02 Aug
|
Pengcorp
|
Calgary
Hiring Location: Calgary, AB (Hybrid/Client Site) Employment Type: Full TimePosition OverviewThe Coordinator, Cybersecurity Incident Management & Monitoring (SOC/NOC) is responsible for the coordination, monitoring, analysis, and escalation of cybersecurity and network operational events affecting critical infrastructure environments within the Oil & Gas, Power Generation, Utilities, and Industrial Operations sectors. This role serves as a key operational resource within a Security Operations Center (SOC) and Network Operations Center (NOC), ensuring the continuous monitoring, detection, prevention, investigation, and response to cybersecurity threats and operational anomalies impacting Information Technology (IT), Operational Technology (OT), Industrial Control Systems (ICS), SCADA networks, and critical energy infrastructure.The Coordinator works closely with cybersecurity analysts, network engineers, plant operations personnel, control system specialists, and client stakeholders to maintain compliance, improve threat visibility, and support incident response activities that protect production, safety, reliability, and regulatory obligations.Key ResponsibilitiesSecurity Monitoring & Incident Prevention- Continuously monitor SOC/NOC dashboards, SIEM platforms, network monitoring tools, and OT security systems for suspicious activity and operational anomalies.- Review automated alerts and perform initial triage, validation, categorization, and prioritization of security incidents.- Identify indicators of compromise (IOCs), threat intelligence alerts, malware activity, network intrusions, unauthorized access attempts, and abnormal OT system behavior.- Coordinate preventative actions to minimize cybersecurity risks to industrial control and business systems.- Maintain awareness of emerging cyber threats affecting critical infrastructure, energy, and industrial sectors.- Coordinate incident response activities according to established cybersecurity incident management procedures.- Escalate security events to cybersecurity analysts, engineers, leadership teams, and client representatives as appropriate.- Document incident timelines, findings, actions taken, and lessons learned.- Support containment, eradication, recovery, and post-incident review activities.- Participate in cyber incident simulations, tabletop exercises, and emergency response drills.Network Operations Monitoring- Monitor network performance, availability, and health across enterprise and OT environments.- Coordinate response activities related to communication failures,
network outages, and system performance issues.- Track service interruptions and assist in managing incident resolution processes.- Ensure accurate incident logging and ticket management within designated platforms.OT / IC Security Support- Monitor industrial environments including:- SCADA Systems- Distributed Control Systems (DCS)- PLC Networks- Historians- Industrial Ethernet Networks- Power Generation Control Systems- Pipeline Monitoring Systems- Remote Terminal Units (RTUs)- Assist with asset inventory management for OT and IC environments.- Support cybersecurity assessments and vulnerability management activities.- Coordinate maintenance windows and security-related operational activities with facility personnel.Compliance & Governance- Support compliance activities related to:- NERC-CIP- NIST Cybersecurity Framework- IEC 62443- ISO 27001- TSA Pipeline Security Directives- CIS Controls- Maintain operational records and evidence required for audits and regulatory reviews.- Ensure adherence to internal cybersecurity policies and client requirements.Reporting & Documentation- Prepare daily, weekly, and monthly operational reports.- Generate cybersecurity incident summaries and executive dashboard metrics.- Track:- Incident volumes- Threat trends- Mean Time to Detect (MTTD)- Mean Time to Respond (MTTR)- System availability metrics- Service level compliance- Maintain operational procedures, runbooks, and escalation matrices.Required QualificationsEducation- Diploma or Bachelor’s Degree in:- Cybersecurity- Information Technology- Computer Science- Network Engineering- Industrial Automation- Engineering Technology- Related DisciplineExperience- 3–7 years of experience in:- Security Operations Centers (SOC)- Network Operations Centers (NOC)- Cybersecurity Operations- Industrial Control Systems Security- Critical Infrastructure Operations- Experience supporting energy sector clients is strongly preferred.Technical Knowledge.Familiarity with:Cybersecurity Technologies- SIEM Platforms (Microsoft Sentinel, Splunk, QRadar, Securonix, CrowdStrike,
FortiSIEM)- Security Orchestration and Automation (SOAR)- Vulnerability Management ToolsNetwork Technologies- TCP/IP- Routing & Switching- VPN Technologies- Firewalls- Wireless Networks- Network Monitoring PlatformsOT/ICS Technologies- SCADA Systems- DCS Platforms- PLC Networks- OPC Communications- Modbus- DNP3- IEC 61850- Industrial Ethernet ArchitecturesPreferred Certifications- Nozomi Networks Advanced Troubleshooting (NNAT)- GIAC Certified Incident Handler (GCIH)- CISSP- GICSP (Global Industrial Cyber Security Professional)- Security+- CySA+- CISM- GIAC Certifications- Cisco CCNA / CCNP (Security) or equivalent- Microsoft Security Certifications- IEC 62443 Cybersecurity Fundamentals Specialist- Robust analytical and investigative skills- Excellent situational awareness and decision-making ability- Ability to manage multiple incidents simultaneously- Robust communication and stakeholder management skills- High attention to detail- Critical thinking and problem-solving capabilities- Ability to work effectively under pressure in a 24/7 operational environment- Strong understanding of operational risk management and critical infrastructure protectionPhysical & Work Environment Requirements- Ability to work rotating shifts- Participation in on-call support rotations as required.- Occasional travel to client sites, plants, substations, power generation facilities, refineries, terminals, pipelines, and industrial operations.- Ability to obtain client-specific security clearances and site access permissions.Success MeasuresThe Coordinator will be evaluated on:- Reduction in cybersecurity incident exposure.- Timely detection and escalation of security events.- Compliance with client and regulatory requirements.- Accuracy and completeness of reporting.- Continuous improvement of SOC/NOC operational processes.- Client satisfaction and operational reliability metrics.Typical Systems & Environments Supported- Securonix- Microsoft Sentinel- QRadar- Active Directory & Identity Services- Microsoft Server Infrastructure- SCADA Systems- Power Generation Assets- Firewalls & Security Appliances- Critical Infrastructure Systems- Operational Technology EnvironmentsThis position is critical to protecting the operational integrity, safety, reliability, and cyber resilience of energy-sector clients. The successful candidate will play a frontline role in defending industrial and power generation environments against evolving cyber threats while ensuring the uninterrupted operation of critical infrastructure assets.#J-18808-Ljbffr
📌 Coordinator, Incident Management & Monitoring Center (Calgary)
🏢 Pengcorp
📍 Calgary