Security Operation Analyst at Flexspring
Canada, Ontario, Canada -
Full Time


Start Date

Immediate

Expiry Date

21 Dec, 26

Salary

65000.0

Posted On

28 Sep, 26

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Industry

Information Technology & Services

Description

Responsibilities

Monitor security alerting and detection tooling (SIEM/EDR) on an ongoing basis; triage, investigate, and escalate confirmed security incidents


Own vulnerability management end to end: track findings from scans and penetration tests through to remediation, following up with the relevant technical owners across IT Ops, Cloud Engineering, and SRE

Maintain and tune detection rules and alert logic to reduce false positives and close monitoring coverage gaps


Act as secondary owner for security incident response, working alongside the Security & Compliance Lead, following the department's established escalation protocols (routed through Jira, no ad hoc direct messaging)

Support the Security & Compliance Lead with evidence collection for SOC 2 / ISO 27001 audits where operational or technical evidence (logs, monitoring configurations, incident records) is required

Coordinate with Cloud Engineering and Integration Support/SRE teams during active security incidents to determine root cause and scope


Stay current on emerging threats, vulnerabilities, and security best practices relevant to cloud infrastructure and SaaS/iPaaS platforms


Ensure any AI-assisted tooling used for triage or detection complies with Flexspring's AI & R&D Safe Sandbox Policy (read-only service accounts, sandboxed environments, no unauthorized use of customer data)

Responsibilities

Responsibilities

Monitor security alerting and detection tooling (SIEM/EDR) on an ongoing basis; triage, investigate, and escalate confirmed security incidents


Own vulnerability management end to end: track findings from scans and penetration tests through to remediation, following up with the relevant technical owners across IT Ops, Cloud Engineering, and SRE

Maintain and tune detection rules and alert logic to reduce false positives and close monitoring coverage gaps


Act as secondary owner for security incident response, working alongside the Security & Compliance Lead, following the department's established escalation protocols (routed through Jira, no ad hoc direct messaging)

Support the Security & Compliance Lead with evidence collection for SOC 2 / ISO 27001 audits where operational or technical evidence (logs, monitoring configurations, incident records) is required

Coordinate with Cloud Engineering and Integration Support/SRE teams during active security incidents to determine root cause and scope


Stay current on emerging threats, vulnerabilities, and security best practices relevant to cloud infrastructure and SaaS/iPaaS platforms


Ensure any AI-assisted tooling used for triage or detection complies with Flexspring's AI & R&D Safe Sandbox Policy (read-only service accounts, sandboxed environments, no unauthorized use of customer data)

Loading...