Endpoint Security Specialist

Bell Cyber

Mississauga

On-site

CAD 90,000 - 120,000

Full time

38 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Bell Cyber in Mississauga is seeking an Endpoint Security Specialist to admin endpoint security platforms, investigate threats, and strengthen protection across workstations and servers. You will work with the CIC, IT teams and customers to support threat detection, containment and remediation.

You will deploy agents, tune policies and coordinate incident response, while integrating telemetry with SIEM and ServiceNow. A strong background in Windows security and scripting is preferred.

Qualifications

  • 3+ years of cybersecurity or endpoint administration experience.
  • Hands-on administration with at least one of CrowdStrike Falcon, Defender for Endpoint or SentinelOne.
  • Experience deploying agents and managing policies.
  • Knowledge of Windows security; macOS/Linux a plus.

Responsibilities

  • Deploy, configure and maintain endpoint security platforms and policies.
  • Investigate alerts and coordinate containment and remediation.
  • Conduct proactive threat hunting and refine detection queries and rules.
  • Integrate telemetry with SIEM, ticketing and automation tools; document work in ServiceNow.
  • Support endpoint hardening, onboarding and operational reporting.

Skills

Threat hunting
Incident response
Troubleshooting
Documentation

Education

Post-secondary education in cybersecurity or IT

Tools

CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne
SIEM
ServiceNow
PowerShell
Python
KQL

Job description

Have hands-on experience with CrowdStrike Falcon, Microsoft Defender for Endpoint and/or SentinelOne? Join Bell Cyber and help protect our organization and customers against evolving cyber threats.


About the role

As an Endpoint Security Specialist, you'll administer endpoint security platforms, investigate threats, and strengthen protection across workstations and servers. Working closely with our Cyber Intelligence Centre (CIC), IT teams and customers, you'll support threat detection, containment and remediation.


What you'll do


  • Deploy, configure and maintain endpoint security platforms, ensuring agent health, protection coverage and effective security policies.

  • Investigate endpoint alerts, analyze suspicious activity and coordinate containment, remediation and recovery.

  • Conduct proactive threat hunting and refine detection queries and rules.

  • Tune security policies, manage approved exceptions and troubleshoot performance or compatibility issues.

  • Integrate endpoint telemetry and workflows with SIEM, ticketing and automation tools, maintaining accurate records in ServiceNow.

  • Support endpoint hardening, customer onboarding, technical documentation and operational reporting.


What you bring


  • Typically 3+ years of relevant cybersecurity or endpoint administration experience.

  • Hands-on administration and operational experience with at least one of CrowdStrike Falcon, Microsoft Defender for Endpoint or SentinelOne. Experience with multiple platforms is preferred.

  • Experience deploying agents, managing policies, investigating alerts and supporting incident response.

  • Practical knowledge of Windows endpoint and server security; macOS and Linux experience is an asset.

  • Understanding of EDR, malware, ransomware, attacker techniques and the incident response lifecycle.

  • Ability to use query languages or scripting tools such as KQL, PowerShell or Python for investigations, reporting or automation.

  • Strong troubleshooting, communication and documentation skills.

  • Post-secondary education in cybersecurity, IT, computer science or a related discipline, or equivalent practical experience.


Experience in an MSSP, SOC or enterprise security environment, along with relevant vendor training or cybersecurity certifications, is an asset.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Endpoint Security Engineer: Threat Detection & Remediation
Endpoint Security Engineer: Threat Detection & Remediation

Bell Cyber • Mississauga

On-site
CAD 90,000 - 120,000
Cybersecurity Tools Lead – Microsoft Defender (MDE, MDI, MDCA)
Cybersecurity Tools Lead – Microsoft Defender (MDE, MDI, MDCA)

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Calgary

On-site
CAD 110,000 - 150,000
Cybersecurity Technical Lead - CrowdStrike, Proofpoint, MDE, MDI, and MDCA
Cybersecurity Technical Lead - CrowdStrike, Proofpoint, MDE, MDI, and MDCA

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Calgary

On-site
CAD 120,000 - 160,000
Microsoft Defender Suite Admin
Microsoft Defender Suite Admin

LanceSoft, Inc. • Calgary

On-site
CAD 110,000 - 140,000
Incident Management Specialist
Incident Management Specialist

PwC Canada • Ottawa

On-site
CAD 120,000 - 160,000
Senior Security Analyst
Senior Security Analyst

Mindlance • Toronto

On-site
CAD 90,000 - 120,000
IT Security Administrator
IT Security Administrator

ROBINSON • Winnipeg

On-site
CAD 70,000 - 100,000
Analyst I, Falcon Complete (Remote, PST/MST)
Analyst I, Falcon Complete (Remote, PST/MST)

CrowdStrike • Calgary

On-site
CAD 90,000 - 135,000
Wellness programs
Vacation & holidays
Parental leaves
+4
Cyber Security Analyst
Cyber Security Analyst

Arsenault • Ottawa

On-site
CAD 85,000 - 110,000
Analyst I, Falcon Complete (Remote, PST/MST)
Analyst I, Falcon Complete (Remote, PST/MST)

CrowdStrike • Vancouver

On-site
CAD 90,000 - 135,000
Market leader compensation & equity
Wellness programs
Vacation & holidays
+5