01 Aug
|
Compunnel
|
Regina
JOB SUMMARY
Handling security queue in Service Now application to manage security incident tickets and comply with incident response plans and processes to address potential threats.
Key Responsibilities
- Monitor, analyze, and investigate network security events and anomalies across firewalls, intrusion detection/prevention systems (IDS/IPS), web proxies, and other network security technologies.
- Perform network traffic analysis to identify indicators of compromise, suspicious communications, unauthorized access attempts, and potential data exfiltration activities.
- Support the implementation, administration, and continuous improvement of network security controls, including firewalls, network access control (NAC), segmentation, VPNs, and secure remote access solutions.
- Conduct reviews of firewall rules, access control lists (ACLs), and network security configurations to ensure adherence to security standards and least-privilege principles.
- Collaborate with architecture, infrastructure and networking teams to assess, troubleshoot and remediate network security risks, vulnerabilities and configuration gaps or weaknesses.
- Participate in security investigations and incident response activities, including packet capture analysis, threat containment, and root cause determination.
- Maintain awareness of emerging network-based threats, attack techniques, and security technologies, and recommend enhancements to detection and prevention capabilities.
- Creating and maintaining operational reporting artefacts (e.g.
Risk Management Decision Item (RMDI), incident reporting, human resource (HR) investigations, lost/stolen reporting, etc.).
- Compiles and analyzes data for management reporting and metrics.
- Coordinating with CSRM Branch to create security awareness campaigns.
- Research proactively regarding needs and trends to anticipate and identify potential security problems/incidents.
- Engaging stakeholders to fulfill their requests (e.g. decommission request, assets decommission executions, etc.).
- Coordinates with other peers in CSRM Branch to research needs and trends to anticipate security problems or incidents.
- Proactively coordinating with appropriate stakeholders across GOS during a security incident – management, security, operations, and others to provide timely and relevant updates to stakeholders and decision-makers.
- Analyzing cyber security incidents to solve issues and suggest improvement in incident response procedures.
- Creating detailed reports and documentation of all incidents and procedures to the CSRM Branch, executive government, and leadership of GOS on a routine basis.
- Supporting the execution and monitoring of phishing simulation exercises, including user targeting, response tracking, and reporting.
- Responding to and resolving Privilege Access Management (PAM) related activities and service requests within defined SLAs using Service Now.
Required Qualifications
Preferred Qualifications
Certifications
#J-18808-Ljbffr
📌 Security Analyst (Regina)
🏢 Compunnel
📍 Regina