Senior MDR Analyst

Blackpoint Cyber

Canada

On-site

CAD 80,000 - 110,000

Full time

11 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Blackpoint Cyber is a leading cybersecurity company seeking an experienced analyst for its SOC. You will evaluate events, hunt threats, and produce incident analyses across global clients. Collaboration with MDR analysts and development of SOC processes are integral to this role.

Ideal candidates have 5+ years in information security, SOC experience, and strong Windows/Linux knowledge, plus scripting in PowerShell or Python.

Qualifications

  • Minimum 5 years in information security.
  • Experience in a Security Operations Center (SOC).
  • 2+ years triaging endpoint events from EDR/NGAV and supporting IR.
  • Deep knowledge of Windows security artifacts (malware, anomalous activity, forensics).
  • Experience with Windows/Linux/OSX environments and scripting."],
  • job_responsibilities_description':['Analyze and evaluate anomalous network and system events in a 24x7 SOC environment via lead-less threat hunting.','Collaborate with MDR Analysts to research threats; act as escalation point for advanced intrusion analysis.','Develop incident analysis reports and coordinate with business units to close issues.','Help design and implement SOC processes and procedures to improve efficiency.','Provide actionable threat and vulnerability analysis for diverse customer environments.','Build test labs to research techniques and contribute to threat operations knowledge.','Review sandbox technologies for IOCs uncovered during analysis.'],
  • CoT_job_summary_short":"COMPANY NAME: Blackpoint Cyber\nKEY POINTS: Threat hunting, SOC operations, incident analysis" ,
  • job_summary_short
  • <p>Blackpoint Cyber is seeking an experienced security analyst to join our SOC. You will analyze anomalous events, hunt threats, and support incident response across customer environments. Collaboration with MDR teams and building operational processes are key parts of the role.</p><p>Ideal candidates bring 5+ years in information security, SOC experience, and strong Windows/Linux/OSX knowledge, plus scripting skills in PowerShell or Python.</p>
  • contract_type':'fulltime
  • location_type':'on site
  • remote_scope":null,

Responsibilities

  • Analyze and evaluate anomalous network and system events in a 24x7x365 SOC environment via conducting lead-less threat hunting.
  • Collaborate with MDR Analysts to research and investigate emerging cyber security threats; become an escalation point of contact for advanced intrusion analysis.
  • Develop Incident analysis reports and work across business units and customers to bring issues to a close.
  • Help design and build operational processes and procedures to improve overall SOC efficiency.
  • Provide actionable threat and vulnerability analysis based on security events for many independent customer environments.
  • Build test lab environments to research emerging techniques and make contributions to the internal and external knowledge development of threat operations.
  • Review sandbox technologies for additional IOCs uncovered from artifacts uncovered during analysis.

Skills

SOC experience
Threat hunting
IR process
PowerShell
Python

Education

Bachelor’s Degree in Computer Science

Tools

ELK stack
EDR/NGAV
AWS
Azure/M365

Job description

Blackpoint Cyber is the leading provider of world-class cybersecurity threat hunting, detection and remediation technology. Founded by former National Security Agency (NSA) cyber operations experts who applied their learningsto bring national security-grade technology solutions to commercial customers around the world, Blackpoint Cyber is in hyper-growth mode, fueled by a recent $190m series C round.

Company Culture

On this team, we value high-quality execution, ownership, and strong morals. With us, principles are never tested, and we are proud to always do right by our customers. If you’re a driven professional with a passion for learning and contributing towards the best, then Blackpoint welcomes you. Our team is energetic and collaborative, maintaining a high-performance culture and enabling growth through overcoming challenges in the modern cyberthreat landscape.

Shift Requirement

This is a Monday through Friday day shift position

How You'll Make an Impact:
  • Analyze and evaluate anomalous network and system events in a 24x7x365 Security Operation Center (SOC) environment via conducting lead-less threat hunting.

  • Collaborate with MDR Analysts to research and investigate emerging cyber security threats; become an escalation point of contact for advanced intrusion analysis.

  • Develop Incident analysis reports and work across business units and customers to bring issues to a close.

  • Help design and build operational processes and procedures to improve overall SOC efficiency.

  • Provide actionable threat and vulnerability analysis based on security events for many independent customer environments.

  • Build test lab environments to research emerging techniques and make contributions to the internal and external knowledge development of threat operations.

  • Review sandbox technologies for additional IOCs uncovered from artifacts uncovered during analysis.

What you'll Bring:
  • Five (5+) years of experience in an information security role. Progressive relevant training and/or certification may be substituted for one (1) year of the experience requirement

  • Experience working in a Security Operations Center (SOC)

  • Two (2+) years of experience with triaging endpoint events from EDR, NGAV, and supporting the Incident Response (IR) process

  • Deep knowledge on assessing threat indicators in a Windows Environment (e.g. Malware/Malicious Anomalies/Abnormal network Activity/Root Level Compromise, Forensic Artifacts, etc.)

  • Robust understanding of at least two of the following: Windows, Linux or OSX;

  • Familiarity with ELK stack (Dashboards, Logstash Config, Searching) Scripting / Programming with Powershell, Python, and Go

  • Familiarity with AWS services such as EC2, S3 and IAM and Azure/M365

  • Experience in developing, refining, and performing leadless threat hunting analysis to uncover new or potential incidents and report on results

  • Excellent problem solving, critical thinking, and analytical skills with the ability to deconstruct issues (hunting anomalous pattern detection)

  • Excellent written and verbal communication skills to effectively summarize and present technical findings to both technical and non-technical audiences

Bonus:
  • Bachelor’s Degree in Computer Science or related technical discipline

  • Network/System Administration and/or Engineering

  • Deep forensic knowledge of Windows, Mac OS and/or Linux

  • Experience in Digital Forensics and Incident Response a plus

  • Malware Analysis (Behavioral and/or Static analysis- IDA, Cuckoo Sandbox, x86/x64 Debugging) Pentesting/Red/Blue Team

  • Capture The Flag (CTF) Development

Blackpoint Cyber welcomes and encourages applications from qualified individuals of all races, colors, religions, sex, sexual orientation, gender identity or expression, national origin, age, marital status, or any other legally protected status. We are committed to equality of opportunity in all aspects of employment.

For eligible employees in the US, Blackpoint offers competitive Health, Vision, Dental, and Life Insurance plans, a robust 401k plan, Discretionary Time Off, and other minor perks. International employees receive competitive benefits in accordance with local market standards and applicable country requirements.

Blackpoint believes all employees should share in the company’s success – equity participation is available to employees globally, with program details varying by location and employment structure.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Software Engineer Backend
Software Engineer Backend

Blackpoint Cyber • Canada

On-site
CAD 70,000 - 110,000
Health Insurance
Vision Insurance
Dental Insurance
+3
Sr. Full Stack Software Engineer
Sr. Full Stack Software Engineer

Blackpoint Cyber • Canada

Remote
CAD 120,000 - 150,000
Sr. Software Engineer (AI/ML)
Sr. Software Engineer (AI/ML)

Blackpoint-Cyber • Canada

On-site
CAD 120,000 - 180,000
Sr. Full Stack Software Engineer at Blackpoint Cyber
Sr. Full Stack Software Engineer at Blackpoint Cyber

Matcha • Canada

Hybrid
CAD 167,000 - 223,000
Director of Platform Engineering
Director of Platform Engineering

Blackpoint Cyber • Canada

Remote
CAD 180,000 - 260,000
AI/ML Ops Engineer
AI/ML Ops Engineer

Blackpoint Cyber • Canada

On-site
CAD 110,000 - 145,000
Senior Threat Analyst
Senior Threat Analyst

Sophos • Canada

On-site
CAD 86,000 - 143,000
Remote-first culture
Flexible work options
Threat Analyst
Threat Analyst

Sophos • Ottawa

Hybrid
CAD 70,000 - 90,000
Remote-first culture
Hybrid options
Flexible start times
+2
Analyst I, Falcon Complete (Remote, PST/MST)
Analyst I, Falcon Complete (Remote, PST/MST)

CrowdStrike • Vancouver

On-site
CAD 90,000 - 135,000
Market leader compensation & equity
Wellness programs
Vacation & holidays
+5
Cybersecurity Analyst
Cybersecurity Analyst

Top Echelon LLC • Edmonton

On-site
CAD 85,000 - 120,000
Annual bonus
Registered Pension Plan
Insurance reimbursement
+2