Senior Security Analyst
Job Summary
- Monitor and manage security incidents through ServiceNow in accordance with established incident response procedures.
- Investigate network security events generated from firewalls IDS/IPS web proxies VPNs NAC and other enterprise security solutions.
- Analyze network traffic packet captures logs and security alerts to detect threats and indicators of compromise.
- Support the implementation administration and optimization of:
- Firewalls
- Network Access Control (NAC)
- VPN solutions
- Secure Remote Access
- Network Segmentation
- Review firewall rules ACLs routing paths and security policies to identify vulnerabilities and misconfigurations.
- Participate in cybersecurity investigations threat containment root cause analysis and incident remediation.
- Produce detailed security reports incident documentation risk assessments and management metrics.
- Coordinate phishing simulation campaigns and analyze user response metrics.
- Process Privileged Access Management (PAM) requests through ServiceNow within SLA.
- Collaborate closely with network infrastructure cloud identity application and security operations teams.
- Research emerging cyber threats and recommend security improvements across the enterprise.
Requirements
- Willing and able to work 100% on-site in Regina Saskatchewan for the full contract duration.
- Enterprise Security Operations Center (SOC)
- Security Monitoring
- Incident Response
- Threat Detection
- Security Event Investigation
- Security Operations Reporting
- Firewalls
- IDS/IPS
- VPN Technologies
- Secure Web Gateways
- Proxy Services
- DNS Security
- Load Balancers
- Network Access Control (NAC)
- Network Segmentation
- Secure Remote Access
- TCP/IP
- Routing & Switching
- VLANs
- NAT
- DNS
- DHCP
- Wireless Security
- Network Protocol Analysis
- Network Traffic Analysis
- Packet Capture Analysis
- Log Analysis
- Threat Hunting
- Root Cause Analysis
- Risk Assessment
- Security Policy Review
- Firewall Rule Review
- Access Control Lists (ACLs)
- Zero Trust Architecture
- Least Privilege
- NIST Cybersecurity Framework (NIST CSF)
- CIS Controls
- ISO/IEC 27001
- ISO/IEC 27002
- Secure Configuration Baselines
- ServiceNow
- Privileged Access Management (PAM)
- Security Reporting
- Change Management
- Experience supporting provincial federal or municipal government environments.
- Experience within large complex highly regulated enterprise environments.
- Strong understanding of government IT security practices.
- Experience working with cross-functional IT teams including:
- Network Engineering
- Infrastructure
- Cloud Operations
- Identity & Access Management
- Endpoint Security
- Security Operations
- Excellent analytical and critical thinking abilities
- Strong troubleshooting and investigative skills
- Outstanding written and verbal communication
- Ability to communicate effectively with technical and non-technical stakeholders
- Strong documentation skills
- Excellent collaboration and stakeholder management
- Ability to prioritize multiple security incidents simultaneously
- Detail-oriented with strong organizational skills
- Degree or Diploma in:
- Cybersecurity
- Computer Science
- Information Systems
- Network Engineering
- Information Technology
- Equivalent practical industry experience.
- CISSP
- CISM
- CCNP Security
- CCIE Security
- Fortinet NSE
- Palo Alto PCNSE
- Check Point CCSA
- Check Point CCSE
- CompTIA Security
Required Skills:
Mandatory Requirements (Pass/Fail) Candidates must satisfy both of the following requirements: Willing and able to work 100% on-site in Regina Saskatchewan for the full contract duration. Mandatory Technical Skills Applicants should possess strong experience in the following: Enterprise Security Operations Enterprise Security Operations Center (SOC) Security Monitoring Incident Response Threat Detection Security Event Investigation Security Operations Reporting Network Security Firewalls IDS/IPS VPN Technologies Secure Web Gateways Proxy Services DNS Security Load Balancers Network Access Control (NAC) Network Segmentation Secure Remote Access Network Technologies TCP/IP Routing & Switching VLANs NAT DNS DHCP Wireless Security Network Protocol Analysis Security Analysis Network Traffic Analysis Packet Capture Analysis Log Analysis Threat Hunting Root Cause Analysis Risk Assessment Security Policy Review Firewall Rule Review Access Control Lists (ACLs) Security Frameworks Zero Trust Architecture Least Privilege NIST Cybersecurity Framework (NIST CSF) CIS Controls ISO/IEC 27001 ISO/IEC 27002 Secure Configuration Baselines Enterprise Tools ServiceNow Privileged Access Management (PAM) Security Reporting Change Management Preferred Experience Candidates with the following experience will be highly preferred: Experience supporting provincial federal or municipal government environments. Experience within large complex highly regulated enterprise environments. Strong understanding of government IT security practices. Experience working with cross-functional IT teams including: Network Engineering Infrastructure Cloud Operations Identity & Access Management Endpoint Security Security Operations Required Soft Skills Excellent analytical and critical thinking abilities Strong troubleshooting and investigative skills Outstanding written and verbal communication Ability to communicate effectively with technical and non-technical stakeholders Strong documentation skills Excellent collaboration and stakeholder management Ability to prioritize multiple security incidents simultaneously Detail-oriented with strong organizational skills Education One of the following is required: Degree or Diploma in: Cybersecurity Computer Science Information Systems Network Engineering Information Technology OR Equivalent practical industry experience. Preferred Certifications (Assets) Candidates holding one or more of the following certifications will be highly preferred: CISSP CISM CCNP Security CCIE Security Fortinet NSE Palo Alto PCNSE Check Point CCSA Check Point CCSE CompTIA Security
Required Education:
EducationOne of the following is required:Degree or Diploma in:CybersecurityComputer ScienceInformation SystemsNetwork EngineeringInformation TechnologyOREquivalent practical industry experience.