Web
Security Operations Analyst, Senior
Canada - Remote · Senior
Sponsorship not specifiedDetected 8 days ago
PythonPowerShellAWSGCPAzureLinuxCybersecuritySIEMMicrosoft DefenderSOARSOC OperationsDetection EngineeringIncident ResponseTCP/IPDNSFirewallLeadershipCommunicationCollaborationMentoringCISSPCompTIA
About the role
- Role Summary Security Operations Analyst is responsible for the day-to-day monitoring, analysis, and investigation of security threats across enterprise systems and networks.
- The role triages and responds to security alerts and incidents, working both independently and in collaboration with senior analysts on known or suspected threats.
- This includes identifying anomalies, escalating issues as appropriate, and contributing to the improvement of detection and response processes.
Requirements
- Working knowledge of security controls including access control, authentication, encryption, system integrity, and logging as applied to security monitoring and detection.
- Experience with security operations including monitoring, incident response, and incident management procedures, with the ability to investigate, escalate, and respond to security events.
- Strong knowledge of operating systems (Windows, Linux, macOS), identity systems (e.g., Active Directory), and network fundamentals (TCP/IP, DNS) as they relate to security monitoring and investigation.
- Experience with endpoint, network, and host-based security tools including EDR, IDS/IPS, firewalls, vulnerability scanners, and host-based detection/prevention systems.
- Ability to analyze and correlate data across multiple security and telemetry sources to identify patterns, anomalies, vulnerabilities, and potential security threats.
- Ability to develop, modify, and maintain threat detection rules within SIEM platforms, including tuning alerts and improving detection fidelity.
- Understanding of security telemetry, including log collection and ingestion (e.g., syslog, Windows Event Forwarding, ELK), normalization, and data quality considerations to support effective detection and visibility.
- Experience applying security frameworks such as MITRE ATT&CK to map adversary behaviors and support detection and response development.
- Experience with malware analysis, network forensics, and digital forensics concepts and tools; reverse engineering skills are a plus.
- Ability to assess security threats and implement timely mitigations under pressure.
- Experience using scripting languages such as Python, PowerShell, or equivalent to support automation, analysis, and response activities.
- Strong collaboration and communication skills with the ability to build effective relationships across technical and non-technical teams.
- Experience with security platforms and tools including SIEM, SOAR, EDR, vulnerability management, and threat intelligence tools (e.g., Google SecOps/Chronicle, Microsoft Defender for Endpoint, SentinelOne Singularity, Tanium Threat Response, Recorded Future).
Nice to have
- Identify, investigate, and respond to security incidents, including analyzing root cause and impact to contain threats and reduce organizational risk.
- Monitor systems and security telemetry for violations, vulnerabilities, and anomalous activity.
- Analyze and apply threat intelligence to enhance detection, response, and situational awareness.
- Experience with malware analysis, network forensics, and digital forensics concepts and tools
- reverse engineering skills are a plus.
- Experience with cloud security monitoring and native security services across AWS, Azure, Google Cloud, or OCI is a plus.
- Familiarity with security-focused frameworks, methodologies, and best practices for detection, response, and vulnerability management is a plus.
This listing is sourced directly from Web's careers page and normalized into a canonical job model.