Senior SOC Analyst

Exchange Technology Services Inc.

Winnipeg

On-site

CAD 90,000 - 120,000

Full time

3 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Onsite Gym
Employee Share Purchase Plan
RRSP with Company Matching
Professional development

Job summary

Exchange Technology Services is seeking a Senior SOC Analyst to act as a technical escalation point for complex security alerts. You will lead investigations end-to-end, from scoping and containment to remediation and lessons learned, while mentoring analysts and shaping detections, playbooks, and automation workflows.

You will work with SIEM, SOAR, EDR, and threat intelligence, translating incidents into improved detections and risk-driven responses for enterprise clients in a dynamic,

Qualifications

  • Hands-on experience in SOC, incident response, or similar environments.
  • Ability to translate incidents into detections and responses.
  • Experience with threat hunting and detection engineering.

Responsibilities

  • Serve as senior escalation point for complex security alerts and incidents.
  • Lead investigations from scoping to remediation and lessons learned.
  • Develop detections, use cases, and playbooks based on threat intelligence.
  • Mentor analysts and document repeatable SOC processes.

Skills

SIEM queries
MITRE ATT&CK
Threat intelligence
SOAR
EDR & Network security

Education

CompTIA Security+
CySA+
Splunk Core Certified

Tools

Splunk
Python scripting
PowerShell

Job description

1558 Willson Pl, Winnipeg, MB R3T 0Y4, Canada

Job Description

Posted Friday, August 21, 2026 at 6:00 AM

About Us:

Exchange Technology Services is a leading IT consulting company in Winnipeg and part of the Exchange Income Corporation's family of companies. We provide a wide range of services, including Managed IT, Project Management, Business Intelligence, Cyber Security, Digital Transformation, Training Services, Installation Services, and Telecommunications across Canada and the US.
If you are looking for a fast-paced career, serving enterprise customers and managing diverse IT projects, we invite you to join us.

Our work environment is dynamic, filled with learning opportunities, exciting and challenging projects, and a chance to make a positive impact on clients’ businesses. We value teamwork, fun, and achieving amazing results together.

JOB OVERVIEW

As a Senior SOC Analyst, you will serve as a technical escalation point within the SOC, lead complex investigations, and help advance the SOC's risk-driven detection and response capabilities. The role combines day-to-day security operations with deeper expertise in at least one of the following areas: Advanced Incident Response, Threat Hunting, SIEM Automation, or Detection Engineering. You will independently handle complex work, mentor analysts, and translate incidents, threat intelligence, and business risks into improved use cases, detections, hunts, and automated workflows. The successful candidate should have at least three years of hands‑on experience in one or more of these specialty areas; broader or multi‑domain experience is preferred.

KEY RESPONSIBILITIES

  • Serve as a senior technical escalation point for complex or high‑impact security alerts and incidents, validating severity, scope, business impact, and required escalation.
  • Lead security incidents through the investigation life cycle, including scoping, evidence collection, containment and remediation guidance, root‑cause analysis, status reporting, and lessons learned.
  • Conduct proactive threat hunting using hypotheses derived from threat intelligence, incident findings, attacker behaviours, environmental risk, and known detection gaps; document methods, evidence, and outcomes.
  • Own or lead the security use case life cycle by identifying and prioritizing detection needs based on threats and business risks; defining objectives, data sources, logic, response actions, ownership, testing, and review requirements; and driving tuning, improvement or retirement.
  • Design, develop, test, validate, and tune SIEM, endpoint, or other security detections; identify coverage gaps and map detection logic to relevant threat behaviours or frameworks.
  • Design, test, document, and maintain SIEM/SOAR automation and orchestration workflows that improve investigation and response consistency, reduce repetitive manual effort, and preserve appropriate approvals and audit trails.
  • Translate incident, threat‑hunting, and threat‑intelligence findings into new or improved detections, use cases, playbooks, automation, and recommendations for security controls.
  • Review use case, detection, and automation performance using operational metrics and analyst feedback, and recommend improvements to alert quality, coverage, investigation efficiency, and response effectiveness.
  • Mentor SOC Analysts, support complex investigations, and perform peer review of queries, detections, playbooks, automation, and investigation findings when appropriate.
  • Maintain clear procedures, playbooks, knowledge articles, investigation records, and shift handoff documentation to support repeatable and auditable SOC operations.
  • Stay current on cybersecurity threats, attacker techniques, technologies, and best practices, and apply relevant developments to SOC monitoring and detection strategy.
  • Support routine monitoring and response across SIEM, EDR, email security, DLP, network security, and other SOC technologies when required.
  • Support the maintenance of the Information Security Management System (ISMS) by following corporate policies and providing supporting evidence for audits when required.
  • Additional responsibilities as assigned.

QUALIFICATIONS

EDUCATION & EXPERIENCE

  • Cybersecurity Certifications such as CompTIA Security+ and CySA+
  • Endpoint, cloud, identity, email security, or related advanced technical certifications considered an asset
  • Mimecast – Email Security, Cloud Gateway Fundamentals Level 1 Certificate
  • Advanced Incident Response, digital forensics, or threat hunting certifications considered an asset
  • SIEM, SOAR, detection engineering, or security automation certifications considered an asset
  • Splunk Certified Cybersecurity Defense Analyst
  • Splunk Core Certified Advanced Power User Certificate considered an asset
  • At least three years of hands‑on experience in one or more of the following specialty areas, supported by practical experience in SOC, cybersecurity operations, incident response, or a similar environment: Advanced Incident Response - leading complex investigations, scoping compromise, correlating evidence across multiple data sources, coordinating containment and remediation, and producing defensible findings.
  • Threat Hunting - developing and executing hunt hypotheses, analyzing large security datasets, identifying abnormal attacker behaviour, and converting findings into repeatable detections or monitoring opportunities.
  • SIEM Automation - building or improving repeatable investigation and response workflows using SIEM/SOAR capabilities, scripting, APIs, integrations, or low‑code automation.
  • Detection Engineering - designing detection logic, creating complex queries or rules, testing and validating detections, tuning false positives, documenting logic, and assessing detection coverage.

KNOWLEDGE, SKILLS & ABILITIES

  • Strong ability to search, interpret, and correlate security logs from multiple sources and create or modify advanced SIEM queries.
  • Working knowledge of MITRE ATT&CK or a comparable framework used to describe attacker behaviours, support threat hunting, and assess detection coverage.
  • Strong understanding of common threat vectors, indicators of compromise, identity and cloud threats, network activity, endpoint telemetry, and layered security controls.
  • Experience with core SOC technologies and workflows such as SIEM, SOAR, endpoint detection and response, email security, threat intelligence, and network security.
  • Ability to independently investigate ambiguous security events, make evidence‑based decisions, document findings clearly, and communicate technical risk to analysts, customers, and leadership.
  • Practical understanding of risk‑driven security use case management, including prioritization, requirements, ownership, testing, validation, review, metrics, continuous improvement, and retirement.
  • Experience working in a managed security services or multi‑customer environment.
  • Experience with SOAR or security automation platforms, Python or PowerShell scripting, REST APIs, JSON, webhooks, or version control.
  • Experience maintaining a use case or detection backlog, inventory, review cycle, coverage assessment, or related quality metrics.
  • Experience with threat intelligence, malware analysis, reverse engineering, or advanced forensic investigation techniques.
  • Microsoft 365 and Exchange Online investigation experience, including identity, audit, message trace, header analysis, and email security controls.
  • Familiarity with security risk assessment, risk management, ITIL, and ITSM platforms.
  • Experience creating and maintaining operational reports, dashboards, metrics, or other evidence used to evaluate SOC effectiveness.
  • Experience mentoring analysts, leading technical investigations, or contributing to continuous improvement of SOC processes.
  • Familiarity with SOC maturity models or risk‑driven SOC operating practices.

WORKING CONDITIONS

  • Must be able to obtain and maintain a clear criminal record check
  • Physically able to perform all listed job duties
  • Work performed primarily in an office environment
  • Manual dexterity required to use desktop computer and telephone
  • Various shifts at a fast pace to meet service level requirements of our clients
What We Offer:
  • Competitive salary and benefits package
  • Registered Retirement Savings Plan with Company Matching
  • Employee Share Purchase Plan
  • Onsite Gym
  • Opportunities for professional development and career growth
  • Collaborative and innovative work environment

Please note, Exchange Technology Services is an equal opportunity employer. We are committed to building a diverse and inclusive workplace and encourage applications from all qualified individuals. Accommodations are available upon request throughout the recruitment process. Please reach out to careers@exchangetech.ca if you have any questions.

1558 Willson Pl, Winnipeg, MB R3T 0Y4, Canada

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

Exchange Technology Services • Winnipeg

On-site
CAD 90,000 - 120,000
Competitive salary
RRSP matching
Employee Share Purchase Plan
+4
Service Desk Analyst
Service Desk Analyst

Exchange Technology Services Inc. • Vaughan

On-site
CAD 45,000 - 55,000
Competitive salary
RRSP with company matching
Employee Share Purchase Plan
+3
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Service Desk Analyst
Service Desk Analyst

Exchange Technology Services • Vaughan

On-site
CAD 45,000 - 55,000
Competitive salary
RRSP matching
Share Purchase Plan
+4
Security Analyst
Security Analyst

EIZIE • West Hawk Lake

On-site
CAD 80,000 - 110,000
Competitive salary
Health and dental benefits
Professional development
+5
Senior Information Security Analyst
Senior Information Security Analyst

IKO North America • Mississauga

On-site
CAD 106,000 - 120,000
Competitive compensation
Health care
Challenging workplace
+1
L3 SOC Analyst - Calgary
L3 SOC Analyst - Calgary

Integrity360 • Calgary

Hybrid
CAD 80,000 - 110,000
SOC Analyst (5+ years) to investigate incidents using Defender, Arctic Wolf, and Tenable
SOC Analyst (5+ years) to investigate incidents using Defender, Arctic Wolf, and Tenable

S I Systems • Toronto

On-site
CAD 85,000 - 110,000
Senior Information Security Analyst
Senior Information Security Analyst

Kaizen Lab Inc. • Winnipeg

Hybrid
CAD 90,000 - 120,000
Health Spending Account
Pension plan
Professional development
+7
Analyste SOC Senior
Analyste SOC Senior

Systematix • Montreal (administrative region)

Hybrid
CAD 80,000 - 100,000