IT Secuity analyst

Maarut Inc

Montreal (administrative region)

On-site

CAD 85,000 - 110,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Maarut Inc. is seeking an IT security analyst for its SOC at level 2, focusing on investigation of escalated alerts and threat handling.

You will qualify phishing, account compromise, malware or lateral movement cases, and coordinate with other teams to implement initial containment measures. As the technical escalation point for Level 1 SOC analysts, you will document investigations, determine verdict, severity and impact, and contribute to improving detection rules and runbooks.

Responsibilities

  • Investigate escalated alerts in phishing, account compromise, malware or lateral movement cases
  • Correlate events across SIEM, XDR, EDR, identity, email, network and cloud platforms
  • Enrich alerts with logs, indicators of compromise and threat intelligence
  • Determine verdict, severity and potential impact of incidents
  • Recommend or initiate first mitigation, containment or escalation actions per processes
  • Document investigations, findings, decisions and actions
  • Provide first-level technical analysis of endpoint and network logs and artefacts
  • Support and coach Level 1 SOC analysts on complex cases
  • Improve detection rules, investigation queries, runbooks and playbooks
  • Utilize approved AI and automation tools for triage, enrichment and documentation

Job description

  • The client is looking for an IT security analyst for its SOC, positioned at level 2: alerts reach this person already escalated by level 1, and the person in turn acts as the technical escalation point for those analysts.
  • The work centres on investigation: qualifying phishing, account compromise, malware or lateral movement cases, correlating events across several platforms, then enriching them with logs, indicators of compromise and threat intelligence.
  • The person determines verdict, severity and impact, then recommends or initiates first measures according to established processes, with incident response remaining initial and carried out with other teams.
  • The form title specifies no level, while the full set of responsibilities describes a level 2 role.
  • The Talents and qualifications section is empty: no degree, certification, language or named tool is required, so assessment rests entirely on the activity profile.
  • Target candidate: a QA professional with at least 10 years in IT, including 5 years in testing, who has coordinated testing within agile teams and uses JIRA, XRAY, Cypress and Playwright in recent mandates.
  • Group insurance exposure or an integration project will set apart otherwise equal candidates.
Requirements

Required:

  • Analysis and qualification of escalated alerts (phishing, account compromise, malware, lateral movement)
  • Event correlation (SIEM, XDR, EDR, identity, email, network, cloud)
  • Alert enrichment (logs, indicators of compromise, threat intelligence)
  • Determination of verdict, severity, potential impact and required actions
  • Initial mitigation, containment or escalation measures, recommended or initiated per processes
  • Documentation of investigations, findings, decisions and actions
  • First-level technical analysis of endpoint and network logs and artefacts
  • Support and coaching of level 1 SOC analysts on complex cases
  • Improvement of detection rules, investigation queries, runbooks and playbooks
  • Use of approved AI and automation tools (triage, enrichment, documentation)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst - Tier 2
Cybersecurity Analyst - Tier 2

Vanderlande • Vancouver

On-site
CAD 90,000 - 130,000
Security Operations Analyst
Security Operations Analyst

F12.net • Surrey

On-site
CAD 70,000 - 100,000
L3 SOC Analyst - Calgary
L3 SOC Analyst - Calgary

Integrity360 • Calgary

On-site
CAD 80,000 - 110,000
Cybersecurity Analyst – Tier 2
Cybersecurity Analyst – Tier 2

Vanderlande Industries GmbH • Vancouver

On-site
CAD 90,000 - 115,000
SOC Analyst
SOC Analyst

Acestack • Toronto

Hybrid
CAD 70,000 - 110,000
Cybersecurity Analyst – Tier 2
Cybersecurity Analyst – Tier 2

Vanderlande • Vancouver

On-site
CAD 90,000 - 115,000
SOC Manager
SOC Manager

ixolabs.ai • Ottawa

On-site
CAD 82,656,000 - 130,872,000
Incident Response Specialist
Incident Response Specialist

Integriti • Toronto

On-site
CAD 90,000 - 130,000
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Security Operations Center Analyst
Security Operations Center Analyst

Paymentus • Richmond Hill

On-site
CAD 75,000 - 105,000