Start Date
Immediate
Expiry Date
22 Nov, 26
Salary
0.0
Posted On
24 Aug, 26
Experience
0 year(s) or above
Remote Job
Yes
Telecommute
Yes
Sponsor Visa
Yes
Skills
Industry
Information Technology & Services
Perform security monitoring, triage, and investigation of alerts generated from Microsoft Sentinel and Microsoft Defender platforms using documented playbooks
Escalate confirmed or complex incidents, including suspected compromise, lateral movement, persistence mechanisms, and data exfiltration scenarios
Perform investigations using log analytics, endpoint telemetry, identity signals, and cloud-native audit logs
Validate, scope, and document security incidents, including root cause analysis and impact assessment
Assist with containment and recovery under senior guidance
Support tuning and maintenance of Sentinel analytics rules
Assist with false positive reduction and improving signal quality across Sentinel and Defender data sources
Document detection gaps
Contribute to use case development under guidance to enhance detections, hunting queries, and alert enrichment
Support threat hunting activities
Identify anomalous or suspicious activity that may not trigger existing detections
Document hunting hypotheses, findings, and recommendations for detection improvements or control gaps
Communicating incident findings clearly
Participating in client calls when required
Supporting onboarding and steady-state operations
Support senior team members in identifying logging, configuration improvements
Support onboarding and steady-state operations for MDR clients within a managed services context
Contribute to playbooks and procedural improvements
Participate in knowledge sharing and case reviews
Assist with service quality improvements, detection maturity, and operational consistency across clients
Ensure investigations and responses align with applicable regulatory, contractual, and evidentiary requirements
Represents the skills you have
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Proven experience operating in a SOC or MSSP environment at a Tier 1 or Tier 2 level
Hands-on expertise with Microsoft Sentinel, including analytics rules, KQL, workbooks, and incident investigations
Experience with Microsoft Defender technologies, including Defender for Endpoint and identity-related signals
Exposure to investigations across cloud, endpoint, and identity domains
Working understanding of attack techniques, threat actor behaviors, and incident response methodologies
Ability to manage multiple investigations simultaneously while maintaining investigation quality and documentation
Strong written and verbal communication skills, with the ability to explain technical findings to security-focused audiences
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline
Relevant certifications such as:
o Microsoft Certified: Azure Security Engineer Associate
o Microsoft Sentinel specialization
o CISSP, GCED, GCIA, or similar (preferred, not required)
Minimum 1-2 years of experience in cybersecurity operations, with significant time spent in incident response and security monitoring roles
Proficiency in French, including Quebec French, is desired for client facing engagements