25 Sep
|
Hitachi Cyber
|
Montreal
25 Sep
Hitachi Cyber
Montreal
Join Hitachi Cyber, a global leader in cybersecurity, and become part of a dynamic team of experts dedicated to protecting organizations across various industries. As an Information Security Specialist, you’ll play a key role in delivering cutting‑edge security services, leveraging tools like Microsoft Sentinel and Google SecOps (Chronicle) to detect, respond, and prevent threats.
You’ll play a key role in quality assurance, vulnerability management coordination, reporting, and proactive threat analysis and helping clients strengthen their security posture and stay ahead of emerging threats.
Your mission:
- Investigate and triage alerts in Google SecOps, using entity context, timelines, and case views to understand the full scope of an incident.
- Write and refine UDM search queries for investigations, threat hunting, and reporting, and build dashboards that give clients visibility into their setting.
- Review and tune existing detection rules in Google SecOps, working with engineering to adjust thresholds, reference lists, and exclusions to cut down on false positives.
- Use curated detections, threat intelligence feeds, and risk scoring to prioritize what matters and elevate appropriately.
- Support the onboarding of new log sources into Google SecOps, validating that events are ingesting correctly and flagging parsing or field‑mapping issues to the engineering team.
- Work with SOAR playbooks in Google SecOps to streamline triage and enrichment, and suggest improvements where manual steps are slowing the team down.
- Perform quality assurance reviews of SOC‑generated incidents to ensure alerts from Microsoft Sentinel, Google SecOps, and other SIEM platforms are accurately captured,
classified, and escalated.
- Collaborate with SOC analysts and engineering teams to improve alert fidelity, rule tuning, and incident‑handling procedures.
- Prepare monthly operational and security performance reports and deliver presentations to clients, summarizing key metrics, incident trends, and improvement actions.
- Schedule and track vulnerability scans, ensuring scans are completed on time and results are communicated to relevant stakeholders.
- Support the onboarding and validation of new log sources, ensuring they are properly integrated into SIEM platforms for effective monitoring.
- Maintain and update documentation for alert flows, incident management procedures, and escalation paths.
- Conduct threat hunting activities and recommend new correlation rules or detections based on emerging threats, attack trends, or recent incidents.
- Contribute to continuous improvement efforts by identifying recurring issues, false positives, or detection gaps and recommending corrective actions.
- Provide expert guidance and support to clients on security‑related issues.
- Lead complex incident response cases and provide post‑incident recommendations.
- Mentor and coach junior analysts in technical and procedural areas.
- Participate in on‑call rotations and security investigations.
What we���re looking for:
- 3–5 years of experience in a security operations environment (SOC).
- A strong customer service mindset and ability to communicate clearly with both technical and non‑technical audiences.
- Bachelor's degree or equivalent skilled experience in a related field.
- Solid hands‑on experience with SIEM tools, particularly Microsoft Sentinel and Google SecOps / Chronicle — comfortable investigating, searching, and tuning day to day.
- Working knowledge of UDM search and detection rule concepts in Google SecOps; ability to read and adjust existing rules (experience writing YARA‑L from scratch is a plus, not a requirement).
- Proven skills in incident response and security analysis.
- Good understanding of packet capture and network protocols.
- Familiarity with vulnerability management and scanning tools.
- Cloud experience is considered a strong asset, particularly with Google Cloud and Microsoft Azure.
- Relevant certifications in any of:
- Google Cloud Professional Cloud Security Engineer
- Google Cybersecurity Professional Certificate
- Microsoft Certified: Security Operations Analyst Associate (SC‑200)
- Microsoft Certified: Azure Security Engineer Associate (AZ‑500)
- Other certifications such as GCIA, CEH, CISM, or CISSP (asset)
- Excellent communication skills in English, French and Spanish.
*
- Google Cloud Professional Cloud Security Engineer
- Google Cybersecurity Professional Certificate
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
📌 Information Security Specialist (2 openings: French-English or English-Spanish) | Spécialiste en sécurité de l'information (2 ouvertures: français-anglais)
🏢 Hitachi Cyber
📍 Montreal