Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Mark Anthony Group in Vancouver, BC, is seeking a Senior SOC Analyst to serve as the core escalation point for complex security events, leading investigations, containment, and forensic collection across hybrid cloud, network, and endpoint environments.
You will monitor alerts, conduct log analysis, and help implement detection logic and response playbooks while collaborating with IT teams to protect the confidentiality, integrity, and availability of systems, data, and networks.
Mark Anthony Group is one of North America's most successful privately held alcohol beverage companies. We are a leading producer and distributor of fine wine, premium Ready to Drink (RTD) products, and spirits in the Global beverage alcohol industry. We are an innovative and ambitious organization with a successful track record of building successful and disruptive brands, including the iconicMike’s Hard LemonadeandWhite Claw.
The Senior SOC Analyst serves as the core escalation point for complex security events, leading deep-dive investigations, containment, and forensic evidence collection across hybrid cloud, network, and endpoint environments. Beyond alert triage, this role actively improves SOC operational maturity by authoring response playbooks, engineering new detection logic aligned with frameworks like MITRE ATT&CK, and collaborating with cross-functional IT teams to drive rapid root-cause remediation.
This is a hands-on role for a cybersecurity professional with foundational experience in IT security, infrastructure, or a related technology environment. The position is ideal for someone looking to expand their expertise in security operations, incident management, and risk mitigation.
In this role, you will monitor, analyze, and investigate security alerts, support the timely resolution of incidents, and help enhance security technologies, controls, documentation, and operational processes. Working closely with the IT Security team and cross-functional technology stakeholders, you will contribute to protecting the confidentiality, integrity, and availability of the organization's systems, networks, and data. The ideal candidate is analytical, detail-oriented, and eager to grow in a collaborative, fast-paced environment while building expertise across a broad range of cybersecurity disciplines.
· Review, investigate, and coordinate the response to security alerts and incidents raised by MDR, EDR, SIEM, and related tools.
· Monitor and triage security events, escalating critical incidents in accordance with established protocols and response workflows.
· Conduct log analysis and threat hunting across endpoint, network, cloud, and identity platforms to identify potential indicators of compromise.
· Investigate, document, and report security incidents, maintaining accurate operational logs and incident records for audit and compliance purposes.
· Support identity and access management processes, including privileged access reviews, privileged identity management, and secure remote access requests.
· Monitor and maintain network security operations, including firewall rule reviews, secure remote access, and wireless security controls.
· Contribute to the implementation and ongoing improvement of the organization’s SIEM by onboarding data sources, developing detection use cases, tuning rules, and refining alert quality.
· Support security policies, standards, playbooks, procedures, and other operational documentation.
· Respond to requests for security assistance and collaborate with IT Operations, Infrastructure, Risk and Compliance, and Security Engineering teams.
· Recommend practical enhancements or integrations that improve security tools, processes, alert quality, and incident response effectiveness
· A minimum of 2-5 years of experience in cybersecurity, infrastructure, a Security Operations Centre, incident response, or related IT role.
· Post-secondary education in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.
· Working knowledge of Microsoft 365, Windows administration, and core security concepts.
· Solid understanding of networking fundamentals, including TCP/IP, DNS, VPNs, and firewalls.
· Experience with MDR, EDR, SIEM, vulnerability management, or incident response processes
· Familiarity with cybersecurity frameworks and standards such as MITRE ATT&CK, NIST, ISO 27001, or SOC 2.
· Strong analytical, problem-solving, prioritization, and decision-making skills, including the ability to work effectively under pressure.
· Ability to assess and communicate technical risks in a business context to both technical and non-technical stakeholders.
· Self-motivated, organized, and able to manage competing priorities in a fast-paced environment.
· Relevant certifications such as Security+, CySA+, or Microsoft or AWS security certifications are considered an asset.
Mark Anthony is committed to hiring, engaging, and growing qualified, talented, and motivated team members at every level of our organization. We offer competitive compensation that recognizes individual and company performance. Thetypical hiring range for this position is $80,000 - $120,000annually complemented by a bonus plan; the base pay is determined by market location and job-related knowledge, skills, experience, and education.
As part of our Total Rewards program, we are also proud to offer:
Other perks include:
We are growing a lasting legacy in the beverage alcohol industry, with people first.
Mark Anthony Group is an equal opportunity employer.We encourage applications from individualsof all backgrounds who areeligibleto work in Canada.We thank all candidates for their interest in MAG and we will reach out to thosecandidates that are under consideration. If you are contacted for an interview and require accommodationduring the recruitment process, pleasecontactyour recruiter.
At Mark Anthony, we exist to Unearth the Extraordinary:
Our Purpose is not just a statement; it is a call to action that binds us together and ignites our passion for making a difference. It is the driving force behind why we do what we do every single day, connecting our global organization across all business units, roles, and locations. We are: