Intermediate Forensics Mechanical Engineer

j s held

Vancouver

Vor Ort

CAD 90.000 - 115.000

Vollzeit

Vor 9 Tagen
Bewerbungsgenerator

Bekomme eine Antwort von diesem Arbeitgeber — ein Lebenslauf und ein Anschreiben, die genau auf die Eigenschaften eingehen, die gesucht werden.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Vanderlande is seeking a Senior SOC Analyst to lead complex investigations and coordinate incident response efforts across customer environments.

You will serve as escalation support for Tier 1, develop detection rules, and mentor junior analysts while aligning with MITRE ATT&CK principles and best practices in threat intelligence.

Qualifikationen

  • 5+ years of experience in cybersecurity, with at least 2 years in a SOC or IR role.
  • Advanced expertise in SIEM, EDR, and forensic tools.
  • Strong understanding of MITRE ATT&CK framework and threat actor TTPs.

Aufgaben

  • Perform advanced analysis of escalated security incidents and support investigation efforts.
  • Act as an escalation point for Tier 1 analysts during incident response activities.
  • Develop and tune detection rules and use cases in SIEM and other platforms.
  • Perform threat hunting based on intelligence and behavioral analysis.
  • Conduct forensic analysis and reverse engineering of malware when needed.
  • Collaborate with threat intelligence teams to enrich investigations.

Kenntnisse

SOC analysis
Incident response
Threat detection
Threat hunting
Forensic analysis
Python
PowerShell
MITRE ATT&CK
Leadership
Communication

Ausbildung

Bachelor's degree in IT/Cybersecurity

Tools

EDR
IDS/IPS
SIEM
SOAR
Network security tools

Jobbeschreibung

About the Role

The Security Operations Center - Tier 2 Analyst will lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation point for Tier 1 analysts, customers or other departments. This role supports incident detection, escalation, and response activities within customer environments, in line with agreed SOC service scope and service level agreements (SLAs). You will have had previous experience in handling escalation from Tier 1 and direct work in security monitoring, threat intelligence, or incident response.

Key Responsibilities
  • Perform advanced analysis of escalated security incidents and support investigation efforts.
  • Act as an escalation point for Tier 1 analysts and provide expert guidance during incident response activities.
  • Develop and tune detection rules and use cases in SIEM and other platforms.
  • Perform threat hunting based on intelligence and behavioral analysis.
  • Conduct forensic analysis and reverse engineering of malware when needed.
  • Collaborate with threat intelligence teams to enrich investigations.
  • Provide strategic recommendations to improve SOC processes and technologies.
  • Mentor junior analysts and contribute to training programs.
  • Participate in detection validation and lessons‑learned activities to enhance SOC detection and response.
Additional Responsibilities
  • Validate complex alerts escalated by Tier 1
  • Determine scope, impact, and severity of confirmed incidents.
  • Perform deep log analysis, forensic investigations, and develop custom detection rules.
  • Implement containment, mitigation and remediation actions in accordance with playbooks and customer agreements
  • Understanding TTPs (tactics, techniques, procedures) of threat actors
  • Ability to develop custom detection rules and correlation logic
  • Analyze data patterns and outliers to identify threat actor behaviors and insider threats.
  • Conduct deep investigations into logs, network telemetry, and endpoint activity.
  • Document findings, actions taken, and recommended next steps.
  • Assist the SOC team during active security incidents by collecting evidence and containing low-severity threats as per playbooks.
  • Follow established runbooks to ensure consistent and compliant response actions.
  • Respond to escalated security incidents requiring advanced analysis.
  • Provide containment recommendations and support remediation.
Access Management
  • Processing user access requests (add, remove, modify) following established workflows.
  • Enforcing least‑privilege principles and role‑based access standards.
  • Conducting periodic access reviews (user accounts, permissions, group memberships).
  • Investigating and escalating suspicious access activities or unauthorized access attempts.
Patch Management
  • Assist with tracking and verifying system patch status as part of vulnerability review activities.
  • Monitor patch‑related alerts (failed deployments, outdated versions) within security tools and coordinate remediation with IT operations.
  • Support the vulnerability management process by validating missing patches identified during scans and escalating high-risk findings.
    (This is aligned with Tier 1’s documented tasks involving vulnerability scans and reporting.)
Reporting & Communication
  • Generate clear, accurate incident reports and daily shift summaries.
  • Communicate event details with internal teams in a professional and timely manner.
  • Recommend improvements to detection rules, response processes, and SOC procedures.
  • Stay current on cyber threat trends, attacker techniques (TTPs), and security best practices.
Requirements
  • 5+ years of experience in cybersecurity, with at least 2 years in a SOC or IR role.
  • Advanced expertise in SIEM, EDR, and forensic tools.
  • Strong understanding of MITRE ATT&CK framework and threat actor TTPs.
  • Experience with scripting and automation (e.g., Python, PowerShell).
  • Ability to lead and manage incident response efforts under pressure.
  • Relevant security certifications from ISC2 or ISACA
  • Excellent communication and leadership skills.
Preferred Qualifications
  • Bachelor’s degree in IT, Cybersecurity, or CS
  • Certifications such as:
  • CompTIA Security+
  • Microsoft SC-200
  • CEH, CySA+
  • GIAC certifications (GSEC, GCIH, GMON)
  • Experience with:
  • EDR, IDS/IPS, and network security tools
  • SIEM/SOAR workflows/playbooks
  • Strong analytical and problem‑solving skills
  • Ability to work under pressure during incidents
  • Team-first mindset and willingness to learn
  • Ability to recognize patterns and anomalies
  • Prior SOC or IR experience
  • Strong analysis and investigation skills
  • Familiarity with threat intelligence and adversary behavior
  • Ability to perform forensic/log analysis
  • More advanced certifications preferred
  • 24/7 SOC environment - day shift with weekend coverage
  • Fast-paced operational setting with tight response timelines
  • Collaboration with cross‑functional IT and security teams

Vanderlande is an Equal Employment Opportunity Employer committed to providing equal employment opportunities to all qualified applicants and employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, national origin, age, disability, genetic information, or any other status protected by applicable law. We are committed to providing reasonable accommodations as required by law.

Salary range

This is a full-time, exempt position, eligible to receive a base salary and to participate in an annual performance bonus program. The salary range listed represents the maximum and minimum starting base pay for this position as of the time of posting. Final salary offered will be determined based on factors including but not limited to the candidate's skills and experience. The annual performance bonus program is preset and not candidate dependent.

Salary range for this position is CAD$90,000 to CAD$115,000.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cybersecurity Analyst – Tier 2
Cybersecurity Analyst – Tier 2

Vanderlande Industries GmbH • Vancouver

Vor Ort
CAD 90.000 - 115.000
Cybersecurity Analyst – Tier 2
Cybersecurity Analyst – Tier 2

Vanderlande • Vancouver

Vor Ort
CAD 90.000 - 115.000
Cybersecurity Analyst – Tier 2
Cybersecurity Analyst – Tier 2

Vanderlande Industries B.V. • Vancouver

Vor Ort
CAD 90.000 - 115.000
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

Vor Ort
CAD 90.000 - 120.000
Remote working available
Flex Office work environment
Annual training and certification
Soc Analyst
Soc Analyst

Altis Technology • Toronto

Vor Ort
CAD 90.000 - 130.000
Remote Senior Incident Response Analyst, MDR
Remote Senior Incident Response Analyst, MDR

Sophos • Milton

Remote
CAD 131.000 - 219.000
Bonus eligibility
Comprehensive benefits
Incident Response Analyst, Digital Forensics & Incident Response
Incident Response Analyst, Digital Forensics & Incident Response

isacybersecurity • Toronto

Remote
CAD 75.000 - 105.000
Flexible sick days
Health plan
Education reimbursement
+3
Cybersecurity Incident Response Commander
Cybersecurity Incident Response Commander

isacybersecurity • Toronto

Hybrid
CAD 135.000 - 180.000
Flexible sick and personal days
Health plan
Education reimbursement
Senior Threat Analyst
Senior Threat Analyst

Sophos • Kanada

Vor Ort
CAD 86.000 - 143.000
Remote-first culture
Flexible work options
SOC Analyst
SOC Analyst

Staffing Inc. • Kanada

Remote
CAD 95.000 - 115.000