Information Security Operations Analyst (Toronto, Canada)
Core
24/7 SOC Analyst supporting incident triage, response, and investigations for cloud infrastructure, endpoints, and perimeter security across Starling Group's global businesses.
Role type
SOC Analyst (Incident Response & Threat Hunting)
Builds
Incident handling processes, analytic triggers, and threat hunting capabilities
Domain
Fintech / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Cloud security (AWS/GCP), SIEM platforms, Endpoint Detection and Response, Incident Response, Threat hunting, Tabletop Exercises, Cloud investigations, Endpoint investigations, Network security controls
Preferred skills
Digital forensics, Malware analysis, Python/Go/Java programming
Technologies
AWS, GCP, SIEM, EDR, Cloud infrastructure, Endpoint security tools
Responsibilities
Triage and investigate security alerts from multiple sources, Respond to security incidents raised by users, Enhance analytic triggers for alert efficacy, Conduct proactive threat hunting based on threat intelligence, Document incidents and investigations, Develop incident handling and readiness processes
Seniority
Mid-level, hands-on IC