01 Oct
|
AceStack
|
Toronto
Job Title: SOC Analyst
Job Type: Full Time
Location: Toronto, ON (Hybrid)
Job Description
We are seeking an experienced SOC Analyst to join our cybersecurity operations team. The ideal candidate will have hands-on experience in security monitoring, incident detection and response, SIEM, EDR/XDR, threat analysis, and vulnerability management .
The candidate will be responsible for monitoring security events, investigating alerts, identifying potential threats, performing incident triage, and supporting incident response activities across enterprise environments.
Key Responsibilities
- Monitor and analyze security alerts and events using SIEM, EDR/XDR, and other security monitoring tools.
- Investigate security incidents, suspicious activities, malware alerts, phishing attempts, unauthorized access, and potential threats.
- Perform incident triage, investigation, containment, eradication, and recovery activities.
- Analyze security logs from firewalls, servers, endpoints, applications, cloud environments, and network devices.
- Conduct threat hunting and identify indicators of compromise (IOCs), attack patterns, and emerging threats.
- Perform root cause analysis and document security incidents, findings, and remediation activities.
- Support vulnerability assessments, remediation activities, and security risk tracking.
- Develop and maintain security monitoring rules, alerts, dashboards, and reports.
- Correlate events across multiple security platforms to identify potential security incidents.
- Collaborate with infrastructure, network, cloud, application, and IT teams to investigate and remediate security issues.
- Participate in security investigations,
incident response exercises, and continuous improvement of SOC processes.
- Maintain accurate documentation of incidents, investigations, procedures, and security controls.
Required Technical Skills
- 3 7+ years of experience in SOC, cybersecurity, security operations, incident response, or security monitoring.
- Strong hands-on experience with SOC operations and security monitoring.
- Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar , or equivalent.
- Experience with EDR/XDR platforms such as Microsoft Defender, CrowdStrike, SentinelOne , or equivalent.
- Solid knowledge of network security concepts including TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls, IDS/IPS, and proxies.
- Experience analyzing Windows and Linux security logs.
- Knowledge of vulnerability management and remediation.
- Understanding of common cyber threats, malware, phishing, credential attacks, and network-based attacks.
- Familiarity with MITRE ATT&CK;, IOC analysis, threat intelligence, and security incident investigation .
- Knowledge of Azure and/or AWS security concepts is preferred.
- Scripting or automation experience using Python, PowerShell, or Bash is an asset.
- Strong analytical, troubleshooting, communication, and documentation skills.
Security Frameworks & Standards
- Knowledge of NIST, ISO 27001, SOC 2, PCI DSS , or other cybersecurity frameworks is preferred.
Preferred Certifications
- CompTIA Security+
- CompTIA CySA+
- CEH
- GCIH
- GCIA
- CISSP or equivalent cybersecurity certification
Job Details
- Job Type: Full Time
- Location: Toronto, ON
- Work Model: Hybrid
#J-18808-Ljbffr
📌 SOC Analyst (Toronto)
🏢 AceStack
📍 Toronto