Analyste principal en sécurité/Senior Security Analyst
SITA View all jobs
- Montreal, QC
- Permanent
- Full-time
- Collaborate with cross-functional teams and experts (Threat Hunters, Intelligence Analysts, Security Engineers).
- Mentor SOC L1/L2 analysts, ensuring process compliance and updating procedures as needed.
- Monitor, detect, and respond to security alerts across ELK SIEM, EDR/XDR, and other platforms.
- Lead escalated incident response: triage, investigation, remediation, and documentation.
- Oversee SOC L1 ticket queues, ensuring timely resolution, closure, or reassignment.
- Apply frameworks (e.g., MITRE ATT&CK) to document, track, and analyze threats.
- Onboard and validate new security use cases in SIEM and EDR/XDR.
- Conduct host and network forensics to identify malicious patterns and behaviors.
- Share intelligence with SOC peers and security teams to improve detection/response.
- Support SOC Manager with reporting, projects, and administrative tasks.
- Deliver clear shift handover reports to maintain seamless 24/7 SOC coverage.
- Bachelor’s degree in IT or related field, or equivalent experience.
- 3+ years as an L2 SOC Analyst with progression toward senior duties.
- Strong knowledge of TCP/IP networking, protocols, and intrusion detection.
- Hands-on with SIEM (Elastic, Splunk), EDR/XDR, and Threat Intelligence tools.
- Familiar with SOAR, IDS/IPS, and vulnerability tools (Nessus, Qualys).
- Skilled in incident detection, analysis, escalation, and documentation.
- Solid grasp of cyber kill chain and attacker tactics/techniques.
- Experience with ticketing/monitoring systems (e.g., ServiceNow).
- Strong communication, organization, and multitasking skills in English.
- Security certification (e.g., Security+, CySA+, GSEC, ECIH, CISSP) and eagerness to learn new tools.