L3 SOC Analyst - Calgary

Integrity360

Calgary

Hybrid

CAD 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Integrity360 is seeking a Level 3 SOC Analyst to act as the escalation point within the MDR/SOC function in Calgary, providing advanced technical support during complex investigations. You will bring deep operational knowledge of SIEM, EDR, NIDS, SOAR and related monitoring platforms, while guiding Level 2 analysts and collaborating with customers.

The role emphasizes threat analysis, detection tuning, and proactive threat hunting to strengthen client security postures.

Qualifications

  • Experience in Security Operations Centre or MDR environments.
  • Proficient in triage, correlation, investigation and escalation.

Responsibilities

  • Act as the Level 3 escalation point for advanced, complex or high-impact security investigations.
  • Support Level 2 analysts during complex investigations, providing technical guidance and direction.
  • Perform in-depth analysis of security events, alerts, logs, endpoint telemetry, network traffic and other data sources.
  • Lead advanced incident investigations: scoping, containment, eradication and remediation recommendations.
  • Analyze malicious activity, attacker behavior and adversary TTPs.
  • Support customers in optimization and tuning of security monitoring capabilities.
  • Review and improve SIEM, EDR, NIDS, SOAR and other tool configurations to reduce false positives.
  • Contribute to development and refinement of detection use cases, rules and playbooks.
  • Define customer security monitoring strategies based on risk and telemetry.
  • Provide technical recommendations to strengthen customer security posture.
  • Conduct threat hunting and proactive analysis based on indicators and intelligence.
  • Document investigation findings, timelines, containment actions and remediation in clear reports.
  • Prepare and deliver technical reports to customers and internal stakeholders.
  • Monitor trusted sources for emerging threats relevant to customer environments.
  • Contribute to SOC process improvements and knowledge base materials.
  • Develop proficiency in Integrity360’s MDR technologies and services.
  • Mentor Level 1/2 analysts on best practices and investigative methods.

Skills

SIEM
EDR
NIDS
SOAR
DLP
Threat hunting
Incident response
MITRE ATT&CK

Tools

Microsoft Sentinel
Splunk
QRadar
CrowdStrike
Palo Alto

Job description

Title: Level 3 SOC Analyst

Location: Calgary, 5 days a week onsite

Work Hours: 9.00-17.30

Job type: Full-Time Permanent

Salary: Negotiable / DOE

About Us


Integrity360 is a leading independent cybersecurity and PCI specialist operating across Europe, Africa, the Caribbean, and North America. The company has office locations in Ireland, the UK, Bulgaria, Italy, Sweden, Spain, Lithuania, Ukraine, Africa, the Caribbean, and Canada, supported by seven Security Operations Centres (SOCs) located in Dublin, Sofia, Madrid, Stockholm, Rome, Johannesburg and Cape Town.

With over 780 employees, including more than 585 dedicated cybersecurity professionals, Integrity360 delivers a full suite of professional, support, and managed security services. These span the complete cyber risk lifecycle, from identification and prevention to detection, response, and recovery. Integrity360 supports over 3000 mid-market and enterprise organisations across sectors including financial services, insurance, government, healthcare, retail, telecommunications, and utilities.


At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you're ready to take your cyber security career to the next level, we’d love to hear from you.

Job Role / Responsibilities

In this role, you will act as a Level 3 escalation point within the MDR/SOC function, providing advanced technical support to Level 2 analysts during complex or high-severity investigations. You will be expected to bring deep operational knowledge across modern security technologies, including SIEM, EDR, Network Intrusion Detection Systems, SOAR, DLP and related security monitoring platforms.

The Principal SOC Analyst will support the investigation, containment and remediation of advanced threats, ensuring that incidents are analysed in the correct business and technical context. The role requires strong hands‑on experience in security operations, incident response, threat analysis and detection tuning, as well as the ability to work directly with customers and internal stakeholders to improve detection capability and strengthen cyber security posture.

You will contribute to the continuous improvement of the MDR service by supporting the definition of security monitoring strategies, improving detection logic, tuning security technologies, reviewing investigation processes and advising customers on technical optimisation opportunities. A strong understanding of malware behaviour, adversary tactics, techniques and procedures, and emerging threats will be critical to success.

Primary Duties/Responsibilities include:
  • Act as the Level 3 escalation point for advanced, complex or high-impact security investigations.
  • Support Level 2 analysts during complex investigations, providing technical guidance, validation and direction.
  • Perform in-depth analysis of security events, alerts, logs, endpoint telemetry, network traffic and other relevant data sources.
  • Lead advanced incident investigations, including scoping, containment, eradication and remediation recommendations.
  • Analyse malicious activity, suspicious files, attacker behaviour and adversary TTPs.
  • Support customers from a technical perspective in the optimisation, tuning and improvement of their security monitoring capabilities.
  • Review and improve SIEM, EDR, NIDS, SOAR and other security tool configurations to reduce false positives and improve detection quality.
  • Contribute to the development and refinement of detection use cases, correlation rules, alerting logic and investigation playbooks.
  • Support the definition of customer security monitoring strategies based on risk profile, threat landscape and available telemetry.
  • Provide technical recommendations to strengthen customer cyber security posture and improve resilience against current and emerging threats.
  • Conduct threat hunting and proactive analysis based on indicators, behaviours, intelligence and attack patterns.
  • Document investigation findings, evidence, timelines, containment actions and remediation recommendations in a clear and structured manner.
  • Prepare and deliver technical reports to customers, partners and internal stakeholders.
  • Monitor trusted sources for emerging threats, vulnerabilities and adversary activity relevant to customer environments.
  • Contribute to the continuous improvement of SOC processes, procedures, documentation and knowledge base material.
  • Develop and maintain proficiency in Integrity360’s MDR technologies, processes, and service offerings, applying this knowledge to improve customer outcome and service
  • Support mentoring and technical development of Level 1 and Level 2 analysts, promoting best practices, investigative methodologies and operational excellence across the SOC.
Desired Skills
  • Strong hands-on experience in Security Operations Centre or MDR environments.
  • Deep operational knowledge of SIEM, EDR, Network Intrusion Detection Systems, SOAR, DLP and related security monitoring technologies.
  • Strong experience with security event triage, correlation, investigation and escalation.
  • Ability to analyse endpoint, network, identity, cloud and application telemetry in support of complex investigations.
  • Experience with SIEM query languages and detection logic, such as KQL, SPL, Sigma or equivalent.
  • Experience tuning security controls and detection content to improve alert fidelity and reduce false positives.
  • Strong understanding of attacker tactics, techniques and procedures, including MITRE ATT&CK.
  • Ability to perform host-based and network-based threat analysis.
  • Experience analysing packet captures, endpoint artefacts, logs, scripts, documents and potentially malicious files.
  • Strong understanding of incident response lifecycle, including preparation, identification, containment, eradication, recovery and lessons learned.
  • Strong understanding of enterprise network architecture, TCP/IP, firewalls, proxies, VPNs, DNS, email security and cloud environments.
  • Understanding of security protocols, encryption technologies and common authentication mechanisms.
  • Experience supporting customer-facing technical discussions, including investigation reviews, tuning recommendations and posture improvement activities.
  • Ability to manage multiple complex incidents and make effective decisions under pressure.
  • Strong written and verbal communication skills, with the ability to explain technical findings to both technical and non-technical stakeholders.
  • Experience with Microsoft Sentinel, Microsoft Defender, Splunk, QRadar, CrowdStrike, SentinelOne, Palo Alto, Suricata, Zeek, Snort or similar technologies is highly beneficial.
  • Experience with cloud security monitoring across Microsoft Azure, AWS or Google Cloud is beneficial.
  • Experience with threat hunting, detection engineering or purple team activities is beneficial.
    Ability to produce clear technical documentation, investigation reports and customer-facing recommendations.
Certifications/Qualifications
  • Security industry certifications such as GCIH, GCFA, GCIA, GNFA, GCTI, GSEC, CISSP, CySA+, SC-200, AZ-500 or equivalent are highly beneficial.
  • Minimum 5 years of experience in cyber security, including experience in SOC, MDR, incident response, CSIRT or cyber security operations environments.
  • Proven experience handling complex security incidents and supporting advanced investigations.
  • Willingness and ability to undertake training on Integrity360's MDR solutions, platforms and operational methodologies.
  • Working knowledge of SIEM, EDR, SOAR, NIDS, DLP and threat intelligence platforms.

#LI-JL1

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Information Security Operations Lead
Information Security Operations Lead

Jobtailor • Toronto

On-site
CAD 110,000 - 150,000
Senior SOC Analyst
Senior SOC Analyst

Exchange Technology Services Inc. • Winnipeg

On-site
CAD 90,000 - 120,000
Onsite Gym
Employee Share Purchase Plan
RRSP with Company Matching
+1
Senior SOC Analyst
Senior SOC Analyst

Exchange Technology Services • Winnipeg

On-site
CAD 90,000 - 120,000
Competitive salary
RRSP matching
Employee Share Purchase Plan
+4
MONTREAL [Hybrid] - Senior Security Analyst L3
MONTREAL [Hybrid] - Senior Security Analyst L3

QUANTEAM (RAINBOW PARTNERS Group) • Montreal

Hybrid
CAD 80,000 - 100,000
SOC Analyst (5+ years) to investigate incidents using Defender, Arctic Wolf, and Tenable
SOC Analyst (5+ years) to investigate incidents using Defender, Arctic Wolf, and Tenable

S I Systems • Toronto

On-site
CAD 85,000 - 110,000
Senior Information Security Analyst
Senior Information Security Analyst

IKO North America • Mississauga

On-site
CAD 106,000 - 120,000
Competitive compensation
Health care
Challenging workplace
+1
Security Analyst (26-22517)
Security Analyst (26-22517)

Russell Tobin • Regina

On-site
Threat Analyst 3
Threat Analyst 3

Sophos Group • Canada

On-site
CAD 74,000 - 123,000
Manager, Security Incident Response
Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development Corporation • Toronto

On-site
CAD 80,000 - 120,000