Cybersecurity Production Expert
Tech Talent International · Montreal, QC, Canada · Hybrid
Pay: CAD 110,000 – 120,000 a year
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Tech Talent International (SI) supplies technical talent to a variety of clients ranging from Fortune 100/500/1000 companies to small and mid-sized organizations in Canada/US and Europe.
We currently have a role as a Cybersecurity Production Expert with our large consulting client on a long term project with a major financial services client in the downtown Montreal area.
This role can either be a fulltime, perm role or a long term C2C contract.
Role: Cybersecurity - Cybersecurity Production Expert
Type: Permanent or Contract 40 hrs/week
Location: Hybrid - Downtown Montreal, QC -(roles starts off 5 days in office for 1st 3 months, then turns into hybrid setup 3 days onsite, 2 days from home)
Salary: $110,000 - $120,000 + 9% bonus + 3-5 weeks paid vacation + RRSP contribution + benefits + sick/personal days
Contract Rate Option: $100 - $105/hr C2C
On-Call Info: 6pm to 6am, for 1 weeks, every 16 weeks
Job Description :
The Production CSIRT Purple Team Expert position will provide security expertise to the 24x7 Security
Operation Center (SOC). The primary purpose of this position is to develop, implement and assist on the continuous evolution of security use cases and correlation rules which assist on detecting, preventing, and responding to cyber threats against our group's infrastructure. It provides critical support to the firm - wide cybersecurity program via partnerships in the region with our peer s globally and within our diverse lines of business as well as externally with client s, partners and regulators.
As a Production Security Purple Team Expert , you are not only responsible for the continuous use case and correlation rule development and enhancement but also expected to participate in Threat Hunting and participate in cybersecurity investigations which will enhance the 24x7 Security Opera tion Center (SOC) capabilities as the first line of defense to identify potential information security incidents.
MAIN RESPONSIBILITIES
Responsibilities include but are not limited to:
Provide analysis and trending of security log data from many heterogeneous security devices
Responsible for use - case development and validation
Develop threat hunting program and capabilities
Investigate, document and report on information security issues and emerging trends
Perform threat hunting to identify potential adversaries within the network as well as participate in exercises with the AMER Purple Team to detect and remediate any potential gaps or use case defects.
Provide support and /or research any security related questions or incidents.
Perform tasks independently with some oversight
Integrate and share information with other analysts and other teams.
Follow incident - specific procedures to perform triage of potential security incidents to validate and determine needed mitigation and maintain said procedures up to date.
Escalate potential security incidents to Level IV engineers, implements…