Senior SOC Analyst (Winnipeg)

Senior SOC Analyst (Winnipeg)

23 Aug
|
Exchange Technology Services
|
Winnipeg

23 Aug

Exchange Technology Services

Winnipeg

About Us Exchange Technology Services is a leading IT consulting company in Winnipeg and part of the Exchange Income Corporation's family of companies. We provide a wide range of services, including Managed IT, Project Management, Business Intelligence, Cyber Security, Digital Transformation, Training Services, Installation Services, and Telecommunications across Canada and the US.

If you are looking for a fast-paced career, serving enterprise customers and managing diverse IT projects, we invite you to join us.

Our work setting is dynamic, filled with learning opportunities, exciting and challenging projects, and a chance to make a positive impact on clients’ businesses. We value teamwork, fun, and achieving amazing results together.

Job Overview As a Senior SOC Analyst, you will serve as a technical escalation point within the SOC, lead complex investigations, and help advance the SOC's risk-driven detection and response capabilities. The role combines day-to-day security operations with deeper expertise in at least one of the following areas: Advanced Incident Response, Threat Hunting, SIEM Automation, or Detection Engineering.

You will independently handle complex work, mentor analysts, and translate incidents, threat intelligence, and business risks into improved use cases, detections, hunts, and automated workflows. The successful candidate should have at least three years of hands-on experience in one or more of these specialty areas; broader or multi-domain experience is preferred.

Key Responsibilities

- Serve as a senior technical escalation point for complex or high-impact security alerts and incidents, validating severity, scope, business impact, and required escalation.
- Lead security incidents through the investigation life cycle, including scoping, evidence collection, containment and remediation guidance, root-cause analysis, status reporting, and lessons learned.
- Conduct proactive threat hunting using hypotheses derived from threat intelligence, incident findings, attacker behaviours, environmental risk, and known detection gaps; document methods, evidence, and outcomes.
- Own or lead the security use case life cycle by identifying and prioritizing detection needs based on threats and business risks; defining objectives, data sources, logic, response actions, ownership, testing, and review requirements; and driving tuning, improvement, or retirement.
- Design, develop, test, validate, and tune SIEM, endpoint, or other security detections; identify coverage gaps and map detection logic to relevant threat behaviours or frameworks.
- Design, test, document, and maintain SIEM/SOAR automation and orchestration workflows that improve investigation and response consistency, reduce repetitive manual effort, and preserve appropriate approvals and audit trails.
- Translate incident, threat-hunting, and threat-intelligence findings into new or improved detections, use cases, playbooks, automation, and recommendations for security controls.
- Review use case, detection, and automation performance using operational metrics and analyst feedback,



and recommend improvements to alert quality, coverage, investigation efficiency, and response effectiveness.
- Mentor SOC Analysts, support complex investigations, and perform peer review of queries, detections, playbooks, automation, and investigation findings when appropriate.
- Maintain clear procedures, playbooks, knowledge articles, investigation records, and shift handoff documentation to support repeatable and auditable SOC operations.
- Stay current on cybersecurity threats, attacker techniques, technologies, and best practices, and apply relevant developments to SOC monitoring and detection strategy.
- Support routine monitoring and response across SIEM, EDR, email security, DLP, network security, and other SOC technologies when required.
- Support the maintenance of the Information Security Management System (ISMS) by following corporate policies and providing supporting evidence for audits when required.
- Additional responsibilities as assigned.

Qualifications EDUCATION & EXPERIENCE

- Cybersecurity Certifications such as CompTIA Security+ and CySA+
- Endpoint, cloud, identity, email security, or related advanced technical certifications considered an asset
- Mimecast – Email Security, Cloud Gateway Fundamentals Level 1 Certificate
- Advanced Incident Response, digital forensics, or threat hunting certifications considered an asset
- Crowdstrike Certified Falcon Hunter (CCFH) Certificate
- SIEM, SOAR, detection engineering, or security automation certifications considered an asset
- Splunk Certified Cybersecurity Defense Analyst
- Splunk Core Certified Advanced Power User Certificate considered an asset
- At least three years of hands-on experience in one or more of the following specialty areas, supported by practical experience in SOC, cybersecurity operations, incident response, or a similar environment: Advanced Incident Response - leading complex investigations, scoping compromise, correlating evidence across multiple data sources, coordinating containment and remediation, and producing defensible findings.
- Threat Hunting - developing and executing hunt hypotheses, analyzing large security datasets, identifying abnormal attacker behaviour, and converting findings into repeatable detections or monitoring opportunities.
- SIEM Automation - building or improving repeatable investigation and response workflows using SIEM/SOAR capabilities, scripting, APIs, integrations, or low-code automation.
- Detection Engineering - designing detection logic, creating complex queries or rules, testing and validating detections, tuning false positives, documenting logic, and assessing detection coverage.

Knowledge, Skills & Abilities

- Strong ability to search, interpret,



and correlate security logs from multiple sources and create or modify advanced SIEM queries.
- Working knowledge of MITRE ATT&CK; or a comparable framework used to describe attacker behaviours, support threat hunting, and assess detection coverage.
- Strong understanding of common threat vectors, indicators of compromise, identity and cloud threats, network activity, endpoint telemetry, and layered security controls.
- Experience with core SOC technologies and workflows such as SIEM, SOAR, endpoint detection and response, email security, threat intelligence, and network security.
- Ability to independently investigate ambiguous security events, make evidence-based decisions, document findings clearly, and communicate technical risk to analysts, customers, and leadership.
- Practical understanding of risk-driven security use case management, including prioritization, requirements, ownership, testing, validation, review, metrics, continuous improvement, and retirement.
- Experience working in a managed security services or multi-customer environment.
- Experience with SOAR or security automation platforms, Python or PowerShell scripting, REST APIs, JSON, webhooks, or version control.
- Experience maintaining a use case or detection backlog, inventory, review cycle, coverage assessment, or related quality metrics.
- Experience with threat intelligence, malware analysis, reverse engineering, or advanced forensic investigation techniques.
- Microsoft 365 and Exchange Online investigation experience, including identity, audit, message trace, header analysis, and email security controls.
- Familiarity with security risk assessment, risk management, ITIL, and ITSM platforms.
- Experience creating and maintaining operational reports, dashboards, metrics, or other evidence used to evaluate SOC effectiveness.
- Experience mentoring analysts, leading technical investigations, or contributing to continuous improvement of SOC processes.
- Familiarity with SOC maturity models or risk-driven SOC operating practices.

WORKING CONDITIONS

- Must be able to obtain and maintain a clear criminal record check
- Physically able to perform all listed job duties
- Work performed primarily in an office environment
- Manual dexterity required to use desktop computer and telephone
- Various shifts at a fast pace to meet service level requirements of our clients

What We Offer

- Competitive salary and benefits package
- Registered Retirement Savings Plan with Company Matching
- Employee Share Purchase Plan
- Onsite Gym
- Subsidized Phone Plan
- Opportunities for career development and career growth
- Collaborative and innovative work environment

If this sounds like an opportunity you would like to be a part of, please apply! Please note, Exchange Technology Services is an equal opportunity employer. We are committed to building a diverse and inclusive workplace and encourage applications from all qualified individuals. Accommodations are available upon request throughout the recruitment process. Please reach out to [email protected] if you have any questions.

📌 Senior SOC Analyst (Winnipeg)
🏢 Exchange Technology Services
📍 Winnipeg

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior soc analyst (winnipeg) / winnipeg

Subscribe to this job alert:

Get the latest job offers by email for: senior soc analyst (winnipeg) / winnipeg