Maarut
IT Security Analyst (SOC) - GC1721-09
Quebec/Montreal, CAIn sedeContrattoTempo pieno
Pubblicato il 26 set 2026
Questa offerta è pubblicata in EN
Overview:
- The client is looking for an IT security analyst for its SOC, positioned at level 2: alerts reach this person already escalated by level 1, and the person in turn acts as the technical escalation point for those analysts.
- The work centres on investigation: qualifying phishing, account compromise, malware or lateral movement cases, correlating events across several platforms, then enriching them with logs, indicators of compromise and threat intelligence.
- The person determines verdict, severity and impact, then recommends or initiates first measures according to established processes, with incident response remaining initial and carried out with other teams.
- The form title specifies no level, while the full set of responsibilities describes a level 2 role.
- The Talents and qualifications section is empty: no degree, certification, language or named tool is required, so assessment rests entirely on the activity profile.
- Target candidate: a QA professional with at least 10 years in IT, including 5 years in testing, who has coordinated testing within agile teams and uses JIRA, XRAY, Cypress and Playwright in recent mandates.
- Group insurance exposure or an integration project will set apart otherwise equal candidates.
Requirements
Required:- Analysis and qualification of escalated alerts (phishing, account compromise, malware, lateral movement)
- Event correlation (SIEM, XDR, EDR, identity, email, network, cloud)
- Alert enrichment (logs, indicators of compromise, threat intelligence)
- Determination of verdict, severity, potential impact and required actions
- Initial mitigation, containment or escalation measures, recommended or initiated per processes
- Documentation of investigations, findings, decisions and actions
- First-level technical analysis of endpoint and network logs and artefacts
- Support and coaching of level 1 SOC analysts on complex cases
- Improvement of detection rules, investigation queries, runbooks and playbooks
- Use of approved AI and automation tools (triage, enrichment, documentation)
Informazioni ruolo
Tipo di lavoro
Tempo pieno
Skill richieste
Alert Triage and QualificationPhishing Investigation and AnalysisAccount Compromise InvestigationInitial Malware AnalysisLateral Movement Detection and InvestigationSIEM Event CorrelationEDR/XDR Endpoint AnalysisNetwork and Cloud Log AnalysisThreat Intelligence and IOC EnrichmentIncident Severity, Verdict and Impact AssessmentInitial Mitigation, Containment and Escalation ActionsDetection Rule, Investigation Query and Playbook/Runbook ImprovementInvestigation Documentation and ReportingUse of Approved AI and Automation Tools for Triage/Enrichment/Documentation
Offerte simili
Python Developer, API integration of security tools
Maarut
Quebec/Montreal, CAIn sedeContrattoTempo pieno
10 giorni fa
Salesforce Developer
Maarut
Quebec/Montreal, CAIn sedeContrattoTempo pieno
13 giorni fa
GCP Infrastructure & Cloud SRE Engineer
Astra North Infoteck Inc.
Toronto, CAIn sedeContrattoTempo pieno
9 ore fa
AWS Sagemaker / MLOPS Engineer
Astra North Infoteck Inc.
Toronto, CAIn sedeContrattoTempo pieno
9 ore fa
Data Center IT Infrastructure Technician
Astra North Infoteck Inc.
Markham, CAIn sedeContrattoTempo pieno
9 ore fa
Bilingual IT Support Engineer
Astra North Infoteck Inc.
mirabel, CAIn sedeContrattoTempo pieno
9 ore fa