17 Sep
|
CYBERWELL
|
Winnipeg
17 Sep
CYBERWELL
Winnipeg
CYBERWELL is the new name behind North America's most trusted cybersecurity brands – Source44, Seekintoo, Cycura, and Proack Security. Now under one banner, we're scaling our impact with a fresh vision, a stronger portfolio, and a renewed commitment to helping organizations build lasting resilience in today's evolving threat landscape. In today's threat landscape, complexity is the constant. At CYBERWELL, we're built to help organizations not just keep up but get ahead. CYBERWELL is a cybersecurity company purpose built for scale, change, and the realities of modern enterprise. We deliver integrated solution that span the full cybersecurity lifecycle-from offensive security exposure management to GRC, architecture and engineering, threat intelligence, and 24/7 managed detection and response. We partner with enterprise leaders who are navigating regulatory pressure, evolving risk, and growing infrastructure. Whether it's a healthcare provider safeguarding patient data, a government agency defending critical systems, or a tech or financial firm scaling securely - our team helps unify strategy, reduce complexity, and strengthen cyber resilience.
Why it matters: Cybersecurity isn't just a technical issue - it's a business imperative. From compliance and operational uptime to reputation and trust, we help organizations protect what matters most, stay ahead of threats, and build the foundation for long-term success. We're not just another vendor. We're your cybersecurity partner - relentlessly focused on outcomes, backed by world-class talent, and obsessed with your success.
About the Role The SOC Analyst - Tier 2 is a key escalation and incident response role within the CYBERWELL CYBERSOC. You will investigate complex security events across multiple client environments, validate and scope potential incidents, execute authorized containment actions, and provide clear technical guidance to Tier 1 analysts.
This role is well suited to an analyst who is comfortable working independently, making sound decisions under pressure, and moving beyond initial alert triage into deeper investigation and response. You will work across technologies including Microsoft Sentinel, Cortex XSOAR, EDR/XDR, network security platforms, and cloud environments while supporting government and highly regulated clients.
Following onboarding and training, this position will primarily support our night shift as part of CYBERWELL’s 24/7/365 security operations model. You will play an important role in strengthening overnight escalation coverage and ensuring complex incidents can be investigated and acted on without waiting for daytime resources.
Key Responsibilities
Investigate escalated security alerts and incidents across SIEM, SOAR, EDR/XDR, identity, network, and cloud security platforms
Perform advanced investigation and correlation using logs, endpoint telemetry, threat intelligence, and other available data sources
Determine incident scope, severity, impact, and required response actions using sound technical judgment and client-specific procedures
Execute authorized containment and response actions, including host isolation, account or session containment, and other approved measures in accordance with client-specific SOPs
Own escalated cases through resolution, client escalation, or structured handoff, ensuring analysis and actions are complete and defensible
Act as an escalation point for Tier 1 analysts, providing investigative guidance, escalation review, and coaching to improve case quality
Maintain detailed, high-quality case documentation and produce transparent client-facing notes describing findings, impact, actions taken, and next steps
Participate in incident calls and client interactions as a technical subject matter contributor when required
Maintain situational awareness across multiple concurrent incidents and client environments, including during overnight operations
Contribute to continuous improvement of playbooks, runbooks, detection fidelity, response procedures, and operational workflows
Qualifications
2-4 years of experience in a SOC, incident response, or cybersecurity operations environment, with demonstrated experience performing advanced security investigations (Essential)
Experience in an MSSP or multi-tenant environment is strongly preferred
Hands-on experience with:
SIEM platforms and investigative query workflows (Microsoft Sentinel and KQL preferred)
SOAR platforms and response automation (Cortex XSOAR preferred)
EDR/XDR, identity, network security tools, and log analysis workflows
Working knowledge of
TCP/IP networking, Windows/Linux security fundamentals, and authentication workflows
Common attack techniques, indicators of compromise, and incident response / containment practices
MITRE ATT&CK; framework and practical application during investigation
Ability to work independently, prioritize concurrent incidents,
and make sound escalation and containment decisions within defined authority
Strong written and verbal communication skills with an emphasis on clear, precise, and defensible analysis
Preferred Certifications
CompTIA CySA+ or Security+
Microsoft SC-200, SC-100, SC-300, or SC-500 are preferred
ISC² SSCP, GIAC GCIH, or equivalent security operations / incident response certification
Work Requirements
Participation in a 24/7/365 coverage model, with primary assignment to night shift following completion of onboarding and training
Training and onboarding may be completed on day or evening shifts before transition to the primary night-shift schedule
Must be a Canadian Citizen or Permanent Resident
Must be eligible to obtain and maintain required security clearances
Ability to operate effectively and independently in a high-volume environment, including periods with limited overnight supervision
Pay range and compensation package The salary offered for this position falls within a specified salary range and will be determined based on a variety of factors, including but not limited to the candidate's experience, qualifications, skills, and the specific needs of the organization.
There are shift premiums for evening and night shifts included.
CYBERWELL offers a comprehensive benefits package, including:
Life insurance
Accidental Death and Dismemberment (AD&D;) insurance
Extended health and dental coverage
Long-term disability coverage The salary offered for this position falls within a specified salary range and will be determined based on a variety of factors, including but not limited to the candidate's experience, qualifications, skills, and the specific needs of the organization.
At WELL, we believe in fair and equitable compensation, and our goal is to offer a competitive salary that reflects the value and expertise of the selected candidate.
WELL is committed to supporting a diverse, inclusive, and accessible workplace. We welcome and celebrate the diversity of applicants and team members across ability, race, gender identity, sexual orientation, and perspective. We strive to create an inclusive workplace where differences are celebrated and fuel our success - this is the WELL Way!
WELL has been independently certified as a Great Place to Work by Great Place to Work Institute Canada, an achievement that reflects the company’s strong commitment to creating a workplace culture centered on trust, inclusivity, and employee well-being, aligning with its 'Healthy Place to Work' ESG strategy pillar. Want Read more about us: https://stories.well.company/
📌 Cyber Security Analyst (Winnipeg)
🏢 CYBERWELL
📍 Winnipeg