09 Sep
|
Spait Infotech
|
Saint-Esprit, Quebec
09 Sep
Spait Infotech
Saint-Esprit, Quebec
Key Responsibilities
- Monitor security alerts and events from SIEM, EDR/XDR, firewall, IDS/IPS, antivirus, email security, and other security tools.
- Perform real-time monitoring of security events in a 24×7 SOC environment.
- Investigate and triage security alerts based on severity, priority, and potential business impact.
- Identify false positives and distinguish them from genuine security incidents.
- Perform initial investigation and incident analysis using logs, alerts, endpoint data, and network activity.
- Analyze Indicators of Compromise (IOCs) such as IP addresses, domains, URLs, file hashes, and suspicious processes.
- Investigate common threats including:
- Phishing and malicious emails
- Malware and ransomware
- Brute-force attacks
- Unauthorized access
- Account compromise
- Suspicious PowerShell activity
- Data exfiltration
- Network intrusion
- Escalate confirmed or complex incidents to L2/L3 analysts, Incident Response, or Security Engineering teams.
- Create and maintain detailed incident tickets and investigation documentation.
- Perform basic threat hunting and identify suspicious patterns across security data.
- Correlate events across multiple security platforms to identify attack activity.
- Follow defined SOPs, playbooks, escalation procedures, and SLAs.
- Participate in incident response activities, including containment and remediation support.
- Support vulnerability management and security monitoring activities when required.
- Track emerging threats, vulnerabilities, malware campaigns, and attack techniques.
- Contribute to improving detection rules, SIEM use cases, and SOC processes.
- Prepare daily, weekly, and monthly security monitoring reports.
Required Technical Skills
- Good understanding of Cybersecurity fundamentals.
- Robust knowledge of networking concepts:
- TCP/IP
- DNS
- HTTP/HTTPS
- VPN
- Firewalls
- Proxies
- Network protocols
- Hands-on experience with SIEM tools, such as:
- Microsoft Sentinel
- Splunk
- IBM QRadar
- LogRhythm
- Elastic Security
- Knowledge of endpoint security/EDR tools such as Microsoft Defender, CrowdStrike, or SentinelOne.
- Understanding of Windows and Linux security logs.
- Knowledge of authentication technologies such as Active Directory, Azure AD/Entra ID, MFA, and SSO.
- Ability to perform log analysis and event correlation.
- Understanding of malware, phishing, vulnerability, and common attack techniques.
- Familiarity with MITRE ATT&CK;, IOC analysis, and threat intelligence.
- Basic knowledge of incident response and digital forensics.
- Familiarity with security frameworks such as NIST, ISO 27001, or CIS Controls is an advantage.
SIEM / Query Skills
Candidates should have experience with or willingness to learn SIEM query languages, such as:
- KQL – Microsoft Sentinel / Defender
- SPL – Splunk
- AQL – IBM QRadar
- Elasticsearch Query / KQL – Elastic Security
📌 SOC Analyst - saint-esprit (Saint-Esprit, Quebec)
🏢 Spait Infotech
📍 Saint-Esprit, Quebec