SOC Cybersecurity Analyst

Security AnalystSecurity AnalystFull TimeRemoteMid LevelTeam 1,001-5,000

Location

Canada

Posted

6 days ago

Salary

0

Seniority

Mid Level

Job Description

SOC Cybersecurity Analyst

OnePoint

Role Description The L3 Production Cybersecurity Analyst position will provide security expertise to the 24/7 Security Operations Center (SOC). The main objective of this position is to contribute to the coordination and reporting of cyber incidents affecting the bank's critical assets by detecting, preventing, and responding to cyber threats targeting our group's infrastructure. This role provides essential support to the company-wide cybersecurity program through regional partnerships with our various business lines and, externally, with our customers, partners, and regulators. As a Cybersecurity Analyst, you are not only responsible for real-time monitoring, analysis, and resolution of identified security incidents, but also for the development and continuous improvement of the capabilities of the 24/7 SOC, the first line of defense for identifying potential information security incidents. Responsibilities - Provide analysis and monitoring of security log trends from numerous heterogeneous security devices. - Be responsible for the development and validation of use cases. - Provide incident response (IR) support or escalate when analysis confirms an actionable incident. - Provide threat and vulnerability analysis and security consulting services. - Develop a threat hunting program and capabilities. - Analyze and respond to previously undisclosed software and hardware vulnerabilities. - Investigate, document, and report on information security issues and emerging trends. - Conduct threat hunting activities to identify potential adversaries present in the network. - Perform analysis on compromised systems to identify the extent and nature of the compromise and provide remediation recommendations. - Provide support and/or conduct research for any security-related questions or incidents. - Perform tasks independently with a certain level of supervision. - Integrate and share information with other analysts and teams. - Monitor internal bank sources that may indicate security incidents, health alerts from monitored solutions, and requests for information. - Follow incident-specific procedures to triage potential incidents, validate and determine necessary mitigation measures, and keep these procedures up to date. - Escalate potential security incidents to Level IV engineers, implement countermeasures where appropriate, and recommend operational improvements. - Maintain accurate incident notes in the case management system. - Maintain in-depth knowledge of the bank's technology architecture, known weaknesses, and recent incidents. - Continuously improve the service by identifying and correcting gaps, adjusting false positives, and recommending new tools or scripts. - Serve as a recognized expert in at least one security-related field. - Actively seek professional development through continuous learning and aim to progress to the Analyst IV level. - Comply with internal operational security rules and other policies. - Carry out small ad hoc tasks/projects that may be assigned to you. Qualifications - Knowledge or 3-5 years of experience with the following technologies: SIEM, ELK, IDS/IPS, network and host firewalls, data leak prevention (DLP). - Direct experience with antivirus software, endpoint detection and response (EDR) solutions, firewalls, and content filtering. - Demonstrable experience or knowledge in incident response, log analysis, and PCAP file analysis. - Good knowledge of network fundamentals, e.g., OSI model, TCP/IP, DNS, HTTP(S), SMTP. - Good understanding of threat actors' methods of attack against a network: phishing, port scans, web application attacks, DDoS, lateral movement. - Knowledge of Windows and/or Linux operating systems and investigation methods to detect signs of compromise. - Motivation to learn and contribute to the team's ongoing development. - Recommended certifications: GCFA, GCIH, OSCP, or equivalent. - Excellent communication skills in English are required as the position involves communicating with stakeholders outside Quebec. - Only candidates legally authorized to work for any employer in Canada will be considered. Benefits - Minimum of 3 weeks of vacation starting from the first year. - Comprehensive group insurance with a generous employer contribution. - Employer contribution to a group RRSP. - Full remote work flexibility: Hybrid, Remote, or On-site. - A warm, bright, and welcoming office offering fresh fruit, coffee, beverages, occasional meals, etc. - Annual IT equipment budget. - A balanced work environment with flexible working hours. - Career development: training and certifications, online or in-person learning, Wepoint Academy, etc. - An international community of experts ready to share their knowledge. - A company culture focused on individuals’ needs and their belonging to a strong community.

Related Job Pages

More Security Analyst Jobs

Full TimeRemoteTeam 10,001+Since 1860H1B No Sponsor

• Perform hands-on Application Security assessments including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and manual code reviews. • Identify, analyze, and remediate vulnerabilities in web, mobile, and API applications (OWASP Top 10, API Security, etc.). • Lead and support Software Supply Chain Security initiatives: Dependency vulnerability management, SBOM (Software Bill of Materials) generation and analysis. • Conduct threat modeling for applications and integration points. • Review and secure build pipelines, container images, and third-party libraries. • Work closely with development, DevOps, and infrastructure teams to embed security into the SDLC. • Monitor and triage security findings from various AppSec tools. • Support Cloud Security posture reviews (basic knowledge required) – IAM, network security, and cloud misconfigurations. • Prepare clear security reports, risk assessments, and remediation guidance for stakeholders. • Stay updated with emerging threats in application security and software supply chain attacks (e.g., SolarWinds, Log4j, dependency confusion).

India
Banner Bank logo

Senior Cyber Security Analyst

Banner Bank

Let's Create Tomorrow, Together.

Full TimeRemoteTeam 1,001-5,000Since 1890H1B No Sponsor

• In this role you’ll lead the design, architecture, and implementation of enterprise security systems across on-prem and Azure environments • In this role you’ll drive strategic security initiatives and advise leadership on risks, threats, and security posture • In this role you’ll direct complex investigations and incident response efforts, serving as an escalation point for critical security events • In this role you’ll architect, deploy, and manage advanced security tools including Azure-native platforms such as Defender for Cloud and Sentinel • In this role you’ll monitor, detect, and respond to threats across network, endpoint, and cloud environments using automated and manual methods • In this role you’ll perform risk assessments, security testing, and control validations to ensure safeguards are effective and compliant • In this role you’ll partner with business and IT teams to implement secure solutions and enforce access controls and policies • In this role you’ll maintain thorough documentation, reporting, and threat intelligence to support audits, compliance, and continuous improvement

Idaho + 2 moreAll locations: Idaho | Oregon | Washington
$117.2K - $154.5K / year

Epic Security Analyst

UnitedHealth Group

UnitedHealth Group is a healthcare and well-being company that’s dedicated to improving the health outcomes of millions around the world. We are comprised of

Role Description Optum Insight is improving the flow of health data and information to create a more connected system. We remove friction and drive alignment between care providers and payers, and ultimately consumers. Our deep expertise in the industry and innovative technology empower us to help organizations reduce costs while improving risk management, quality and revenue growth. The Optum Provider Technology Services team is building an innovative, comprehensive Epic services capability using the collective expertise of our clinical, consulting, delivery, technology and operations teams. For you, that means working on high performance teams to leverage the power of technology and services delivery to improve care. Strong candidates for this role will be able to demonstrate self-motivation, individual leadership and team collaboration. Most importantly, our team will foster a culture of diversity and inclusion and drive innovation for our company and our clients. Primary Responsibilities: - Provisions application security levels and user roles - Coordinates security template and role updates following the security change control process - Works with application and compliance teams to design system-level access - Creates and maintains provider records - Understands the Epic software security structures, including user profiles, roles, and security classes - Provisions access to third party applications in accordance with system policies and procedures - Designs and documents the general functional requirements and detailed technical specifications - Ability to troubleshoot technical issues - Provides technical consultation including configuration - Reviews, analyzes, and evaluates systems needs to develop recommendations for customers - Develops, supports and maintains all required system design and build documents and other system documentation - Provides support of application incidents reported through the help desk; including 24/7 on call coverage as required - Adheres to organization standards for system configuration and change control - Develops strong relationships with end user communities, customers and business partners - Attends, participates in, and contributes to meetings throughout the facility - Troubleshoots and/or resolves application issues and escalates more complex issues as appropriate You’ll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Qualifications - 1+ year of healthcare experience - 1+ year of customer service experience - Ability to travel per business need (most likely 1-2 times per year) - Intermediate proficiency with MS Excel, Visio, PowerPoint and SharePoint Requirements - Ability to demonstrate and have a history of team management (informal or formal), cross-team communication and leadership skills - Active / current Epic certification in Security - Additional Certification, or proficiency, in either EpicCare Ambulatory or Cadence - Completed Epic CEE (Continued Epic Education) to maintain certifications, proficiencies, and badges - Healthcare domain knowledge such as patient flow, scheduling, registration, authorization, or eligibility or other support functions in a healthcare organization - Reside in greater Nashville, TN or willing to relocate to Nashville Soft Skills - Excellent time management, organizational, and prioritization skills and ability to balance multiple priorities. - Teamwork and Collaboration. Consultative and collaborative style with demonstrated ability with cross-functional teams - Understanding of concepts of confidentiality and data security - Demonstrates the ability to build and maintain strong internal relationships as well as motivate and inspire other team members through strong consultative skills - Demonstrates a strong ability to build partnerships and influence others. Work across team, group and business boundaries to drive commonality and reusability in solution to real-world problems - Demonstrates strong relationship management skills and ability to handle challenging interpersonal situations Benefits - Comprehensive benefits package - Incentive and recognition programs - Equity stock purchase - 401k contribution (all benefits are subject to eligibility requirements) Application Deadline This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.

United States
$60.2K - $107.4K / year
Full TimeRemoteTeam 51-200Since 1997H1B No Sponsor

• Promover, divulgar e gerenciar a cultura de Segurança da Informação; • Propor novas melhorias e controles para as políticas, normas e ambientes (local e nuvem); • Auxiliar na correção e controle de vulnerabilidades; • Realizar implantação e melhorias nos Baselines de Hardening; • Configurar e administrar ferramentas e plataformas de segurança (firewalls, WAF, IDS, IPS, SIEM, antivírus); • Manter os processos para conformidade de certificações; • Analisar riscos e propor ações para as vulnerabilidades encontradas; • Planejar/Executar projetos de segurança voltados a infraestrutura e Cloud.

Brazil