24 Aug
|
Jobtailor
|
Toronto
- Hunt for TTPs, threats, risks, and vulnerabilities aligned to the MITRE ATT&CK; framework using internal and external intelligence data - Identify threats, risks, and security control gaps and produce detection and mitigation recommendations to reduce the bank’s attack surface - Participate in proactive attack surface reduction operations across enterprise and cloud environments - Use threat intelligence, anomalous log analysis, and brainstorming-session results to detect and mitigate threats - Develop methodologies to identify adversary tools, techniques, and procedures - Produce metrics and dashboards identifying potential threats, suspicious or anomalous activity, and malware - Tune detection infrastructure with technology teams to identify emerging threats - Document best practices for hunting playbooks, procedures, and courses of action - Serve as a subject matter expert in host-based and network-based hunting analysis - Collaborate with intelligence, SOC, incident response, and security engineering teams - Review internal processes and activities and identify improvement opportunities - Influence behavior to reduce risk and strengthen the enterprise information security culture - Monitor emerging issues, industry trends, and relevant changes to the security landscape Requirements - Bachelor’s degree in an IT/cyber-related field or equivalent experience - At least 7+ years of cybersecurity experience - 3+ years of experience in malware reverse engineering, threat hunting, DFIR, threat detection, or threat intelligence preferred - Expert knowledge of log management, security analytics, and SIEM platform mechanics - Experience with SIEM, SOAR, EDR, cloud-native tools, and other cybersecurity toolsets - Advanced knowledge of Endpoint and Identity/IAM architectures, operations, and investigations - Proficiency with Splunk ES, CrowdStrike, Logscale, Defender for Endpoint (MDE), MS Sentinel, and Wiz Defend - Hands-on experience with Netskope, Akamai, AppOmni, Qualys,
and Symantec DLP is optional/valuable to have - Deep understanding of coding, scripting, and APIs for investigations, automation, and integrations - Ability to identify and generate detection logic - Experience writing and implementing complex analytics queries, threat visualization dashboards, and large-volume data analysis using tools such as Splunk, Logscale, KQL, and syslog - Strong knowledge of network protocols, ports, and common services including TCP/IP, HTTP/S, DNS, FTP, SMTP, and Active Directory - Extensive knowledge of Windows, Mac, and Linux endpoints, operating systems, services, file systems, and agents - Excellent written and oral communication skills - Organizational and self-directing skills - Ability to initiate, coordinate, prioritize, and complete responsibilities with minimal supervision - Ideal/preferred candidates have at least two certifications from the listed general cyber, endpoint/forensic, cloud, penetration-testing, or coding/scripting/SIEM certifications Core Competencies Demonstrates expertise in threat hunting, risk assessment, and security control gap analysis, utilizing the MITRE ATT&CK; framework and advanced cybersecurity tools. Proficient in developing detection methodologies, producing metrics, and collaborating with cross-functional teams to enhance the security posture of the organization. Highest-signal resume keywords - Threat Hunting - Malware Reverse Engineering - SIEM Platform Mechanics - Splunk ES - Endpoint Security ATS Optimization Keywords Hard Skills - Threat Detection - Log Management - Security Analytics - Coding - Scripting - APIs - Complex Analytics Queries - Data Analysis - Network Protocols - Operating Systems Soft Skills - Excellent Communication Skills - Organizational Skills - Self-Directing Skills Industry Keywords - Cybersecurity - Threat Intelligence - Incident Response - Cloud Security - Forensics Tools & Technologies - SIEM - SOAR - EDR - Splunk - CrowdStrike - Logscale - Defender for Endpoint - MS Sentinel - Wiz Defend - Netskope
📌 Information Security Specialist – Attack Surface Reduction (Toronto)
🏢 Jobtailor
📍 Toronto