19 Aug
|
Jobtailor
|
Toronto
- Lead a team of subject matter experts and analysts to ensure Information Security is managed and continuously improved in line with Bank policy and procedure.
- Supporting the development and progression of the Information Security Analyst team from both a technical and professional perspective.
- Incident Triage, Response, and Investigations based on Alerts received from multiple sources which include:
- Cloud Infrastructure/Security.
- Endpoint Detection and Response.
- Perimeter detection tooling.
- Conduct Quality Assurance for Triage case handling, mitigation actions and shift handover, collating lessons learned and implementing improvements where required.
- Interpret logs from a variety of sources (e.g. cloud, endpoint, network) to identify root cause and determine next steps for containment, eradication and recovery as part of incident response activities.
- Work together with other teams in the organisation to analyse, contain, eradicate and recover from cyber security incidents - Continuous development and maintaining of incident handling, response and readiness processes.
- Support the wider SecOps team with detection engineering - creating and optimising analytic triggers to enhance alert efficacy - and threat hunting based on threat intelligence.
- Documentation of incidents and investigations, including analysis findings, containment steps and root cause.
- Plan and participate in Tabletop Exercises.
- Present investigation findings to technical and non-technical audiences.
Requirements - 5+ years experience in an in-house SOC role and team, including cyber incident response and digital forensics function.
- Experience in a similar role leading,
developing and motivating a team of subject matter experts and other managers in Information and Cyber Security.
- Understanding of AWS Security Solutions (or other Public Cloud Solutions) - Analysis and Incident Response experience with Cloud systems (GCP, AWS) - Experience working and supporting analytics/SIEM platforms.
- Experience supporting and conducting Incident Response engagements.
- Experience in endpoint based investigations.
- Experience in cloud based investigations.Experience with Incident Command and conducting Tabletop Exercises.
- Experience in acting as both Commander and SME during incidents and investigations.
- Be a Self Starter with the ability to lead, inspire and drive change through an organisation.
- Excellent communication skills (both verbal and written), ability to communicate technical concepts to both technical and non-technical audiences.
- Demonstrated teamwork and collaboration skills as part of a multi-functional team - Time management, problem-solving and interpersonal skills.
- Eagerness to learn and apply knowledge to new security challenges.
- Willingness to share knowledge with the team and mentor colleagues.
- A high level understanding of mobile, network and operating system security controls.
- Preferred - Experience in forensics: cloud (GCP,
AWS); endpoint/server (Windows, MacOS, Linux); and/or network.
- Any experience of programming in Python, Go and/or Java.
- A Cyber/Information Security related degree and/or relevant cyber security qualification(s) would be desired but not required - Understanding of malware analysis techniques Core Competencies Demonstrates expertise in Incident Response, Cyber Security, and Team Leadership, with a solid focus on Cloud Security Solutions and forensic analysis. Capable of effectively communicating technical concepts to diverse audiences while driving continuous improvement in security processes. Highest-signal resume keywords - Incident Response Management - Cloud Security Solutions (AWS, GCP) - Team Leadership and Development - Forensics (Cloud, Endpoint, Network) - Analytic/SIEM Platform Support ATS Optimization Keywords Hard Skills - Incident Triage - Digital Forensics - Cloud Investigations - Endpoint Investigations - Malware Analysis Techniques - Python Programming - Go Programming - Java Programming - Quality Assurance - Threat Hunting Soft Skills - Excellent Communication Skills - Teamwork and Collaboration - Time Management - Problem-Solving - Interpersonal Skills Certifications & Qualifications - Cyber/Information Security Degree - Relevant Cyber Security Qualifications Industry Keywords - Information Security - Cyber Security - Incident Response - Security Operations Center (SOC) - Tabletop Exercises Tools & Technologies - Cloud Infrastructure/Security - Endpoint Detection and Response - Perimeter Detection Tooling - SIEM Platforms - Incident Command Tools
📌 Information Security Operations Lead (Toronto)
🏢 Jobtailor
📍 Toronto