22 Aug
|
Jobtailor
|
Toronto
- Hunt for TTPs, threats, risks, and vulnerabilities aligned to the MITRE ATT&CK framework using internal and external intelligence data- Identify threats, risks, and security control gaps and produce detection and mitigation recommendations to reduce the bank’s attack surface- Participate in proactive attack surface reduction operations across enterprise and cloud environments- Use threat intelligence, anomalous log analysis, and brainstorming-session results to detect and mitigate threats- Develop methodologies to identify adversary tools, techniques, and procedures- Produce metrics and dashboards identifying potential threats, suspicious or anomalous activity, and malware- Tune detection infrastructure with technology teams to identify emerging threats- Document best practices for hunting playbooks, procedures, and courses of action- Serve as a subject matter expert in host-based and network-based hunting analysis- Collaborate with intelligence, SOC, incident response, and security engineering teams- Review internal processes and activities and identify improvement opportunities- Influence behavior to reduce risk and strengthen the enterprise information security culture- Monitor emerging issues, industry trends, and relevant changes to the security landscapeRequirements- Bachelor’s degree in an IT/cyber-related field or equivalent experience- At least 7+ years of cybersecurity experience- 3+ years of experience in malware reverse engineering, threat hunting, DFIR, threat detection, or threat intelligence preferred- Expert knowledge of log management, security analytics, and SIEM platform mechanics- Experience with SIEM, SOAR, EDR, cloud-native tools, and other cybersecurity toolsets- Advanced knowledge of Endpoint and Identity/IAM architectures, operations, and investigations- Proficiency with Splunk ES, CrowdStrike, Logscale, Defender for Endpoint (MDE), MS Sentinel, and Wiz Defend- Hands-on experience with Netskope, Akamai, AppOmni, Qualys,
and Symantec DLP is optional/good to have- Deep understanding of coding, scripting, and APIs for investigations, automation, and integrations- Ability to identify and generate detection logic- Experience writing and implementing complex analytics queries, threat visualization dashboards, and large-volume data analysis using tools such as Splunk, Logscale, KQL, and syslog- Robust knowledge of network protocols, ports, and common services including TCP/IP, HTTP/S, DNS, FTP, SMTP, and Active Directory- Extensive knowledge of Windows, Mac, and Linux endpoints, operating systems, services, file systems, and agents- Excellent written and oral communication skills- Organizational and self-directing skills- Ability to initiate, coordinate, prioritize, and complete responsibilities with minimal supervision- Ideal/preferred candidates have at least two certifications from the listed general cyber, endpoint/forensic, cloud, penetration-testing, or coding/scripting/SIEM certificationsCore CompetenciesDemonstrates expertise in threat hunting, risk assessment, and security control gap analysis, utilizing the MITRE ATT&CK framework and advanced cybersecurity tools. Proficient in developing detection methodologies, producing metrics, and collaborating with cross-functional teams to enhance the security posture of the organization.Highest-signal resume keywords- Threat Hunting- Malware Reverse Engineering- SIEM Platform Mechanics- Splunk ES- Endpoint SecurityATS Optimization KeywordsHard Skills- Threat Detection- Log Management- Security Analytics- Coding- Scripting- APIs- Complex Analytics Queries- Data Analysis- Network Protocols- Operating SystemsSoft Skills- Excellent Communication Skills- Organizational Skills- Self-Directing SkillsIndustry Keywords- Cybersecurity- Threat Intelligence- Incident Response- Cloud Security- ForensicsTools & Technologies- SIEM- SOAR- EDR- Splunk- CrowdStrike- Logscale- Defender for Endpoint- MS Sentinel- Wiz Defend- Netskope#J-18808-Ljbffr
📌 Information Security Specialist (Toronto)
🏢 Jobtailor
📍 Toronto