Maarut Inc. Logo

Maarut Inc.

IT Security Analyst (SOC) - GC1721-09

Posted 5 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Québec, QC, CAN
Expert/Leader
In-Office or Remote
Hiring Remotely in Québec, QC, CAN
Expert/Leader
Investigates and qualifies escalated SOC alerts involving phishing, account compromise, malware, and lateral movement. Correlates events across security platforms, enriches investigations with logs, indicators of compromise, and threat intelligence, determines severity and impact, and recommends or initiates mitigation and escalation actions. Documents findings, analyzes endpoint and network artifacts, coaches Level 1 analysts, improves detection rules and playbooks, and uses approved automation and AI tools.
The summary above was generated by AI

Overview:

  • The client is looking for an IT security analyst for its SOC, positioned at level 2: alerts reach this person already escalated by level 1, and the person in turn acts as the technical escalation point for those analysts.
  • The work centres on investigation: qualifying phishing, account compromise, malware or lateral movement cases, correlating events across several platforms, then enriching them with logs, indicators of compromise and threat intelligence.
  • The person determines verdict, severity and impact, then recommends or initiates first measures according to established processes, with incident response remaining initial and carried out with other teams.
  • The form title specifies no level, while the full set of responsibilities describes a level 2 role.
  • The Talents and qualifications section is empty: no degree, certification, language or named tool is required, so assessment rests entirely on the activity profile.
  • Target candidate: a QA professional with at least 10 years in IT, including 5 years in testing, who has coordinated testing within agile teams and uses JIRA, XRAY, Cypress and Playwright in recent mandates.
  • Group insurance exposure or an integration project will set apart otherwise equal candidates.


Requirements
Required:
  • Analysis and qualification of escalated alerts (phishing, account compromise, malware, lateral movement)
  • Event correlation (SIEM, XDR, EDR, identity, email, network, cloud)
  • Alert enrichment (logs, indicators of compromise, threat intelligence)
  • Determination of verdict, severity, potential impact and required actions
  • Initial mitigation, containment or escalation measures, recommended or initiated per processes
  • Documentation of investigations, findings, decisions and actions
  • First-level technical analysis of endpoint and network logs and artefacts
  • Support and coaching of level 1 SOC analysts on complex cases
  • Improvement of detection rules, investigation queries, runbooks and playbooks
  • Use of approved AI and automation tools (triage, enrichment, documentation)


Similar Jobs

5 Minutes Ago
Remote or Hybrid
Canada
Senior level
Senior level
Healthtech • Information Technology • Security • Software • Cybersecurity
Own the strategy, roadmap, and delivery of shared IAM cloud services across product lines. Define platform vision, requirements, adoption plans, and success metrics while partnering with Engineering, Security, Privacy, DevOps, Customer Success, and product teams. Drive interoperability through OIDC, SAML, SCIM, and APIs; improve reliability, security, adoption, and customer outcomes. Communicate priorities and tradeoffs to executives and stakeholders, and guide product-management practices for shared platform services.
Top Skills: Ai-Assisted WorkflowsAPIsBiometric Identity VerificationCloud ComputingDevOpsDirectory SynchronizationFacial AuthenticationFederationIdentity And Access Management (Iam)MfaObservabilityOidcPasswordless AuthenticationSaaSSAMLScimSdksSlosTenant Isolation
12 Minutes Ago
Remote or Hybrid
CA
Senior level
Senior level
Blockchain • Fintech • Mobile • Payments • Software • Financial Services
Build and optimize data models, pipelines, monitoring, lineage, and data quality systems supporting Block’s product data foundation. Own critical data engineering solutions across their full lifecycle, ensure pipeline reliability through on-call support, and translate business and product needs into automated data solutions. Develop AI-assisted workflows and agents for data quality, issue resolution, and operational efficiency while partnering with engineering, product, data science, and machine learning teams.
Top Skills: AirflowDatabricksDbtGitOmniPrefectPythonSnowflakeSQLTerraform
An Hour Ago
Easy Apply
Remote or Hybrid
2 Locations
Easy Apply
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Partner with sales teams to win strategic data security opportunities. Deliver technical presentations, gather customer requirements, lead product evaluations, configure solutions, and design test plans. The role requires extensive pre-sales experience, security and networking expertise, data protection knowledge, AI fluency, and collaboration across matrixed go-to-market and partner teams.
Top Skills: Coding AssistantsData Protection TechnologiesGenerative AiLlmsNetworking TechnologiesSaaSSaseSecurity TechnologiesWeb TechnologiesZscaler Zero Trust Exchange

What you need to know about the Ottawa Tech Scene

The capital city of Canada and the nation's fourth-largest urban area, Ottawa has proven a rapidly growing global tech hub. With over 1,800 tech companies, many of which are leaders in their sectors, the city's tech talent now makes up more than 13 percent of its total workforce. This growth is driven not only by the big players like UL Solutions and Dropbox, but also by a thriving startup ecosystem, as new businesses emerge to follow in the footsteps of those that came before them.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account