
Cyber Security Specialist - Cyber Incident Management
- Mississauga, ON
- Permanent
- Temps-plein
- Conduct efficient and thorough investigations of security alerts, events, and incidents using a variety of security tools, including SIEM, Firewall, WAF, EDR, IDS/IPS, and Email Security Gateways.
- Analyze security logs, network traffic, and endpoint data to identify indicators of compromise (IOCs) and determine the scope and impact of incidents.
- Perform initial triage and containment actions to limit the spread and impact of security incidents.
- Engage with end-users and other teams to validate suspicious activities and gather additional context for investigations.
- Collaborate closely with our Managed Security Service Provider (MSSP), fostering a strong partnership for seamless alert escalation and information exchange.
- Effectively escalate security gaps, findings, and critical incidents to appropriate internal teams for timely remediation.
- Collaborate with the Threat Management team in the creation, testing, and refinement of new security use cases and detection rules.
- Develop and maintain incident response playbooks, Standard Operating Procedures (SOPs), and other operational documentation.
- Provide technical support and guidance to other IT teams on security best practices, emerging threats, and incident prevention.
- Participate in on-call rotations, including nights and weekends, to ensure timely response to critical security incidents outside of regular business hours.
- Stay up-to-date with the latest cybersecurity threats, vulnerabilities, and industry best practices.
- An undergraduate degree or diploma in computer science, information security, or a related technical discipline.
- 3+ years of industry experience working in Cybersecurity operations (e.g., SOC Analyst/Specialist, Incident Responder).
- Strong understanding of network and system security concepts, including TCP/IP, operating systems (Windows, Linux), common attack vectors, and defensive strategies.
- Proficiency in using a variety of security tools and technologies, including but not limited to: SIEM, EDR, IDS/IPS, Firewalls, Email security gateways, Proxy, etc.
- Excellent analytical and problem-solving skills with a methodical approach to complex investigations.
- Strong attention to detail and the ability to work effectively and make sound decisions under pressure during critical incidents.
- Ability to work on on-call rotations, including nights and weekends, to respond to security incidents outside of regular business hours.
- Excellent written and verbal communication skills, with the ability to articulate technical information clearly to both technical and non-technical audiences.
- Strong interpersonal skills, with the ability to build rapport and collaborate effectively with diverse teams and external partners.
- Relevant industry certification such as Security+, CySA+, CEH, or equivalent.
- Proven experience working directly in or closely with Managed Security Service Providers (MSSPs).
- Knowledge and experience working in a complex retail technology environment is highly desired.
- Experience in Digital Forensics and Incident Response (DFIR) beyond typical SecOps, involving complex and large-scale incidents such as Business Email Compromise (BEC), Ransomware, or Website Compromise.
- Advanced technical industry certifications in the field of DFIR, such as GCIH, GCFA, or similar.
- Competitive Benefits Package, tailored to meet your needs, including health and dental coverage, life, short- and long-term disability insurance.
- Access to Virtual Health Care Platform and Employee and Family Assistance Program.
- A Retirement and Savings Plan that provides you with the opportunity to build and add value to your savings.
- A 10% in-store discount at our participating banners and access to a wide range of other discount programs, making your purchases more affordable.
- Learning and Development Resources to fuel your professional growth.
- Parental leave top-up
- Paid Vacation and Days-off