Connexion

Compétences recherchées — Connectez-vous et téléversez votre CV pour comparer avec votre profil
Analyse de données Cybersécurité Intelligence artificielle +7 autres

Détails du poste

  • Lieu de travail : Montreal
  • Type de poste : Permanent à temps plein

Description du poste

Overview:

  • The client is looking for an IT security analyst for its SOC, positioned at level 2: alerts reach this person already escalated by level 1, and the person in turn acts as the technical escalation point for those analysts.
  • The work centres on investigation: qualifying phishing, account compromise, malware or lateral movement cases, correlating events across several platforms, then enriching them with logs, indicators of compromise and threat intelligence.
  • The person determines verdict, severity and impact, then recommends or initiates first measures according to established processes, with incident response remaining initial and carried out with other teams.
  • The form title specifies no level, while the full set of responsibilities describes a level 2 role.
  • The Talents and qualifications section is empty: no degree, certification, language or named tool is required, so assessment rests entirely on the activity profile.
  • Target candidate: a QA professional with at least 10 years in IT, including 5 years in testing, who has coordinated testing within agile teams and uses JIRA, XRAY, Cypress and Playwright in recent mandates.
  • Group insurance exposure or an integration project will set apart otherwise equal candidates.

Exigences

Requis

  • Analysis and qualification of escalated alerts (phishing, account compromise, malware, lateral movement)
  • Event correlation (SIEM, XDR, EDR, identity, email, network, cloud)
  • Alert enrichment (logs, indicators of compromise, threat intelligence)
  • Determination of verdict, severity, potential impact and required actions
  • Initial mitigation, containment or escalation measures, recommended or initiated per processes
  • Documentation of investigations, findings, decisions and actions
  • First-level technical analysis of endpoint and network logs and artefacts
  • Support and coaching of level 1 SOC analysts on complex cases
  • Improvement of detection rules, investigation queries, runbooks and playbooks
  • Use of approved AI and automation tools (triage, enrichment, documentation)