Security Operations Center (SOC) Analyst
Why this role matters
Our clients trust us to keep them secure and productive. As a SOC Analyst, you’ll monitor and remediate security alerts across multiple client environments, respond to cyber incidents, escalate effectively, and close the loop with clear documentation and Security RCAs. Reporting to the Director of Central Services, you’ll work closely with our Service Desk, NOC, Client Solutions, and Professional Services teams to uphold our security baseline, improve response processes, and reduce recurring support needs through proactive remediation and automation.
What you’ll do
- Remediate, monitor and triage alerts: Monitor the Security Queue, CW Automate, and security mailboxes. Classify and remediate general alerts, confirm business impact, create and assign tickets when required, escalate complex or critical alerts according to established procedures, and document every response and resolution in the ticketing system.
- CVE and vulnerability intake: Review security forums, message boards, community pages, and vendor press pages for imminent threats. Triage CVE vulnerability notifications by creating tickets and assigning them to NOC Analysts when necessary.
- Incident response: Identify the severity of each cyber incident, remediate standard incidents, and escalate major incidents to Expert Analysts according to the escalation process. During a major incident, provide support and guidance to the Tech Lead and Communicator. Complete a Security RCA for every standard and major cyber incident.
- Security tooling, standards and baselines: Help develop and regularly evaluate the Security Baseline for Northern Computer and all managed clients. Maintain efficient baseline auditing processes and security-product SOPs, complete semi-annual top-to-bottom security audits and remediate baseline issues, support security-tool deployments, and complete 60-day security check-ups following security projects.
- Security change coordination: Communicate security changes internally and collaborate with other departments to manage those changes effectively. Keep relevant documentation, calendars, and ticket notes current in real time, and promptly communicate schedule conflicts or outstanding work.
- Internal Cybersecurity support: Provide input to the Client Solutions and Professional Services teams to ensure that security standards and the Security Baseline are upheld. Support client security meetings by providing cybersecurity reports when required.
- Cross-team collaboration: Work closely with the Service Desk and NOC, communicate issues and scheduling conflicts promptly, and collaborate with other departments during wider incidents and security changes.
- Automation and continuous improvement: Find and use efficient or automated methods for recurring work, automate alert resolution whenever practical, and proactively reduce, simplify, or eliminate end-user support requests.
- Additional company support: As requested by the Director of Central Services, assist the Service Desk, support internal IT operations, and participate in project-based security work. Provide after-hours and on-call support as scheduled.
What you bring
- Experienced MSP NOC/SOC professional: 3+ years of experience working in a NOC, SOC, or closely related security operations role within a managed service provider environment, with demonstrated experience triaging alerts across multiple client environments, responding to incidents, documenting outcomes, and escalating effectively.
- Tool awareness: Familiarity with EDR/AV, phishing simulators, basic SIEM concepts, and ticketing workflows (e.g., ConnectWise Manage/Automate).
- Methodical triage: Comfort applying priority rules, confirming impact, and escalating on time—under pressure and in afterhours rotations when needed.
- Documentation discipline: Clear ticket notes and postincident writeups; curiosity to turn fixes into repeatable standards.
- Education and professional development: A cybersecurity certificate, or a college or university certificate, diploma, or degree in cybersecurity or a related field, is preferred. You stay current on relevant threats, trends, tools, and security products.
- Experienced with Microsoft 365 security controls, identity hygiene (MFA/conditional access), and email compromise playbooks
Nice-to-haves
- Basic scripting or workflow-automation experience, such as PowerShell or Rewst
- Hold or be working towards relevant industry certifications, such as CompTIA Security+, ISC2, or Microsoft security certifications
What success looks like: You keep security-tool deployments and configurations aligned with standards, leave no alerts unactioned, resolve assigned cybersecurity alerts and Service Desk security tickets, support security-tool deployments, participate in client security meetings, and create automation that saves the team measurable time.
Location, Schedule & flexibility
This role is based in our Edmonton office and follows a hybrid work arrangement that combines in-office and work-from-home days. It also participates in scheduled after-hours and on-call rotations and occasional client maintenance windows.
What we offer
Hybrid work arrangement, combining in-office and work-from-home-days. Extended health and dental coverage, life and disability insurance, Health & Wellness Spending Accounts, virtual healthcare, Employee & Family Assistance Program, and a Group Retirement Savings Plan.