Montréal [Hybrid] - L3 CSIRT SOC Analyst

QUANTEAM - North America (RAINBOW PARTNERS Group)

Montreal (administrative region)

Hybrid

CAD 90,000 - 150,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Quanteam is seeking aSenior Security Analyst (L3) to join a major international bank client in Montreal. The role focuses on leading investigations, optimizing SIEM use cases, and guiding junior analysts within a hybrid on-site schedule.

The candidate will analyze logs, network traffic, and forensic artifacts across Windows and Linux environments, while collaborating with IR, Network, Cloud, and IAM teams to strengthen security controls.

Qualifications

  • Minimum 7 years of experience in a L3 SOC or equivalent cybersecurity role.
  • Strong hands-on expertise with SIEM platforms (Splunk/ELK) including query writing, correlation rules, and dashboards.

Responsibilities

  • Lead the investigation and response to complex and high-severity security incidents (APT, lateral movement, malware).
  • Perform deep-dive analysis using SIEMs to identify root causes and attacker behaviors.
  • Act as escalation point for L2 analysts with guidance and remediation recommendations.
  • Develop and maintain SIEM use cases, detection rules, dashboards, and alerts.
  • Conduct threat hunting based on intelligence and observed techniques.
  • Use Python/Bash to support investigations and automation.
  • Provide expert-level analysis of logs, network traffic, endpoint activity, and forensic artifacts.
  • Collaborate with IR, Network, Infrastructure, Cloud, IAM, and external partners.
  • Contribute to post-incident reviews and improvements to security controls.
  • Maintain understanding of architecture, attack surface, and evolving threat landscape.
  • Support SOC projects and tooling improvements.
  • Document incidents and findings clearly.
  • Participate in on-call rotations for 24/7 operations.
  • Adhere to security policies and procedures.

Skills

SOC experience
SIEM (Splunk/ELK)
Incident response
Threat hunting
Python
Bash
Windows & Linux
Network security
MITRE ATT&CK
Communication
Mentoring
On-call readiness

Tools

Splunk
ELK
EDR/XDR
Firewalls
IDS/IPS
Proxies
VPNs
PCAP analysis

Job description

As the founding entity of RAINBOW PARTNERS, Quanteam is a consulting firm specializing in Banking, Finance, and Financial Services. Guided by our core values of closeness, teamwork, diversity, and excellence, our team of 1,000 expert consultants, representing 35 different nationalities, collaborates across 10 international offices: Paris, Lyon, New York, Montreal, London, Brussels, Geneva, Lisbon, Porto, and Casablanca.

We are currently seeking a Senior Security Analyst (L3) to join one of our clients in the financial sector, a major international bank based in Montreal

Key Responsibilities:

The responsibilities of this role include, but are not limited to:

  • -Lead the investigation and response to complex and high-severity security incidents, including advanced persistent threats (APT), lateral movement, and sophisticated malware activity.
  • -Perform deep-dive analysis using SIEM platforms (e.g., Splunk, ELK) and other security tools to identify root causes and attacker behaviors.
  • -Act as an escalation point for L2 analysts, providing technical guidance, validation of findings, and recommended remediation actions.
  • -Develop, optimize, and maintain SIEM use cases, detection rules, dashboards, and alerts to improve threat visibility and reduce false positives.
  • -Conduct threat hunting activities based on intelligence, hypotheses, and observed attacker techniques.
  • -Leverage scripting and automation (e.g., Python, Bash) to support investigations, data enrichment, and SOC efficiency.
  • -Provide expert-level analysis of logs, network traffic, endpoint activity, and forensic artifacts.
  • -Collaborate with internal teams (IR, Network, Infrastructure, Cloud, IAM) and external partners as required during incident response.
  • -Contribute to post-incident reviews, lessons learned, and recommendations to improve security controls and processes.
  • -Maintain a strong understanding of the organization’s technical architecture, attack surface, and evolving threat landscape.
  • -Support SOC projects, tooling improvements, and security initiatives.
  • -Ensure accurate documentation of incidents, investigations, and technical findings.
  • -Participate in on-call or shift rotations as required to support 24/7 operations.
  • -Adhere to all internal security policies, standards, and procedures.
Required Qualifications and Skills
  • -Minimum 7 years of experience in a L3 Security Operations Center (SOC) or equivalent cybersecurity role.
  • -Strong hands-on expertise with SIEM platforms, such as Splunk and/or ELK, including query writing, correlation rules, and dashboards.
  • -Advanced knowledge of security technologies, including network security (firewalls, IDS/IPS, proxies, VPNs), endpoint security solutions (EDR/XDR), and email security and data protection tools.
  • -Strong understanding of incident response processes, log analysis, and network traffic analysis (PCAP).
  • -Solid knowledge of network protocols and architectures, including the OSI model, TCP/IP, DNS, HTTP/S, and SMTP.
  • -In-depth understanding of attack techniques and threat actor behaviors, aligned with frameworks such as MITRE ATT&CK.
  • -Proven experience working with Windows and Linux environments, including the detection of compromise and abnormal behavior.
  • -Strong scripting skills (Python, Bash) used for automation and investigation support.
  • -Demonstrated security mindset, with a proactive and adversarial approach to threat detection and defense.
  • -Ability to analyze complex security events and clearly communicate findings to both technical and non-technical stakeholders.
  • -Strong analytical, problem-solving, and decision-making skills under pressure.
  • -Capability to mentor junior analysts and contribute to SOC maturity.
  • -Awareness of adjacent security domains (Forensics, Threat Intelligence, Vulnerability Management, Red Team).
  • -Ability to manage multiple investigations simultaneously in a high-paced environment.
  • -Strong collaboration and communication skills.
Working conditions
  • -Candidate must be located or willing to relocate to Montreal
  • -Hybrid 3 days on-site per week
  • -Participating in on-call and support hours
  • -Possibility to work on the morning or day shift, participating in weekend operations
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

MONTREAL [Hybrid] - Senior Security Analyst L3
MONTREAL [Hybrid] - Senior Security Analyst L3

QUANTEAM (RAINBOW PARTNERS Group) • Montreal

On-site
CAD 80,000 - 100,000
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
MONTREAL [Hybrid] - Network Security Engineer
MONTREAL [Hybrid] - Network Security Engineer

QUANTEAM (RAINBOW PARTNERS Group) • Montreal (administrative region)

On-site
CAD 90,000 - 130,000
Montréal [Hybrid] - Senior Linux Systems Administrator
Montréal [Hybrid] - Senior Linux Systems Administrator

QUANTEAM - North America (RAINBOW PARTNERS Group) • Montreal (administrative region)

On-site
CAD 100,000 - 150,000
Information Security Analyst
Information Security Analyst

Glocomms • Montreal (administrative region)

On-site
CAD 70,000 - 110,000
Bonus opportunity
Generous paid time off
Wellness reimbursement programs
+3
MONTREAL [Hybrid] - Network Engineer Bilingual FR/EN
MONTREAL [Hybrid] - Network Engineer Bilingual FR/EN

QUANTEAM (RAINBOW PARTNERS Group) • Montreal

On-site
CAD 80,000 - 100,000
MONTREAL [Hybrid] - Senior Network Engineer (L3)
MONTREAL [Hybrid] - Senior Network Engineer (L3)

QUANTEAM - North America (RAINBOW PARTNERS Group) • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
ANALYSTE SÉCURITÉ (SOC) Québec, Montréal ou Longueuil (hybride) 2026-09-24
ANALYSTE SÉCURITÉ (SOC) Québec, Montréal ou Longueuil (hybride) 2026-09-24

Chrome Technologies • Montreal (administrative region), Longueuil

Hybrid
CAD 70,000 - 110,000
Senior SOC Analyst L3 - Hybrid (Montreal)
Senior SOC Analyst L3 - Hybrid (Montreal)

QUANTEAM (RAINBOW PARTNERS Group) • Montreal

Hybrid
CAD 80,000 - 100,000
ANALYSTE SÉCURITÉ (SOC) Québec, Montréal ou Longueuil (hybride) 2026-09-24
ANALYSTE SÉCURITÉ (SOC) Québec, Montréal ou Longueuil (hybride) 2026-09-24

Gravity Conseil • Montreal (administrative region)

Hybrid
CAD 70,000 - 110,000
Mode hybride