RESPONSIBILITIES
- Monitor IT security events and alerts generated by SIEM platforms.
- Analyze security alerts related to:
- Intrusion Detection Systems (IDS)
- Antivirus (AV) and malware infections
- Endpoint Detection and Response (EDR) incidents
- Deception technologies and other security monitoring tools
- Perform daily alert triage and investigations to determine true positives versus false positives.
- Use contextual information and threat intelligence to assess potential security threats.
- Escalate security incidents appropriately and in a timely manner.
- Clearly document investigation activities, findings, and escalation steps.
- Recommend detection mechanisms and improvements related to exploit attempts, intrusions, and security incidents.
- Support incident response and remediation efforts.
REQUIREMENTS
Mandatory
- Experience managing IT infrastructure security events and incidents.
- Strong understanding of:
- TCP/IP fundamentals
- Network-level exploits
- Operating system-level exploits
- Proxy logs
- Operating system logs
- Strong analytical and problem-solving skills.
- Excellent verbal and written communication skills.
- Demonstrated willingness to learn and develop technical expertise.
- Bilingual (required).
Nice to Have
- Knowledge of SIEM solutions such as:
- Splunk
- Microsoft Sentinel
- Microsoft EDR
- Knowledge of network security technologies such as:
- Sourcefire IDS/IPS
- Cisco security solutions
- Firewalls
- Proxies
Pay: $100,000.00-$110,000.00 per year
Ability to commute/relocate:
- Montréal, QC: reliably commute or plan to relocate before starting work (preferred)
Language:
- French (preferred)
- English (required)
Work Location: In person