Web

Web

Security Operations Analyst, Senior

Canada - Remote · Senior

Sponsorship not specifiedDetected 8 days ago
PythonPowerShellAWSGCPAzureLinuxCybersecuritySIEMMicrosoft DefenderSOARSOC OperationsDetection EngineeringIncident ResponseTCP/IPDNSFirewallLeadershipCommunicationCollaborationMentoringCISSPCompTIA

About the role

  • Role Summary Security Operations Analyst is responsible for the day-to-day monitoring, analysis, and investigation of security threats across enterprise systems and networks.
  • The role triages and responds to security alerts and incidents, working both independently and in collaboration with senior analysts on known or suspected threats.
  • This includes identifying anomalies, escalating issues as appropriate, and contributing to the improvement of detection and response processes.

Requirements

  • Working knowledge of security controls including access control, authentication, encryption, system integrity, and logging as applied to security monitoring and detection.
  • Experience with security operations including monitoring, incident response, and incident management procedures, with the ability to investigate, escalate, and respond to security events.
  • Strong knowledge of operating systems (Windows, Linux, macOS), identity systems (e.g., Active Directory), and network fundamentals (TCP/IP, DNS) as they relate to security monitoring and investigation.
  • Experience with endpoint, network, and host-based security tools including EDR, IDS/IPS, firewalls, vulnerability scanners, and host-based detection/prevention systems.
  • Ability to analyze and correlate data across multiple security and telemetry sources to identify patterns, anomalies, vulnerabilities, and potential security threats.
  • Ability to develop, modify, and maintain threat detection rules within SIEM platforms, including tuning alerts and improving detection fidelity.
  • Understanding of security telemetry, including log collection and ingestion (e.g., syslog, Windows Event Forwarding, ELK), normalization, and data quality considerations to support effective detection and visibility.
  • Experience applying security frameworks such as MITRE ATT&CK to map adversary behaviors and support detection and response development.
  • Experience with malware analysis, network forensics, and digital forensics concepts and tools; reverse engineering skills are a plus.
  • Ability to assess security threats and implement timely mitigations under pressure.
  • Experience using scripting languages such as Python, PowerShell, or equivalent to support automation, analysis, and response activities.
  • Strong collaboration and communication skills with the ability to build effective relationships across technical and non-technical teams.
  • Experience with security platforms and tools including SIEM, SOAR, EDR, vulnerability management, and threat intelligence tools (e.g., Google SecOps/Chronicle, Microsoft Defender for Endpoint, SentinelOne Singularity, Tanium Threat Response, Recorded Future).

Nice to have

  • Identify, investigate, and respond to security incidents, including analyzing root cause and impact to contain threats and reduce organizational risk.
  • Monitor systems and security telemetry for violations, vulnerabilities, and anomalous activity.
  • Analyze and apply threat intelligence to enhance detection, response, and situational awareness.
  • Experience with malware analysis, network forensics, and digital forensics concepts and tools
  • reverse engineering skills are a plus.
  • Experience with cloud security monitoring and native security services across AWS, Azure, Google Cloud, or OCI is a plus.
  • Familiarity with security-focused frameworks, methodologies, and best practices for detection, response, and vulnerability management is a plus.

This listing is sourced directly from Web's careers page and normalized into a canonical job model.