Tech Talent International logo
Tech Talent InternationalPosted 1 month ago

Cybersecurity - Operations and Threat Detection Analyst

$110,000–$120,000 year

HybridMontréal, Quebec, Canada

ContractSmall

Job Summary

Conduct analysis and trending of security log data from heterogeneous devices while developing and validating use cases and correlation rules for the 24x7 Security Operations Center. Execute threat hunting programs to identify adversaries within the network, investigate information security issues, and perform triage of potential incidents to validate mitigation strategies. Escalate critical alerts to Level IV engineers, implement countermeasures, and recommend operational improvements based on client threat intelligence and recent security incidents. Maintain awareness of network architecture, known weaknesses, and pervasive threats while continuously improving analysis procedures, plays, and false positive tuning. Collaborate with AMER, EMEA, and APAC CSIRT teams, perform light project work, and serve as a subject matter expert in specific security areas such as malware or scripting languages.

Required Qualifications

  • Experience in IT Security Incident management at level 3 or multiple years
  • In-depth technical knowledge of methods used by malware and APTs
  • Extended culture on Cybersecurity
  • Knowledge of security concerning the network infrastructure, UNIX and Windows environments, databases, package deployment tools, security tools (USB port control, hard drive encryption)
  • Script writing in shell, Python, Java, PowerShell, Ansible, SQL
  • Knowledge of 5+ years of experience with the following technologies: SIEM, ELK, IDS/IPS, network- and host-based firewalls, data leakage protection (DLP)
  • Direct experience with anti-virus software, endpoint detection response (EDR), firewalls and content filtering
  • Experience or demonstrable knowledge in Incident response, log analysis and PCAP analysis
  • Good level of knowledge in network fundamentals, for example, OSI Stack, TCP/IP, DNS, HTTP(S)
  • Experience detecting and tracking and preventing network phishing
  • Good level of understanding in the approach threat actors take to attacking port scanning, web application attacks, DDoS, lateral movement
  • Serve as a subject matter expert in at least one security-related area (e.g., specific malware solution, python programming, etc.)
  • Actively seek self-improvement through continuous learning and pursuing advancement to a Level IV Analyst
  • Adhere to internal operational security and other client policies
  • Regular interactions with local AMER CSIRT Teams (CTI, Purple) as well as with EMEA and APAC regions
  • Perform light project work as assigned
  • Must be available for weekend shifts
  • Must be able to lift 50 lbs

Desired Qualifications

  • Certifications like GCFA, GCIH, OSCP, or similar are good to have
  • Ability to demonstrate the right approach to investigating alerts and/or indicators and document your findings in a manner that both peer and executive level colleagues can understand
  • Appreciation of the wider roles of interconnecting Cyber Security teams and collaboration with each of those (i.e., Forensics / Threat Intelligence / Penetration Testing / Vulnerability Management / "Purple Teaming" etc.)
  • Ability to handle fluctuating workloads, conflicting
  • Analytical skills
  • Strategic vision
  • Rigor & Accuracy
  • Flexibility
  • Communication skills
  • Collaboration
  • Self-driven
  • Ability to track various priorities and concurrent activities

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce