S), SMTP
  • Good level of understanding in the approach threat actors take to attacking port scanning, web application attacks, DDoS, lateral movement
  • Serve as a subject matter expert in at least one security-related area (e.g., specific malware solution, python programming, etc.)
  • Actively seek self-improvement through continuous learning and pursuing advancement to a Level IV Analyst
  • Adhere to internal operational security and other policies
  • Regular interactions with local AMER CSIRT Teams (CTI, Purple) as well as with EMEA and APAC regions
  • Perform light project work as assigne
  • Must be able to lift 50 lbs

Desired Qualifications

  • Certifications like GCFA, GCIH, OSCP, or similar are good to have
  • Ability to demonstrate the right approach to investigating alerts and/or indicators and document your findings in a manner that both peer and executive level colleagues can understand
  • Appreciation of the wider roles of interconnecting Cyber Security teams and collaboration with each of those (i.e., Forensics / Threat Intelligence / Penetration Testing / Vulnerability Management / "Purple Teaming" etc.)
  • Ability to handle fluctuating workloads, conflicting
  • Analytical skills
  • Strategic vision
  • Rigor & Accuracy
  • Flexibility
  • Communication skills
  • Collaboration
  • Self-driven
  • Passion to learn and to contribute to the ongoing development of the team
  • Must be available for weekend shifts

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce