L3 SOC Analyst - Calgary
On-siteCalgary, Alberta, Canada
Job Summary
Act as the Level 3 escalation point for advanced, complex, or high-impact security investigations, providing technical guidance and validation to Level 2 analysts. Perform in-depth analysis of security events, alerts, logs, endpoint telemetry, and network traffic to lead incident investigations, including scoping, containment, and remediation recommendations. Analyze malicious activity and adversary tactics, techniques, and procedures to support threat hunting and proactive analysis. Contribute to the continuous improvement of detection logic, tuning security technologies, and refining investigation playbooks while mentoring Level 1 and Level 2 analysts. Document findings, evidence, and timelines in structured reports for customers and stakeholders.
Required Qualifications
- Minimum 5 years of experience in cyber security, including experience in SOC, MDR, incident response, CSIRT or cyber security operations environments
- Proven experience handling complex security incidents and supporting advanced investigations
- Willingness and ability to undertake training on Integrity360's MDR solutions, platforms and operational methodologies
- Working knowledge of SIEM, EDR, SOAR, NIDS, DLP and threat intelligence platforms
- Strong hands-on experience in Security Operations Centre or MDR environments
- Deep operational knowledge of SIEM, EDR, Network Intrusion Detection Systems, SOAR, DLP and related security monitoring technologies
- Strong experience with security event triage, correlation, investigation and escalation
- Ability to analyse endpoint, network, identity, cloud and application telemetry in support of complex investigations
- Experience with SIEM query languages and detection logic, such as KQL, SPL, Sigma or equivalent
- Experience tuning security controls and detection content to improve alert fidelity and reduce false positives
- Strong understanding of attacker tactics, techniques and procedures, including MITRE ATT&CK
- Ability to perform host-based and network-based threat analysis
- Experience analysing packet captures, endpoint artefacts, logs, scripts, documents and potentially malicious files
- Strong understanding of incident response lifecycle, including preparation, identification, containment, eradication, recovery and lessons learned
- Strong understanding of enterprise network architecture, TCP/IP, firewalls, proxies, VPNs, DNS, email security and cloud environments
- Understanding of security protocols, encryption technologies and common authentication mechanisms
- Experience supporting customer-facing technical discussions, including investigation reviews, tuning recommendations and posture improvement activities
- Ability to manage multiple complex incidents and make effective decisions under pressure
- Strong written and verbal communication skills, with the ability to explain technical findings to both technical and non-technical stakeholders
Desired Qualifications
- Experience with Microsoft Sentinel, Microsoft Defender, Splunk, QRadar, CrowdStrike, SentinelOne, Palo Alto, Suricata, Zeek, Snort or similar technologies
- Experience with cloud security monitoring across Microsoft Azure, AWS or Google Cloud
- Experience with threat hunting, detection engineering or purple team activities
- Ability to produce clear technical documentation, investigation reports and customer-facing recommendations
- Security industry certifications such as GCIH, GCFA, GCIA, GNFA, GCTI, GSEC, CISSP, CySA+, SC-200, AZ-500 or equivalent
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.