
Team Lead, CSOC
- Vancouver, BC
- 110.000-150.000 $ par an
- Permanent
- Temps-plein
- Perform any subset of the duties and responsibilities listed for the Cyber Security Specialist role and serve as escalation point for CSOC.
- Provide quality escalated customer service, including effectively handling Global Relay employee complaints.
- Act as the first line of defense lead, supervising daily CSOC activities and mentoring analysts during security investigations and incident response.
- Serve as the main escalation point for Cyber Security Specialists for complex alerts, suspicious activity and high-priority incidents.
- Coordinate shift handovers and ensure documentation and continuity across CSOC operations Globally.
- Operate and monitor security tools and technologies including SIEM, EDR, IDS/IPS, threat intel, vulnerability management.
- Ensure tools are tuned and optimized in collaboration with Cyber Engineering team.
- Develop and document playbooks and escalation procedures to improve Cyber Security Operations Center efficiency and maturity.
- Support Cyber Security Manager to develop dashboards and reports for security KPIs, threat metrics and incident response metrics.
- Assist with Global Relay security audits.
- Assist with the enforcement of security policies.
- Participate in security awareness initiatives.
- Administer firewall rule changes, patches, and updates aligned with the change management process.
- Assist with the team's hiring processes and new team member training.
- Conduct team meetings to update members on best practices and continuing expectations.
- Provide encouragement to team members, including identifying areas for additional training or skills development.
- Answer team member questions, help with team member problems, and oversee team member work for quality and guideline compliance.
- Communicate deadlines and goals to team members.
- Develop strategies to promote team member adherence to company regulations and performance goals.
- Generate and share comprehensive and detailed reports about team performance, mission-related objectives, and deadlines.
- Perform annual individual performance appraisals (IPAs) for team members.
- Approve team members' time off requests.
- 2-5 years of hands-on experience leading, Security Operations team and strong understanding of information security systems such as firewalls, intrusion detection and prevention implementations, antivirus and anti-malware solutions, SIEM solutions, two-factor and biometric authentication solutions, and server and network device hardening.
- 1-2 years of management experience leading technical teams.
- Proven experience performing analysis of security events to determine root cause and provide resolution.
- Experience handling and escalating security incidents in real time.
- Familiarity with MITRE ATT&CK, ISO 27001, SOC 2, FedRAMP frameworks.
- Certification in one or more security domains, including CISSP.
- Excellent understanding of a wide variety of communication protocols.
- Experience using an internal and external ticketing system for ITIL-based incident, problem and change management.
- Previous experience in troubleshooting day-to-day operational processes such as report generation, data verification, data correlation, etc.
- Excellent verbal, written and documentation skills.
- Knowledge of scripting or automation tools e.g. Python.
- Methodical and creative approach to problem-solving.
- Superior time management and prioritizing ability.
- Strong relationship building skills.
- Leadership and motivational skills.
- Employee training experience.
- Interviewing skills.
- Customer service skills.
- Availability after hours for escalations.
- Must be flexible to working across different time zones including UK, US and Canada.