04 Sep
|
407 ETR Concession Company
|
Winnipeg
04 Sep
407 ETR Concession Company
Winnipeg
Title: Sr. IT Security AnalystDepartment: Information TechnologyLocation: 6300 Steeles Ave West, WoodbridgeTotal Potential Compensation: $115,000-$140,000Position SummaryThe Senior Security Analyst – Security Operations is responsible for operating, maturing, and continuously improving core cyber defense and detection capabilities across the enterprise. This role has a robust focus on Vulnerability Management, Endpoint Detection & Response (EDR), Network Detection & Response (NDR), and day‑to‑day Security Operations. The incumbent will act as a senior technical resource within the SOC, providing advanced analysis, threat-driven prioritization, and operational leadership across security monitoring, incident response, vulnerability remediation, and control effectiveness measurement. The role directly contributes to improving the organization’s cyber risk posture, with measurable outcomes reflected in Security Risk Index (SRI) and other governance metrics aligned to NIST and ISO frameworks. After‑hours support and on‑call duties may be required for high‑severity security incidents.Position ResponsibilitiesVulnerability ManagementOwn and operate the enterprise vulnerability management lifecycle, including discovery, assessment, prioritization, remediation tracking, and risk acceptanceCorrelate vulnerability data with asset criticality, exploitability, threat intelligence, and exposure to drive risk‑based remediationTrack remediation SLAs and elevate overdue or accepted risks through appropriate governance channelsSupport internal and external audit evidence for vulnerability management controlsContribute vulnerability metrics to executive and risk committee reporting (e.G., SRI/NSRI)Security Operations & Incident ResponseAct as a senior escalation point for security incidents, providing deep technical analysis, containment guidance, and remediation recommendationsLead investigation of alerts generated by EDR, NDR, SIEM, and security analytics platformsCoordinate incident response activities across IT Infrastructure, Network, Cloud, and Application teamsDevelop and maintain incident response playbooks, runbooks, and escalation proceduresSupport post‑incident reviews, root cause analysis, and lessons learned trackingEndpoint Detection & Response (EDR)Operate and tune EDR platforms to improve detection fidelity, reduce false positives, and enhance response effectivenessAnalyze endpoint telemetry for indicators of compromise (IOC), anomalous behavior, and threat actor activitySupport endpoint containment actions such as process isolation,
host quarantine, and forensic data collectionPartner with IT Operations to ensure EDR coverage, health, and policy compliance across endpointsNetwork Detection & Response (NDR)Operate and maintain NDR capabilities, including alert triage, investigation, and threat huntingAnalyze network traffic, metadata, and behavior‑based detections to identify lateral movement, command‑and‑control activity, and policy violationsCollaborate with Network teams to validate detections and improve network security controls and segmentationUse NDR telemetry to validate network segmentation effectiveness and control gapsThreat Detection & Threat HuntingPerform proactive threat hunting using EDR, NDR, SIEM, and log analytics platformsApply MITRE ATT&CK;–aligned techniques to identify stealthy or low‑signal threatsIntegrate external threat intelligence into detection and hunting activitiesRecommend detection engineering improvements to SOC tooling and analyticsMetrics, Risk & ComplianceDefine and maintain security operations KPIs and KRIs (incident trends, MTTR, vulnerability aging, control coverage)Contribute to Security Risk Index (SRI) calculations and continuous improvement initiativesEnsure alignment with NIST CSF, ISO 27001/27002, and internal security standardsSupport audits by providing defensible evidence of control operation and effectivenessContinuous Improvement & LeadershipMentor junior analysts and provide technical guidance within the SOCIdentify opportunities to improve automation, orchestration, and response workflowsParticipate in security architecture reviews and technology evaluations related to detection and responseContribute to the development of security standards, procedures, and operational playbooksIdentity & Access Management (IAM)Support operational security of IAM platforms (e.G., Active Directory, Azure AD / Entra ID, PAM solutions)Monitor and investigate identity‑based threats, including credential misuse, privilege escalation, and anomalous authentication behaviorCorrelate IAM events with EDR, NDR, and SIEM telemetry during incident investigationsSupport access reviews, entitlement validation,
and privileged access oversight in collaboration with IAM and IT teamsAssist with detection and response use cases related to compromised accounts, excessive privileges, service account misuse, and lateral movement via identityContribute to IAM‑related risk metrics and control effectiveness reporting (e.G., MFA coverage, privileged account exposure)Support audit evidence for IAM controls aligned to NIST CSF PR.AA, ISO 27001 A.5/A.8, and internal access standardsQualificationsMinimum 5+ years of experience in IT Security, with strong hands‑on experience in Security OperationsCollege Diploma or University Degree in Computer Science, Engineering, or related fieldExperience with EDR platforms (e.G., endpoint containment, alert triage, investigation)Experience with NDR technologies and network‑based threat detectionExperience in Security Incident Response and InvestigationStrong understanding of attacker techniques and defensive controls (MITRE ATT&CK;)Experience working in regulated or audit‑driven environmentsHands‑on experience supporting IAM security operations, including identity monitoring and access control validationStrong understanding of authentication, authorization, MFA, RBAC, and privileged access conceptsExperience analyzing identity logs and alerts within SIEM or security analytics platformsPreferred QualificationsExperience with enterprise SOC tooling including SIEM, EDR, NDR, SOARExperience operating security controls in hybrid (on‑prem and cloud) environmentsFamiliarity with Security Risk Index (SRI), cyber risk metrics, or risk‑based reportingKnowledge of network architecture and segmentation conceptsOne or more of the following certifications:CISSPCISMGCIA / GCED / GCEDR / GCIHCompTIA Security+SANS Blue Team certificationsWe are actively seeking to fill this role as it is a current vacancy.We are committed to fostering a diverse, equitable, and inclusive work environment. We value the unique perspectives and backgrounds of all individuals, and we firmly believe that our individual differences make us stronger as a whole. Our commitment to inclusion extends beyond recruitment and encompasses an inclusive workplace culture through raising awareness, ongoing training, and encouraging feedback. We aim to create a protected and supportive environment where all employees can thrive. Accommodation for disabilities or other grounds protected by human rights legislation are available upon request for candidates taking part in all aspects of the employment selection process.#J-18808-Ljbffr
📌 Sr. It Security Analyst - $115,000 - $140,000 A Year (Winnipeg)
🏢 407 ETR Concession Company
📍 Winnipeg