Maarut
IT Security Analyst (SOC) - GC1721-09
Quebec/Montreal, CAPresencialContratoTiempo completo
Publicado 26 sept 2026
Este empleo está publicado en EN
Overview:
- The client is looking for an IT security analyst for its SOC, positioned at level 2: alerts reach this person already escalated by level 1, and the person in turn acts as the technical escalation point for those analysts.
- The work centres on investigation: qualifying phishing, account compromise, malware or lateral movement cases, correlating events across several platforms, then enriching them with logs, indicators of compromise and threat intelligence.
- The person determines verdict, severity and impact, then recommends or initiates first measures according to established processes, with incident response remaining initial and carried out with other teams.
- The form title specifies no level, while the full set of responsibilities describes a level 2 role.
- The Talents and qualifications section is empty: no degree, certification, language or named tool is required, so assessment rests entirely on the activity profile.
- Target candidate: a QA professional with at least 10 years in IT, including 5 years in testing, who has coordinated testing within agile teams and uses JIRA, XRAY, Cypress and Playwright in recent mandates.
- Group insurance exposure or an integration project will set apart otherwise equal candidates.
Requirements
Required:- Analysis and qualification of escalated alerts (phishing, account compromise, malware, lateral movement)
- Event correlation (SIEM, XDR, EDR, identity, email, network, cloud)
- Alert enrichment (logs, indicators of compromise, threat intelligence)
- Determination of verdict, severity, potential impact and required actions
- Initial mitigation, containment or escalation measures, recommended or initiated per processes
- Documentation of investigations, findings, decisions and actions
- First-level technical analysis of endpoint and network logs and artefacts
- Support and coaching of level 1 SOC analysts on complex cases
- Improvement of detection rules, investigation queries, runbooks and playbooks
- Use of approved AI and automation tools (triage, enrichment, documentation)
Resumen del puesto
Tipo de empleo
Tiempo completo
Habilidades requeridas
Alert Triage and QualificationPhishing Investigation and AnalysisAccount Compromise InvestigationInitial Malware AnalysisLateral Movement Detection and InvestigationSIEM Event CorrelationEDR/XDR Endpoint AnalysisNetwork and Cloud Log AnalysisThreat Intelligence and IOC EnrichmentIncident Severity, Verdict and Impact AssessmentInitial Mitigation, Containment and Escalation ActionsDetection Rule, Investigation Query and Playbook/Runbook ImprovementInvestigation Documentation and ReportingUse of Approved AI and Automation Tools for Triage/Enrichment/Documentation
Empleos similares
Python Developer, API integration of security tools
Maarut
Quebec/Montreal, CAPresencialContratoTiempo completo
hace 10 días
Salesforce Developer
Maarut
Quebec/Montreal, CAPresencialContratoTiempo completo
hace 13 días
AutoCAD Design (Fabrication/Steel Experience)
GenZ Talent Pvt.Ltd
Lahore, PKPresencialContratoTiempo completo230.000 PKR – 300.000 PKR / año
hace 3 horas
Draughtsman / Estimator
GenZ Talent Pvt.Ltd
Lahore, PKPresencialContratoTiempo completo
hace 3 horas
Volontär Datenjournalismus, Fokus Wahlen (m/w/d)
IppenMedia
München, DEPresencialContratoTiempo completo2200 € – 2200 € / año
hace 4 horas
Praktikant Social Media Fußball (m/w/d)
IppenMedia
München, DEPresencialContratoTiempo completo6240 € – 6240 € / año
hace 4 horas