Security Operations Analyst

NextGenEnergyJobs

Canada

Hybrid

CAD 80,000 - 110,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health benefits
Paid vacation
Competitive retirement plan

Job summary

NextGenEnergyJobs is seeking a hands-on Enterprise Security Analyst II to join our SOC team. You will monitor alerts, investigate security events, and support incident response across endpoint, identity, network, cloud, and email monitoring platforms.

You will apply MITRE ATT&CK concepts, enrich investigations with threat intelligence, and help improve detection quality, automation, and analyst enablement.

Qualifications

  • Hands-on monitoring and investigation of security alerts.

Responsibilities

  • Monitor SOC alert queue across endpoints, identity, network, cloud, and logs.

Skills

Cybersecurity experience
SIEM & EDR
Threat intelligence
Incident response
Scripting (PowerShell/Python)
Technical writing

Education

Bachelor's in Cybersecurity/IT/CS

Tools

SOAR platforms
KQL
Cloud security
Threat hunting tools

Job description

The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations.

Key Responsibilities
  • Security Operations and Incident Response
  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement
  • Threat Intelligence and Threat Hunting
  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements
Requirements
  • 2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation
  • Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity
  • Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis
  • Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols
  • Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures
  • Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences
  • U.S. citizenship is mandatory
  • Ability and willingness to obtain security clearance
  • Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree
  • Experience performing threat intelligence analysis, threat hunting, incident response, or security engineering in an enterprise environment
  • Experience converting threat intelligence into detections, hunts, watchlists, playbooks, response actions, or mitigation recommendations
  • Experience researching threat actors, malware, ransomware activity, vulnerability exploitation, or emerging attack techniques
  • Familiarity with SOAR platforms, detection engineering practices, automation, scripting, or query languages such as PowerShell, Python, KQL, or SPL
  • Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft security certifications
  • #LI-TM1
  • #LI-onsite
  • Esri’s competitive total rewards strategy includes industry-leading health and welfare benefits: medical, dental, vision, basic and supplemental life insurance for employees (and their families), 401(k) and profit-sharing programs, minimum accrual of 80 hours of vacation leave, twelve paid holidays throughout the calendar year, and opportunities for personal and professional growth. Base salary is one component of our total rewards strategy. Compensation decisions and the base range for this role take into account many factors including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs.
  • A reasonable estimate of the base salary range is
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Cybersecurity Analyst
Remote Cybersecurity Analyst

Placements24 • Kimberley

Hybrid
CAD 80,000 - 110,000
Health insurance
Home office allowance
Professional development
Cybersecurity Analyst
Cybersecurity Analyst

Horizon Computer Solutions • Edmonton

On-site
CAD 85,000 - 120,000
Annual bonus
Registered Pension Plan
Insurance reimbursement
+2
Security Operations Analyst II
Security Operations Analyst II

Tegus, Inc. • Vancouver

Hybrid
CAD 90,000 - 120,000
Cyber Security Analyst
Cyber Security Analyst

koundinyasa Technology Services • Montreal (administrative region)

On-site
CAD 70,000 - 100,000
Senior Security Analyst
Senior Security Analyst

Mindlance • Toronto

On-site
CAD 90,000 - 120,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

Northern Computer • Edmonton

Hybrid
CAD 65,000 - 95,000
Extended health coverage
Dental coverage
Life insurance
+5
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

Northern Computer Inc • Edmonton

Hybrid
CAD 75,000 - 110,000
Extended health
Dental coverage
Wellness spending
L3 SOC Analyst - Calgary
L3 SOC Analyst - Calgary

Integrity360 • Calgary

Hybrid
CAD 80,000 - 110,000
Senior SOC Analyst
Senior SOC Analyst

Socket.dev • Montreal (administrative region)

On-site
CAD 90,000 - 130,000
Senior SOC Analyst
Senior SOC Analyst

Coveo • Montreal (administrative region)

On-site
CAD 90,000 - 120,000