JSOC - Cybersecurity Specialist - Incident Response

Community Trust Company

Argentina

Presencial

ARS 1.200.000 - 2.100.000

Jornada completa

14 días+
Generador de candidaturas

Transforma esta oferta en una entrevista: un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Health & wellbeing resources
Paid vacation, personal and sick days
Competitive compensation
Career growth opportunities
Community involvement
Inclusive and collaborative culture

Descripción de la vacante

Questrade Financial Group seeks an experienced SOC Specialist to join its cybersecurity incident response team. You will lead investigations, triage alerts, and coordinate containment and recovery actions across IT and vendor teams. The role involves ongoing threat hunting, playbook improvements, and post-incident reviews.

You will work in a hybrid environment, collaborating with Cybersecurity and IT teams, and you will help mature detection rules, incident timelines, and reporting metrics.

Formación

  • 3+ years of relevant experience in Cybersecurity Incident Response and Threat Hunting in a SOC environment.
  • Experience in creation and fine-tuning of detection rules.
  • Familiarity with integrating security tools via APIs for automation and SOAR concepts.
  • Experience with CrowdStrike Falcon and Elastic Security (KQL, ESQL).
  • Forensic triage across disk, memory, network on multiple OS.

Responsabilidades

  • Collaborate with team on investigations and share technical knowledge.
  • Monitor, analyze and report possible cybersecurity attacks.
  • Investigate and analyze threat indicators.
  • Gather indicators of compromise for threat hunting.
  • Leverage tools (CrowdStrike, Elastic) for analysis of malicious activity.
  • Analyze identified activity to determine TTPs.
  • Conduct data correlation to determine incident impact.
  • Execute containment and eradication per playbooks.
  • Participate in on-call rotations and IR simulations.
  • Coordinate IR with internal teams and third parties.
  • Document incident timelines, evidence, and actions.
  • Produce lessons-learned reports and update playbooks.
  • Provide proactive security investigations across corporate environments.
  • Maintain up-to-date threat intelligence and security frameworks.
  • Communicate findings to stakeholders and track SOC metrics.

Conocimientos

Cybersecurity Incident Response
Threat Hunting
Investigation
Incident Management
Communication under pressure

Educación

GSEC, Security+, CySA+, CEH, CHFI (certifications)

Herramientas

CrowdStrike Falcon
Elastic Security
SIEM
SOAR concepts

Descripción del empleo

JSOC - Cybersecurity Specialist - Incident Response
Job Description

Questrade Financial Group (QFG), through its companies - Questrade, Inc., Questrade Wealth Management Inc., Community Trust Company, Zolo, and Flexiti Financial Inc., provides securities and foreign currency investment, professionally managed investment portfolios, mortgages, real estate services, financial services and more.

Questrade uses cutting-edge technologies to develop innovative products that give customers better, more affordable ways to take control of their money.

We are everything a traditional financial institution is not. At QFG, you will be constantly moving forward, bringing the future of fintech into existence. You will be a part of a collaborative team that cares deeply about our mission and each other. Your team members will help you conquer challenges, push boundaries and discover what you are truly capable of.

At QFG, we have a culture of innovation where technology serves people—both our team and our customers. We see AI as a collaborative and transformative enabler, and we are seeking forward-thinking individuals who can effectively integrate it into their daily work. The ideal candidate will be a catalyst for change, helping us use AI to create a more efficient and rewarding employee experience while also developing cutting-edge solutions that delight and serve our customers. Join us in shaping a future where AI empowers our team to do their best work and helps us deliver unparalleled customer experiences.

This is a place where you can explore, discover and learn with continuous growth. As a diverse and inclusive place to work, with a hybrid working environment you can unleash your creativity and curiosity with no limits. If you share the same sense of infinite possibility, come shape your future at QFG.

What’s in it for you as an employee of QFG?
  • Health & wellbeing resources and programs
  • Paid vacation, personal, and sick days for work-life balance
  • Competitive compensation and benefits packages
  • Career growth and development opportunities
  • Opportunities to contribute to community causes
  • Work with diverse team members in an inclusive and collaborative environment
We’re looking for our next SOC Specialist. Could It Be You?

Your contribution delivering sustainable and measurable results in the following areas will be very important:

Identifying and responding to cyber threats - safeguarding our company's infrastructure and data. You will be primarily involved in supporting the alert development cycle, triaging and investigating alerts, managing the full incident response lifecycle (investigation, containment, eradication, and recovery) and collecting and tracking metrics for reporting. You will be working alongside internal customers and our vendor support teams to ensure we are utilizing our security tools in accordance with corporate policies and growing business needs. You will work closely with Cybersecurity and IT teams to align priorities and execute plans for new initiatives, as well as contribute to process improvements and build documentation for new tools.

You will:

  • Collaborate with team members on investigations and share technical knowledge.
  • Monitor, analyze and report possible cybersecurity attacks.
  • Investigate and perform analysis of threat indicators.
  • Gather Indicators of compromise and any relevant data to use with threat hunting activities.
  • Leverage security tools (Elastic, CrowdStrike and more) for analysis to identify malicious activities.
  • Analyze identified malicious activity to determine Tactics, Techniques and Procedures.
  • Conduct research, analysis and correlate gathered data from various resources to determine the impact of the incident.
  • Execute containment and eradication actions following established playbooks.
  • Participate in on-call and hands-on scheduled shift rotations, including outside of business hours.
  • Support coordination of Security Incident Response and investigation with other internal teams and 3rd party providers.
  • Document incident timelines, evidence, and actions taken for post-incident review.
  • Perform post-incident reviews and produce lessons-learned reports.
  • Contribute to maintaining and improving incident response playbooks and runbooks.
  • Participate in tabletop exercises and IR simulations.
  • Provide proactive security investigation and searches on corporate environments to detect malicious activities.
  • Maintain up-to-date understanding of security threats, countermeasures, security tools, cloud security and SaaS technologies.
  • Maintain technical proficiency through training, keeping up with industry best practices, and security frameworks.
  • Communicate investigation findings to technical stakeholders and contribute to reporting.
  • Contribute to tracking SOC operational metrics (MTTD, MTTR, alert fidelity).
So are YOU our next SOC Specialist? You are if you have…
  • 3+ years of relevant experience in performing Cybersecurity Incident Response and Threat Hunting activities in a complex incident management or Security Operations Center environment.
  • Experience in the creation and fine-tuning of detection rules.
  • Familiarity with integrating security tools via APIs for automation, and familiarity with Security Orchestration, Automation, and Response (SOAR) concepts.
  • Experience with investigations and incident response using EDR tools such as CrowdStrike Falcon and SIEM tools such as Elastic Security (KQL, ESQL, Timeline analysis).
  • Experience with forensic triage (disk, memory, network) and multiple operating systems (Mac, Linux, Windows).
  • Experience with contributing to SOC processes, playbooks, SIEM correlation rules, and incident reports.
  • Experience in incident management and communication under pressure.
  • Knowledge of NIST Cybersecurity Framework, MITRE ATT&CK.
  • Knowledge of security products and device monitoring tools including Firewalls, IDS/IPS, Phishing and e-mail security, content filtering, DDoS, WAF, and more.
Brownie points if you have...
  • GSEC, Security+, CySA+, CEH, CHFI or similar relevant certifications.

At Questrade Financial Group of Companies, with multiple office locations around the world, we are committed to fostering a diverse, inclusive and accessible work environment. This is an environment where individuals are treated with dignity and respect. Here, the unique skills and experience you bring will be valued. You will be supported and motivated, so that you can harness your unlimited potential. Our team reflects the diversity of the communities we serve and operate in. Having a collaborative and diverse team helps us push boundaries to bring the future of fintech into existence—not only for the benefit of our customers, but for those who build their career with us.

Questrade Financial Group of companies Applicant Tracking System utilizes artificial intelligence (AI) for application screening. The AI system operates on predetermined criteria, with final decisions subject to human review.

Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment/selection process, please let us know and we will work with you to meet your needs.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Principal Quality Assurance Engineer
Principal Quality Assurance Engineer

Community Trust Company • Argentina

Híbrido
ARS 178.643.000 - 267.965.000
Hybrid work environment
Career growth opportunities
Diversity & inclusion
Principal Quality Assurance Engineer
Principal Quality Assurance Engineer

Questrade Financial Group • Argentina

Híbrido
ARS 178.643.000 - 282.852.000
Health & wellbeing resources
Vacation, personal, and sick days
Competitive compensation
+4
Hybrid SOC Incident Response Specialist
Hybrid SOC Incident Response Specialist

Community Trust Company • Argentina

Híbrido
ARS 1.200.000 - 2.100.000
Health & wellbeing resources
Paid vacation, personal and sick days
Competitive compensation
+3
Senior Data Engineer
Senior Data Engineer

Flexiti • Argentina

Híbrido
ARS 1.200.000 - 1.500.000
Health & wellbeing resources and programs
Paid vacation, personal, and sick days
Competitive compensation and benefits packages
+1
Senior Spam Data Engineer
Senior Spam Data Engineer

JobCubby • Córdoba

Híbrido
ARS 1.200.000 - 2.400.000
Competitive compensation
Comprehensive benefits
Global collaboration opportunities
Senior Spam Data Engineer
Senior Spam Data Engineer

proofpoint • Argentina

Presencial
ARS 1.800.000 - 2.400.000
Senior Spam Data Engineer
Senior Spam Data Engineer

Proofpoint • Córdoba

Presencial
ARS 1.200.000 - 2.400.000
Competitive compensation
Comprehensive benefits
Global collaboration opportunities
Senior Security Analyst — Remote Threat & Incident Response
Senior Security Analyst — Remote Threat & Incident Response

Netrix LLC • Buenos Aires

Presencial
Senior Security Analyst
Senior Security Analyst

Netrix LLC • Buenos Aires

Presencial
Senior Quant Developer
Senior Quant Developer

SimCorp • Buenos Aires

Híbrido
ARS 2.400.000 - 4.200.000