Senior Security Analyst
Role summary
This role is for an experienced Tier 3 Analyst within a Security Operations Center (SOC) team, focusing on advanced analysis and leading incident response for critical government systems. Responsibilities include investigating high-severity threats like APTs and zero-day exploits, performing deep-dive analysis across various environments, and conducting advanced threat hunting. The analyst will serve as the final escalation point, providing technical guidance and mentoring to junior analysts, and producing detailed incident reports. Collaboration with incident response teams, ISSOs, system owners, and agency leadership is crucial. The position requires 10+ years of experience in security operations, incident response, or cyber threat analysis, proficiency with SIEM, EDR, and forensic tools, and knowledge of frameworks like MITRE ATT&CK. A Secret clearance and Bachelor's degree are mandatory.
We are seeking an experienced Tier 3 Analyst to join our Security Operations Center (SOC) team. In this role, you will be responsible for conducting advanced analysis, leading incident response efforts, and developing mitigation strategies to protect critical government systems and data.
What You'll Work On:
- Investigate and resolve high-severity and advanced persistent threats (APTs), zero-day exploits, and targeted attacks.
- Perform deep-dive analysis across endpoint, network, and cloud environments.
- Conduct advanced threat hunting based on hypotheses, threat intelligence, and behavioral indicators.
- Serve as the final escalation point for Tier 1 and Tier 2 analysts, providing technical guidance and mentoring.
- Produce comprehensive incident reports with root cause analysis, timelines, and recommended corrective actions.
- Interface with incident response teams, ISSOs, system owners, and agency leadership during incident handling.
You Have:
- 10+ years of experience in security operations, incident response, or cyber threat analysis
- Experience with SIEM platforms, EDR tools, packet capture analysis, and forensic toolkits
- Knowledge of the MITRE ATT&CK framework, network protocols, malware behavior, and adversary TTPs
- Ability to work under pressure and communicate effectively with both technical and executive stakeholders
- Secret clearance
- Bachelor’s degree
Nice If You Have:
- Experience with cloud security operations such as AWS and Azure and Zero Trust environments
- Experience contributing to threat detection engineering or threat intelligence integration
- GCIA, GCIH, GNFA, GCFA, OSCP, CISSP, or equivalent Certification
Similar roles
- Security AnalystDecryption Digest ® · United States · Remote
- Security AnalystMjolnir Security · Toronto, Ontario, Canada · Hybrid
Security AnalystExperis Canada · Canada · Remote
Security AnalystCanada's Wonderland · Ontario, Canada · Onsite
Security AnalystCanada's Wonderland · Ontario, Canada · Onsite