Cyber and Information Security Consultant Job at Insight Global, Greater Vancouver Regional District, BC

TnM3R0dkeXVJWmw1YWlTR3BXeGhvSmxTS0E9PQ==
  • Insight Global
  • Greater Vancouver Regional District, BC

Job Description

Job Description

Insight Global is Looking for a Tier 2 security Operations Analyst in Vancouver or Seattle for a hybrid 6-month contract with a high possibility for extension or conversion to permanent. The Cyber Security Analyst will help the team to perform Security Operations Center (SOC) duties, which include incident response, malware analysis, and monitoring. This role will work with the team to implement processes and practices designed to protect networks, devices, and data from malicious attack, damage, or unauthorized access.

• Triages alerts/incidents and performs deep analysis; correlates with threat intelligence tools, tactics and procedures (TTP) in indicators of compromise (IOCs) to identify the threat actor, nature of the attack, and systems or data affected.

• Prioritizes and triages alerts or issues to determine whether a real security incident is taking place and escalate incidents to Tier 3 if remediation cannot be closed within SLA time.

• Performs analysis, triage and remediation of low/medium priority alerts.

• Analyzing logs, network traffic, and other data sources to identify the source of incidents.

• Record identified vulnerabilities, create remediation tickets and track their status.

• Build internal scripts, tools, and automation processes to enhance detection and response capabilities.

• Adjusting security tools and processes, e.g. EDR alerting modifications, updating detection rules conditions, etc.

Required Skills & Experience

• Bachelor’s in: Computer Science, Information Security, Cybersecurity, or a related degree.

• 3+ year experience in one or more areas: Security Operations, Incident Response, Information Security Technology, etc.

• Strong security concepts of threat categories (such as malware, phishing attacks, Defense-in-Depth, MITRE ATT&CK framework, etc.)

• Strong knowledge of M365 Security tools, Azure, AWS, GCP

• Working experiences to security tools such as SIEM (Sentinel, Splunk, Elastic etc.), EDR, firewalls, IDS/IPS, anti-spam, content management, server and network device hardening, etc.

• Strong knowledge of Windows, Linux and/or Mac OS and comfortable with looking at, understanding, and investigating Security Event logs.

• Good knowledge of networking protocols (SMTP, FTP, DNS, DHCP, etc).

• Experiences of any query language and scripting language

• SharePoint, Excel, JIRA and/or Microsoft Office skills

• Experience in using security orchestration, automation, and response tools

• Experience with query languages and scripting languages

• Experience in using security orchestration, automation, and response tools

Job Tags

Permanent employment, Contract work, Work at office,

Similar Jobs

Health Match BC

Psychiatry Job at Health Match BC

 ...Health is embracing virtual methods to enhance patient care. This position provides entirely virtual clinical services! The Virtual Psychiatry Unit represents a novel approach to delivering acute Mental Health and Substance Use care to clients across the Fraser Health Region... 

Snaphunt

Blockchain Engineer Job at Snaphunt

 ...posing swap routes and analytics. The Profile You have at least 3 years experience, ideally within a Software Engineer or System Architect role. Proficiency in Golang and/or Rust programming. Deep understanding of Ethereum inter... 

Cardinal Health

Software Developer Job at Cardinal Health

 ...PSDPost Sales Discount...  ...oking for a talented and experienced Software Developer to join our Cardinal Hea...  ...and technically skilledIntermediate Level Software Developer (.NET, Java, Ful... 

Thermo Fisher Scientific

Field Service Job at Thermo Fisher Scientific

 ...ns Office ="" The responsibilities of a Field Service Engineer for Ion Chromatography (IC) are diverse, but ma...  ...ce: Visit customer sites periodically under contract to clean the instrument, replace consumables, verify operation, a...