- Location
- Canada - Remote
- Workplace
- Remote
- Type
- Full-time
- Department
- Security
Description
IT Security Analyst II
Department: Technology Operations
Employment Type: Full Time
Location: Canada - Remote
Description
Key Responsibilities
- Understand and follow “The VC3 Way”. This is our set of standards and processes that produce a predictable result for the client. You must be aware of and maintain our standards
- Translate complex Cyber Security concepts into actionable insights for clients, ensuring alignment with their business priorities and enhancing their understanding of strategic security decisions.
- Oversee and prioritize security event monitoring and incident response queues, ensuring swift and accurate triage to meet or exceed established SLAs/objectives.
- Develop and implement strategies to streamline incident response processes and improve resolution times.
- Conduct comprehensive analysis of system, security, and application logs to diagnose intricate faults, identify subtle abnormal behaviors, and refine false positive reduction techniques.
- Leverage advanced tools and techniques for sophisticated threat detection and analysis.
- Utilize and optimize a broad range of VC3 and client toolsets, including advanced End Detection and Response (EDR) tools, for in-depth investigation of alerts, anomalies, and building accurate timelines related to potential security compromises.
- Formulate and execute strategic approaches for investigating, escalating, containing, and eradicating sophisticated malicious activities.
- Develop, deliver, and present detailed written and oral reports to clients, teammates, and management, focusing on security trends, metrics, and strategic recommendations.
- Provide strategic input and recommendations for improving internal processes, procedures, and security practices based on industry trends and operational experience.
- Lead threat hunting activities and oversee special projects, employing advanced methodologies to proactively identify and mitigate potential threats.
- Advocate for and lead the adoption of innovative security solutions and methodologies within the organization.
- Collaborate with internal stakeholders to address changes in technologies, practices, and business activities that may impact security.
- Facilitate cross-departmental initiatives to enhance client security and mitigate threats.
- Maintain and update comprehensive documentation related to security operations, threat analysis, and incident management.
- Ensure timely and accurate communication with clients and internal teams, reflecting changes and new findings effectively.
- Mentor and guide Security Analyst I team members, providing support and sharing expertise to enhance their skills and knowledge.
- Lead by example in adhering to security best practices, and take ownership of complex security issues, leading escalation efforts to senior resources or specialized teams.
- Engage actively in team huddles, L10 meetings, and other collaboratively structured meetings.
- Review Tickets with Manager
- Attend company-based meetings as required
- Participate in the on-call rotation (1 week every ~ 1.5-2 months)
- Additional duties as required
Skills, Knowledge and Expertise
- Five or more years of work experience in information security, risk management, or related fields.
- One of the following certifications preferred: CompTIA Security+, CompTIA CySA+, CCNA, C|EH, SSCP, or equivalent
- Advanced certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or Certified Risk & Information Security Controls (CRISC) are highly desirable.
- Practical knowledge of security technologies and tools, including Firewalls, IDS/IPS, SIEM, Identity and Access Management (IAM), remote working solutions, and cloud technologies.
- Understanding of current and emerging threats, countermeasures, and organizational challenges in addressing these threats.
- Awareness of information security management frameworks and industry regulations (e.g., NIST, ISO 27001, GDPR).
- Strong problem-solving and decision-making abilities with a capacity to analyze complex issues and develop effective solutions.
- Excellent verbal and written communication skills, with the ability to present complex technical issues in a clear and simple format.
- Self-motivated, detail orientated, highly organized and able to handle a variety of tasks and responsibilities in an efficient manner with a high level of quality
- Demonstrates effective communication skills, both written and verbal
- Shows the ability to adapt and thrive in ambiguous or uncertain situations, quickly assessing and navigating challenges.
Additional information you will want to know:
- Applicant selected will be subject to a criminal and department of motor vehicles background checks and must meet Criminal Justice Information Systems (CJIS) requirements post-employment
- Minimal travel required
- VC3 offers a comprehensive benefit package and 401K/RRSP company matching