Job Closed
This listing is no longer active.
Canada's most trusted and authoritative source for broadcast measurement and consumer behavior data.
Information Security Analyst – 1-Year Contract
Location
Canada
Posted
8 days ago
Salary
$85K - $90K / year
Seniority
Senior
Job Description
Information Security Analyst – 1-Year Contract
Numeris
• Monitoring Security Systems: Continuously monitor various security systems, including firewalls, intrusion detection systems, antivirus software, and others, to promptly detect and respond to any security incidents. • Security Incident Response: Take the lead in investigating security breaches and incidents, pinpointing their root causes, and developing strategies to prevent similar occurrences in the future. Collaborate closely with IT and business teams to ensure coordinated and effective response efforts. • Vulnerability Management: Identify and assess vulnerabilities present in systems and networks, collaborating with technical teams to mitigate risks through patch management and configuration changes. Thoroughly document findings and facilitate clear communication across teams to promptly address security weaknesses. • Security Policy Enforcement: Ensure the enforcement of robust security controls, policies, and procedures throughout the organization, guaranteeing compliance with relevant regulations, standards, and best practices. • Security Awareness Training: Support and contribute to security awareness initiatives and trainings aimed at educating employees on the best practices for maintaining information security, fostering a culture of security consciousness within the organization. • Security Risk and Vendor Assessments: Conduct comprehensive assessments of security risks and evaluate third-party vendor security measures to gauge the effectiveness of existing security controls and identify areas for enhancement. • Security Tool Evaluation: Assess and evaluate the suitability of new security tools and technologies to bolster the organization's overall security posture, ensuring that chosen solutions align with the organization's security objectives and requirements. • Lead end-to-end incident response activities, including detection, triage, containment, eradication, and post-incident analysis.
Job Requirements
- Requires a graduate degree with at least 5 years of experience in information security or a related field, with specific experience in areas such as incident response, vulnerability management, or security operations.
- Relevant certifications, such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or CompTIA Security+ preferred.
- Proficient in various security technologies and tools, such as firewalls, intrusion detection/prevention systems, SIEM (Security Information and Event Management) systems, and antivirus software.
- Strong systems-level understanding of how applications, operating systems, and networks interact from a security perspective.
- Knowledgeable about networking protocols and operating systems.
- Extensive working knowledge of information security, vulnerabilities, and threats.
- Expertise in information security best practices, tools, and techniques, including encryption methods.
- Familiarity with relevant security and privacy legislation.
- Understanding of the software development lifecycle.
- Proven communication, presentation, and negotiation skills, with the ability to convey complex information to various audiences.
- Excellent judgment and strong decision-making skills. Critical thinking abilities. Detail-oriented approach to work.
- Basic familiarity with Identity and Access Management (IAM).
- Experience with cloud security is a plus.
- Demonstrated ability to quickly learn new tools, technologies, and security domains.
Benefits
- Competitive salary and benefits package (Health, Dental, Vision and Personal Spending Account - employer paid premiums).
- Flexible Work location (on-site offices in Toronto and Montreal, remote – work from home, hybrid as required per role).
- Continuous learning and development via Percipio, our Learning Management System.
- Be part of additional programs such as MentorMe, which helps our employee’s network, and grow within the organization.
- Leadership Training offerings for new and emerging leaders.
- Culture of great teams, coworkers and supportive leadership.
- Perkopolis: Participation in a program that provides exclusive discounts on products and services to employees. Perks include shopping discounts, movie tickets, services, event/show tickets and much more!
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
• Own and implement data protection controls for AI platforms and SaaS applications • Design and enforce DLP policies across AI prompts, outputs, file uploads, and APIs • Identify and mitigate AI-specific risks including prompt injection, data exfiltration, and shadow AI usage • Build and operationalize guardrails such as data masking, prompt filtering, and response inspection • Analyze and map data flows across AI tools to identify control points and enforce protections • Secure integrations between AI tools and enterprise systems (APIs, plugins, third-party apps) • Monitor AI usage and integrate signals into SIEM, DLP, and CASB platforms • Investigate and respond to AI-related security incidents and data leakage events • Partner with engineering to embed security controls into AI pipelines and workflows • Support AI governance by enforcing policies and enabling secure AI adoption
Role Description Estamos en búsqueda de un perfil System & Security Analyst con la siguiente experiencia: - Experiencia en resiliencia operativa y cumplimiento de requisitos regulatorios como DORA y GDPR en entornos financieros o regulados. - Experiencia en gestión de vulnerabilidades y en el uso de análisis estático de seguridad sobre el ciclo de desarrollo, con referencia explícita al uso de GitHub SAST / GitHub Advanced Security. - Experiencia en seguridad en el desarrollo (Secure SDLC) y aplicación de guías OWASP para desarrollo seguro sobre tecnologías .NET Core. - Experiencia en gestión de secretos y manejo seguro de credenciales en pipelines, con uso de herramientas corporativas y referencia a Terraform y servicios de secretos en cloud. - Experiencia en auditoría y mejora continua, manteniendo documentación de procesos y registros de actividad disponibles para auditorías internas o externas. - Experiencia en evaluación inicial de riesgos técnicos y de transición, incluyendo diagnóstico AS-IS, matriz de riesgos de transición y análisis de brechas de conocimiento. - Conocimiento de entornos cloud AWS y de sus implicaciones de seguridad, resiliencia y gobernanza, incluyendo servicios como EC2, S3, RDS y despliegues controlados con Terraform. - Conocimiento de sistemas operativos Windows Server 2019 y Linux aprobados para contenedores, además de software base como IIS 10, .NET Framework / .NET Core. - Conocimiento de herramientas corporativas del cliente como JIRA Service Management, JIRA Software, Confluence, Xray, así como de observabilidad y monitorización con Nagios, Control-M, Grafana y Splunk. - Conocimiento de continuidad de servicio, simulacros de DRP, validación de RTO/RPO y reporting de resiliencia operativa. Qualifications - Capacidad analítica y de evaluación de riesgos, especialmente en fases de transición, auditoría técnica inicial y control de exposición de seguridad. - Orientación a compliance y gobernanza, asegurando alineación con controles operacionales, seguridad corporativa y estándares del cliente. - Visión de resiliencia operativa, combinando seguridad, continuidad, recuperación y estabilidad del servicio Back Office. - Capacidad de documentación y trazabilidad, generando evidencias, reportes técnicos, matrices de riesgos y documentación de arquitectura/procesos. - Comunicación técnica transversal, con interlocución con equipos de desarrollo, operaciones, seguridad, arquitectura y responsables internacionales del Grupo. - Mentalidad DevSecOps, integrando seguridad dentro del ciclo de vida del desarrollo y no como actividad aislada al final del proceso. Requirements - Experiencia en seguridad de activos y control de acceso en entornos críticos, aplicando el principio de Least Privilege y control nominal de accesos a producción. - Experiencia en resiliencia operativa y cumplimiento de requisitos regulatorios como DORA y GDPR en entornos financieros o regulados. - Experiencia en gestión de vulnerabilidades y en el uso de análisis estático de seguridad sobre el ciclo de desarrollo, con referencia explícita al uso de GitHub SAST / GitHub Advanced Security. - Experiencia en seguridad en el desarrollo (Secure SDLC) y aplicación de guías OWASP para desarrollo seguro sobre tecnologías .NET Core. - Experiencia en gestión de secretos y manejo seguro de credenciales en pipelines, con uso de herramientas corporativas y referencia a Terraform y servicios de secretos en cloud. - Experiencia en auditoría y mejora continua, manteniendo documentación de procesos y registros de actividad disponibles para auditorías internas o externas. - Experiencia en evaluación inicial de riesgos técnicos y de transición, incluyendo diagnóstico AS-IS, matriz de riesgos de transición y análisis de brechas de conocimiento. - Conocimiento de entornos cloud AWS y de sus implicaciones de seguridad, resiliencia y gobernanza, incluyendo servicios como EC2, S3, RDS y despliegues controlados con Terraform. - Conocimiento de sistemas operativos Windows Server 2019 y Linux aprobados para contenedores, además de software base como IIS 10, .NET Framework / .NET Core. - Conocimiento de herramientas corporativas del cliente como JIRA Service Management, JIRA Software, Confluence, Xray, así como de observabilidad y monitorización con Nagios, Control-M, Grafana y Splunk. - Conocimiento de continuidad de servicio, simulacros de DRP, validación de RTO/RPO y reporting de resiliencia operativa. Benefits - La modalidad de trabajo es 100% en remoto.
Senior Cyber Threat Intelligence & Forensics Analyst
CallTekYour White Label Enterprise Support Company.
Role Description - Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. - Experience: 5+ years in a dedicated SOC, IR, or Intel role (ideally within a CSIRT or MSSP). - The Toolkit: Mastery of tools like Splunk/ELK, CrowdStrike/SentinelOne/VisionOne, Magnet AXIOM/FTK/EnCase/Autopsy, Sandbox, Volatility, and Wireshark. - Programming: Ability to script in Python or PowerShell to automate repetitive tasks or parse forensic artifacts. - Certifications: We value skills over paper, but GIAC (GCIH, GCFA, GCTI), CFE, CTIA or CHFI are highly preferred. - Familiarity with incident response processes and frameworks. - Strong analytical and problem-solving skills with attention to detail. - Excellent verbal and written communication skills to present complex technical information clearly. Qualifications - Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. - 5+ years in a dedicated SOC, IR, or Intel role (ideally within a CSIRT or MSSP). - Mastery of tools like Splunk/ELK, CrowdStrike/SentinelOne/VisionOne, Magnet AXIOM/FTK/EnCase/Autopsy, Sandbox, Volatility, and Wireshark. - Ability to script in Python or PowerShell. - GIAC (GCIH, GCFA, GCTI), CFE, CTIA or CHFI certifications preferred. - Familiarity with incident response processes and frameworks. - Strong analytical and problem-solving skills. - Excellent verbal and written communication skills. Requirements - 5+ years in a dedicated SOC, IR, or Intel role. - Mastery of specified tools. - Ability to script in Python or PowerShell. - Preferred certifications. - Familiarity with incident response processes. - Strong analytical skills. - Excellent communication skills. Company Description
• Design, implement, and evolve detection use cases on SIEM platforms. • Increase threat identification capabilities and reduce false positives. • Develop, test, and maintain use cases and correlation rules in SIEM. • Create and refine detections based on the MITRE ATT&CK framework. • Perform continuous tuning to reduce false positives/negatives. • Work on log engineering (onboarding, parsing, normalization, and enrichment). • Define and monitor detection effectiveness metrics (coverage, MTTD, etc.). • Support complex investigations (N2/N3) with in-depth event analysis. • Integrate sources such as EDR, NDR, cloud platforms, IAM, and applications into the SIEM. • Develop playbooks and automations (SOAR where applicable). • Collaborate with incident response and threat intelligence teams. • Document use cases, detection patterns, and implemented improvements.




