Maarut
IT Security Analyst (SOC) - GC1721-09
Quebec/Montreal, CASur siteContratTemps plein
Publié 26 sept. 2026
Cet emploi est publié en EN
Overview:
- The client is looking for an IT security analyst for its SOC, positioned at level 2: alerts reach this person already escalated by level 1, and the person in turn acts as the technical escalation point for those analysts.
- The work centres on investigation: qualifying phishing, account compromise, malware or lateral movement cases, correlating events across several platforms, then enriching them with logs, indicators of compromise and threat intelligence.
- The person determines verdict, severity and impact, then recommends or initiates first measures according to established processes, with incident response remaining initial and carried out with other teams.
- The form title specifies no level, while the full set of responsibilities describes a level 2 role.
- The Talents and qualifications section is empty: no degree, certification, language or named tool is required, so assessment rests entirely on the activity profile.
- Target candidate: a QA professional with at least 10 years in IT, including 5 years in testing, who has coordinated testing within agile teams and uses JIRA, XRAY, Cypress and Playwright in recent mandates.
- Group insurance exposure or an integration project will set apart otherwise equal candidates.
Requirements
Required:- Analysis and qualification of escalated alerts (phishing, account compromise, malware, lateral movement)
- Event correlation (SIEM, XDR, EDR, identity, email, network, cloud)
- Alert enrichment (logs, indicators of compromise, threat intelligence)
- Determination of verdict, severity, potential impact and required actions
- Initial mitigation, containment or escalation measures, recommended or initiated per processes
- Documentation of investigations, findings, decisions and actions
- First-level technical analysis of endpoint and network logs and artefacts
- Support and coaching of level 1 SOC analysts on complex cases
- Improvement of detection rules, investigation queries, runbooks and playbooks
- Use of approved AI and automation tools (triage, enrichment, documentation)
Aperçu du poste
Type de poste
Temps plein
Compétences requises
Alert Triage and QualificationPhishing Investigation and AnalysisAccount Compromise InvestigationInitial Malware AnalysisLateral Movement Detection and InvestigationSIEM Event CorrelationEDR/XDR Endpoint AnalysisNetwork and Cloud Log AnalysisThreat Intelligence and IOC EnrichmentIncident Severity, Verdict and Impact AssessmentInitial Mitigation, Containment and Escalation ActionsDetection Rule, Investigation Query and Playbook/Runbook ImprovementInvestigation Documentation and ReportingUse of Approved AI and Automation Tools for Triage/Enrichment/Documentation
Emplois similaires
Python Developer, API integration of security tools
Maarut
Quebec/Montreal, CASur siteContratTemps plein
il y a 10 jours
Salesforce Developer
Maarut
Quebec/Montreal, CASur siteContratTemps plein
il y a 13 jours
S
IT Associate - Filipinas 1821
SOFTGIC
Manila Hilton, PHSur siteContratTemps plein
il y a 3 heures
Senior Product Manager - Rewards Strategy, Loyalty & SSO Integrations
Recrute Action
Toronto, CASur siteContratTemps plein
il y a 3 heures
S
1945 - Medellin -Asistente Administrativa
SOFTGIC
Sabaneta, COSur siteContratTemps plein
il y a 3 heures
Administrative Technician III
Smarter HR Solutions LLC
Houston, USSur siteContratTemps plein
il y a 3 heures