17 Aug
|
Jobtailor
|
Toronto
Hunt for TTPs, threats, risks, and vulnerabilities aligned to the MITRE ATT&CK; framework using internal and external intelligence data Identify threats, risks, and security control gaps and produce detection and mitigation recommendations to reduce the bank’s attack surface Participate in proactive attack surface reduction operations across enterprise and cloud environments Use threat intelligence, anomalous log analysis, and brainstorming-session results to detect and mitigate threats Develop methodologies to identify adversary tools, techniques, and procedures Produce metrics and dashboards identifying potential threats, suspicious or anomalous activity, and malware Tune detection infrastructure with technology teams to identify emerging threats Document best practices for hunting playbooks, procedures, and courses of action Serve as a subject matter expert in host-based and network-based hunting analysis Collaborate with intelligence, SOC, incident response, and security engineering teams Review internal processes and activities and identify improvement opportunities Influence behavior to reduce risk and strengthen the enterprise information security culture Monitor emerging issues, industry trends, and relevant changes to the security landscape Requirements ~ Bachelor’s degree in an IT/cyber-related field or equivalent experience ~ At least 7+ years of cybersecurity experience ~3+ years of experience in malware reverse engineering, threat hunting, DFIR, threat detection, or threat intelligence preferred ~ Expert knowledge of log management, security analytics, and SIEM platform mechanics ~ Experience with SIEM, SOAR, EDR, cloud-native tools, and other cybersecurity toolsets ~ Advanced knowledge of Endpoint and Identity/IAM architectures, operations, and investigations ~ Proficiency with Splunk ES, CrowdStrike, Logscale, Defender for Endpoint (MDE), MS Sentinel, and Wiz Defend ~ Hands-on experience with Netskope, Akamai,
AppOmni, Qualys, and Symantec DLP is optional/good to have ~ Deep understanding of coding, scripting, and APIs for investigations, automation, and integrations ~ Ability to identify and generate detection logic ~ Experience writing and implementing complex analytics queries, threat visualization dashboards, and large-volume data analysis using tools such as Splunk, Logscale, KQL, and syslog ~ Robust knowledge of network protocols, ports, and common services including TCP/IP, DNS, FTP, SMTP, and Active Directory ~ Extensive knowledge of Windows, Mac, and Linux endpoints, operating systems, services, file systems, and agents ~ Excellent written and oral communication skills ~ Organizational and self-directing skills ~ Ability to initiate, coordinate, prioritize, and complete responsibilities with minimal supervision ~ Ideal/preferred candidates have at least two certifications from the listed general cyber, endpoint/forensic, cloud, penetration-testing, or coding/scripting/SIEM certifications Core Competencies Demonstrates expertise in threat hunting, risk assessment, and security control gap analysis, utilizing the MITRE ATT&CK; framework and advanced cybersecurity tools. Proficient in developing detection methodologies, producing metrics, and collaborating with cross-functional teams to enhance the security posture of the organization. Highest-signal resume keywords Threat Hunting Malware Reverse Engineering SIEM Platform Mechanics Splunk ES Endpoint Security ATS Optimization Keywords Hard Skills Threat Detection Log Management Security Analytics Coding Scripting APIs Complex Analytics Queries Data Analysis Network Protocols Operating Systems Soft Skills Excellent Communication Skills Organizational Skills Self-Directing Skills Industry Keywords Cybersecurity Threat Intelligence Incident Response Cloud Security Forensics Tools & Technologies SIEM SOAR EDR Splunk CrowdStrike Logscale Defender for Endpoint MS Sentinel Wiz Defend Netskope
📌 Information Security Specialist - Attack Surface Reduction (Toronto)
🏢 Jobtailor
📍 Toronto