2 hours ago
Montréal, CanadaMid Level / Senior
Responsibilities
- Build and maintain security tooling and integrations.
- Collaborate with detection engineering teams on rule development and tuning.
- Design and implement automation pipelines across SIEM, SOAR, EDR, and other SOC platforms.
- Support incident response activities with technical solutions.
- Develop and maintain SOAR playbooks and automation workflows.
- Support CI/CD pipelines for security tools and infrastructure.
- Identify gaps in telemetry, logging, and alerting.
- Document architectures, processes, and runbooks.
Requirements
- Require 3–6 years of experience in a SOC environment.
- Require programming experience with Python or a similar language.
- Require DevOps experience including CI/CD, containerization, and infrastructure as code.
- Require knowledge of cybersecurity domains including SIEM, SOAR, threat detection, cloud security, or incident response.
- Require experience with logging pipelines and data systems.
- Require working knowledge of the MITRE ATT&CK framework and attacker techniques and defensive practices.
- Prefer experience with SIEM platforms such as Splunk, Elastic, or Sentinel.
- Prefer experience with SOAR tools and cloud security across AWS, Azure, or GCP.
- Prefer relevant cybersecurity certifications and knowledge of API security and SSDLC.
- Prefer experience with Kubernetes and open-source security tooling.
- Prefer the ability to work in fast-paced environments, manage priorities, and switch between engineering and operational contexts.
- Prefer experience working with multiple stakeholders.
Benefits
- Collaborative and innovative work environment.
- Opportunity to work on advanced technologies.
- Flexible work arrangements.
- Competitive benefits.
