L3 SOC Analyst / Incident Responder

act digital

Montreal (administrative region)

On-site

CAD 90,000 - 120,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Remote working available
Flex Office work environment
Annual training and certification

Job summary

A technology consulting firm in Montreal is seeking an experienced L3 SOC Analyst to lead incident response efforts and enhance threat detection capabilities. In this role, you will monitor security events, investigate incidents, and collaborate with IT teams to strengthen the security posture. The ideal candidate has 5+ years of experience in a SOC environment, strong technical skills in SIEM and incident response, and a proactive mindset. This position allows for a hybrid work setup, balancing on-site and remote work.

Qualifications

  • 5+ years of experience in a SOC environment with incident response focus.
  • Proven track record of handling complex security incidents.
  • Strong understanding of network protocols and malware analysis.
  • Strong knowledge of MITRE ATT&CK, NIST frameworks, and threat intelligence concepts.

Responsibilities

  • Monitor and analyze security events using SIEM, EDR, and firewalls.
  • Lead incident response efforts and coordinate with teams.
  • Perform in-depth forensic analysis on compromised systems.
  • Proactively hunt for hidden threats in the network.
  • Collaborate with the SOC team to improve detection capabilities.
  • Provide mentorship to junior SOC analysts and contribute to post-incident reports.
  • Develop and maintain incident response playbooks.
  • Collaborate with IT and security teams to strengthen security posture.

Skills

SIEM platforms (e.g., Splunk, QRadar)
Incident response
Advanced threat detection
Scripting languages (Python, PowerShell)
Problem-solving
Strong communication skills

Education

Bachelor’s degree in Computer Science, Information Security, or a related field

Tools

EDR tools
Firewalls
Threat intelligence platforms
EDR tools
Python
PowerShell

Job description

Act Digital is a technology consulting and expertise firm founded in 2006. Our mission is to support our clients with their technical and organizational cybersecurity challenges. Our offering is structured around the following areas of expertise:

  • Security Management
  • Architecture and Integration
  • Audit and Penetration Testing
  • Cyber Defense

We are an international group with 6,500 employees and operations in 12 countries. Our success depends on the development and fulfillment of each employee, and we place great importance on providing the best possible working conditions:

  • Remote working is available for a large part of our assignments
  • A Flex Office work environment available to everyone at all times to foster communication and collaboration
  • Communities of experts to share and disseminate skills within the group
  • Project management and local HR support
  • Training and certification offered annually
  • Promotion of our consultants\' expertise
  • Strong openness to occasional or long-term international mobility

act digital Canada is one of our newest subsidiaries, created in 2023. We have our offices located in downtown Montreal, directly connected to the city\'s metro network.

Job Description

We are looking for an experienced L3 SOC Analyst / Incident Responder to join our cybersecurity team. In this role, you will be responsible for leading advanced threat detection, incident response activities, and driving the continuous improvement of our security operations. You will be a key player in protecting our clients digital assets from sophisticated cyber threats. (3 days on site, 2 day on remote)

Key Responsibilities:

Advanced Threat Detection: Monitor and analyze security events from various sources, including SIEM, EDR, NDR, firewalls, and other protection systems. Identify and respond to advanced persistent threats (APTs) and complex security incidents.

Incident Response: Lead incident response efforts, including investigation, containment, eradication, and recovery. Coordinate with other teams to manage and mitigate security incidents, ensuring minimal impact on business operations.

Forensics and Analysis: Perform in-depth forensic analysis on compromised systems, including malware analysis, network traffic analysis, and log analysis. Document findings and provide detailed incident reports.

Threat Hunting: Proactively hunt for hidden threats in the network, using threat intelligence, behavioral analysis, and anomaly detection techniques. Identify and mitigate potential security risks before they escalate.

Security Improvements: Collaborate with the SOC team to continuously improve detection capabilities, including tuning and optimizing SIEM rules, developing custom scripts, and integrating new tools and technologies.

Training and Mentorship: Provide guidance and mentorship to junior SOC analysts (L1/L2), sharing knowledge and best practices for incident response and threat detection.

Post-Incident Reporting: Prepare detailed post-incident reports that include root cause analysis, impact assessments, and recommendations for future prevention measures. Communicate findings to senior management and relevant stakeholders.

Incident Playbooks: Develop and maintain incident response playbooks, ensuring they are up-to-date and aligned with the latest threat landscape and industry best practices.

Collaboration: Work closely with other IT and security teams, including vulnerability management, IT operations, and network security, to strengthen the organization’s overall security posture.

Qualifications

Experience:

  • 5+ years of experience in a SOC environment, with a focus on incident response and advanced threat detection.
  • Proven track record of handling complex security incidents and conducting forensic investigations.

Technical Skills:

  • Expertise in SIEM platforms (e.g., Splunk, QRadar), IDS/IPS, firewalls, and endpoint detection and response (EDR) tools.
  • Proficiency in scripting languages (e.g., Python, PowerShell) for automation and custom detection use cases.
  • Strong understanding of network protocols, malware analysis, and cybersecurity frameworks (e.g., MITRE ATT&CK, NIST).
  • Experience with threat hunting techniques and tools, as well as familiarity with threat intelligence platforms.

Soft Skills:

  • Excellent problem-solving skills and the ability to work under pressure during high-stress incidents.
  • Strong communication skills, capable of explaining technical issues to both technical and non-technical stakeholders.
  • A proactive mindset with a passion for staying current with the latest cybersecurity trends and threats.

Education:

  • Bachelor’s degree in Computer Science, Information Security, or a related field is preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Montréal [Hybrid] - L3 CSIRT SOC Analyst
Montréal [Hybrid] - L3 CSIRT SOC Analyst

QUANTEAM - North America (RAINBOW PARTNERS Group) • Montreal (administrative region)

Hybrid
CAD 90,000 - 150,000
MONTREAL [Hybrid] - Senior Security Analyst L3
MONTREAL [Hybrid] - Senior Security Analyst L3

QUANTEAM (RAINBOW PARTNERS Group) • Montreal

On-site
CAD 80,000 - 100,000
L3 SOC Analyst - Calgary
L3 SOC Analyst - Calgary

Integrity360 • Calgary

On-site
CAD 80,000 - 110,000
Soc Analyst
Soc Analyst

Altis Technology • Toronto

On-site
CAD 90,000 - 130,000
Cybersecurity Analyst – Tier 2
Cybersecurity Analyst – Tier 2

Vanderlande Industries GmbH • Vancouver

On-site
CAD 90,000 - 115,000
Security Analyst
Security Analyst

EIZIE • West Hawk Lake

On-site
CAD 80,000 - 110,000
Competitive salary
Health and dental benefits
Professional development
+5
Cybersecurity Analyst - Tier 2
Cybersecurity Analyst - Tier 2

Vanderlande • Vancouver

On-site
CAD 90,000 - 130,000
Incident Response Lead (Cyber)
Incident Response Lead (Cyber)

CyberClan • Canada

On-site
CAD 100,000 - 130,000
Manager, Security Incident Response
Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development Corporation • Toronto

On-site
CAD 80,000 - 120,000
ANALYSTE SÉCURITÉ (SOC)
ANALYSTE SÉCURITÉ (SOC)

Chrome Technologies • Montreal (administrative region), Longueuil

On-site
CAD 70,000 - 100,000