Specialist, Cyber Defence

ipss inc.

Toronto

On-site

CAD 114,000 - 155,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The City of Toronto is seeking a dedicated Cyber Defense professional to support Threat Management’s cyber programs and initiatives from the SOC floor and through incident response. You will work under guidance to help develop project plans and execution roadmaps and collaborate across City divisions.

In this permanent full-time role, you will contribute by applying security monitoring, threat intelligence, and incident response practices while assisting with security tool management, like

Qualifications

  • Post-secondary degree in Business or Technology or a related discipline.
  • Over 3 years experience in Cyber Operations.
  • In-Depth security monitoring experience with one or more SIEM technologies (i.e. QRadar, Splunk, Azure Sentinel), EDR solutions, and intrusion detection/prevention technologies.
  • Basic knowledge of client-server applications, multi-tier web applications, relational databases, firewalls, VPNs, and enterprise Anti-Virus products.
  • Strong understanding of security incident management, remediation steps and vulnerability management processes.
  • An understanding of a Cloud environment’s Security monitoring components (e.g. Microsoft Defender, Sentinel; AWS CloudWatch, CloudTrail; GCP Chronicle Security, etc.).
  • Experience with web content filtering technology – policy engineering and troubleshooting.
  • Strong knowledge of networking principles including TCP/IP, WANs, LANs, and protocols.
  • Experience in Incident Response or relevant cyber security field(s).
  • Experience managing cases with enterprise SIEM systems.
  • In depth knowledge of security vulnerabilities, exploits, malware and digital forensics as they relate to Incident Response.

Responsibilities

  • SOC Operations Support: monitors alerts, escalates incidents, and supports threat detection and incident response.
  • Collaborate with Stakeholders to Assist with SOC Security Technologies: supports operation, maintenance, and optimization of SOC tools; assists with integration efforts.
  • Assist with Security Tools Management: works with MSSP and internal teams to monitor and maintain security tools; ensures alerts are documented and escalated.
  • Support the Application of Cyber Threat Intelligence: applies basic operational/tactical intelligence to security operations.
  • Assist in Developing and Supplying Security Metrics: helps collect and prepare data to track security metrics, compliance, and trends.
  • Reporting Support: prepares security reports and metrics for senior management.

Skills

Cyber Operations
Security Monitoring
Incident Response
Networking
Cloud Security
Threat Intelligence
Stakeholder Communication
Prioritization
Analytical Thinking
Problem Solving

Education

Post-secondary degree in Business or Technology

Tools

QRadar
Splunk
Azure Sentinel
SIEM
EDR

Job description

Division: Office of the Chief Information Security Officer

Reports To: Manager, Cyber Defense

Salary Range: $113,683 to $155,216

Work Location: 55 John Street, Toronto

Job Type: Permanent Full Time

Shift Information: Monday to Friday, 35 hours work week

JOB SUMMARY

To support the execution of the Office of the CISO’s mandate, cyber vision, and strategy by assisting with technical tasks, business support, and services related to Threat Management’s cyber programs and initiatives across all City divisions, agencies, and corporations.

To contribute to the development and delivery of Threat Management’s cyber programs and initiatives by collaborating with teams across the organization and supporting the creation of project plans and execution roadmaps.

To provide operational support and assist with the implementation of Cyber Defense activities within the Threat Management section under the guidance of senior team members.

MAJOR RESPONSIBILITIES
  • SOC Operations Support: Assists in the day-to-day activities of the Security Operations Center (SOC) by monitoring alerts, escalating incidents as needed, and supporting threat detection and incident response efforts to help maintain the City’s security posture.
  • Collaborate with Stakeholders to Assist with SOC Security Technologies: Supports internal IT teams, external partners, and service providers by helping with the operation, maintenance, and optimization of SOC security tools and technologies. Assists with integration efforts related to enterprise security programs (e.g., SIEM, EDR, NDR, WAAP, SOAR, etc.).
  • Assist with Security Tools Management: Works with the Managed Security Services Provider (MSSP) and internal teams to monitor and maintain security tools (SIEM, EDR, NDR, WAAP, SOAR, etc.), ensuring alerts and anomalies are documented and escalated appropriately.
  • Support the Application of Cyber Threat Intelligence: Supports the Threat Intelligence team by applying basic operational and tactical cyber threat intelligence to security operations, contributing to the organization’s ability to detect, analyze, and respond to security events.
  • Assist in Developing and Supplying Security Metrics: Supports the collection and preparation of data to track key security metrics, compliance status, and trends, under the direction of senior team members.
  • Reporting Support: Assists in the preparation of security reports and metrics for senior management, contributing to visibility into the efficiency and compliance of security operations.
QUALIFICATIONS/CERTIFICATIONS
  • Post-secondary degree in Business or Technology or a related discipline.
  • Over 3 years experience in Cyber Operations
  • In-Depth security monitoring experience with one or more SIEM technologies (i.e. QRadar, Splunk, Azure Sentinel), EDR solutions, and intrusion detection/prevention technologies.
  • Basic knowledge of client-server applications, multi-tier web applications, relational databases, firewalls, VPNs, and enterprise Anti-Virus products.
  • Strong understanding of security incident management, remediation steps and vulnerability management processes.
  • An understanding of a Cloud environment’s Security monitoring components (e.g. Microsoft: Defender, Sentinel; Amazon: CloudWatch, CloudTrail, Event Bridge; GCP: Chronicle Security, Event Threat Detection, Security Command Center, etc.)
  • Experience with web content filtering technology – policy engineering and troubleshooting.
  • Strong understanding of networking principles including TCP/IP, WANs, LANs, and commonly used Internet protocols such as SMTP, HTTP, FTP, POP, LDAP.
  • Experience in Incident Response or relevant cyber security field(s)
  • Experience managing cases with enterprise SIEM systems.
  • In depth knowledge of security vulnerabilities, exploits, malware and digital forensics as they relate to Incident Response.
  • Strong deductive reasoning, critical thinking, problem solving, and prioritization skills
  • Strong knowledge of effective security practices in a large, complex environment and awareness of general security-related training requirements within this environment.
  • Preferred Certifications (any in the list): GCIH, ECIH, CCSP, Azure, AWS or GCP Security Certifications, CISSP, CRISC, OSCP, CEH, GPEN
SOFT SKILLS
  • Ability to work in transformative programs.
  • Ability to lead efficient communication between all project stakeholders, including internal teams and clients
  • Ability to achieve business objectives through influencing and effectively working with key stakeholders.
  • Excellent written & verbal communication skills (comfortable & confident communicating at all levels including business partners, leadership and vendors.
  • Excellent problem-solving skills with capability to identify solutions to unusual and complex problems.
  • Keen attention to detail and strong organizational skills.
  • Highly organized, proactive, self-motivated team player who takes initiative and is able to work independently.
  • Ability to work in a fast-paced environment managing multiple priorities with proven time management skills.
  • Strong analytical skills and ability to prioritise and multitask.
  • Ability to prioritize and effectively manage competing priorities and projects.
  • Ability to manage multiple initiatives while adhering to strict deadlines.
  • Able to work extremely well under pressure while maintaining a high level of professionalism
  • Self-motivated person with desire to go above and beyond tasks
  • Transferable skills, like communication and decision-making, are equally important.
  • Being able to think on your feet and show good judgment are especially valuable in this field. “Security pros should always be ready to react to cyber-related incidents quickly.
ADDITIONAL COMMENTS/INFORMATION

The standard work week is 35 hours. Occasionally, unforeseen situations may require extended hours with limited notice. In the event of a cyber incident or breach, employees may be asked to support shift rotations or work extended hours. When extended hours are required, employees will receive compensating time off.

*Subject to a police check, background check, psychological assessment and/or any other checks on a regular basis as the Office of the CISO handles highly sensitive and confidential information.

EQUITY, DIVERSITY AND INCLUSION

The City is an equal opportunity employer, dedicated to creating a workplace culture of inclusiveness that reflects the diverse residents that we serve. Learn more about the City’s commitment to employment equity.

ACCOMMODATION

The City of Toronto is committed to creating an accessible and inclusive organization. We are committed to providing barrier-free and accessible employment practices in compliance with the Accessibility for Ontarians with Disabilities Act (AODA). Should you require Code-protected accommodation through any stage of the recruitment process, please make them known when contacted and we will work with you to meet your needs. Disability-related accommodation during the application process is available upon request. Learn more about the City’s Hiring Policies and Accommodation Process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Specialist Cyber Service Management
Specialist Cyber Service Management

City of Toronto • Toronto

On-site
CAD 116,000 - 161,000
Senior Specialist Business Strategy & Planning
Senior Specialist Business Strategy & Planning

City of Toronto • Toronto

On-site
CAD 126,000 - 176,000
SENIOR SPECIALIST Cyber Architecture
SENIOR SPECIALIST Cyber Architecture

City of Toronto • Toronto

On-site
CAD 100,000 - 130,000
Cyber Defense Specialist: SOC Ops & Threat Intel
Cyber Defense Specialist: SOC Ops & Threat Intel

ipss inc. • Toronto

On-site
CAD 114,000 - 155,000
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

Quantum Technology Recruiting Inc. (QTR) • Toronto

Hybrid
CAD 105,000 - 120,000
On-Call Rotation
HEALTH & SAFETY OFFICER
HEALTH & SAFETY OFFICER

City of Toronto • Toronto

On-site
CAD 89,000 - 133,000
Senior Manager, Information Security & IT
Senior Manager, Information Security & IT

Talent Minded • Toronto

Hybrid
CAD 150,000 - 165,000
RQ08347 - Specialized IT Consultant - Senior
RQ08347 - Specialized IT Consultant - Senior

Rubicon Path • Toronto

Hybrid
CAD 90,000 - 110,000
Business Programs & Solutions Specialist (Integration & Platform Solutions Developer)
Business Programs & Solutions Specialist (Integration & Platform Solutions Developer)

City of Toronto • Ontario

On-site
CAD 80,000 - 90,000
Director, Development & Operations (DevOps)
Director, Development & Operations (DevOps)

City of Toronto • Toronto

On-site
CAD 165,000 - 223,000