Investigates and qualifies escalated SOC alerts involving phishing, account compromise, malware, and lateral movement. Correlates events across security platforms, enriches investigations with logs, indicators of compromise, and threat intelligence, determines severity and impact, and recommends or initiates mitigation and escalation actions. Documents findings, analyzes endpoint and network artifacts, coaches Level 1 analysts, improves detection rules and playbooks, and uses approved automation and AI tools.
Overview:
- The client is looking for an IT security analyst for its
SOC, positioned at level 2: alerts reach this person already escalated by level
1, and the person in turn acts as the technical escalation point for those
analysts.
- The work centres on investigation: qualifying phishing,
account compromise, malware or lateral movement cases, correlating events
across several platforms, then enriching them with logs, indicators of
compromise and threat intelligence.
- The person determines verdict, severity and impact, then
recommends or initiates first measures according to established processes, with
incident response remaining initial and carried out with other teams.
- The form title specifies no level, while the full set of
responsibilities describes a level 2 role.
- The Talents and qualifications section is empty: no degree,
certification, language or named tool is required, so assessment rests entirely
on the activity profile.
- Target candidate: a QA professional with at least 10 years
in IT, including 5 years in testing, who has coordinated testing within agile
teams and uses JIRA, XRAY, Cypress and Playwright in recent mandates.
- Group insurance exposure or an integration project will set
apart otherwise equal candidates.
Requirements
Required:
- Analysis and qualification of escalated alerts (phishing,
account compromise, malware, lateral movement)
- Event correlation (SIEM, XDR, EDR, identity, email, network,
cloud)
- Alert enrichment (logs, indicators of compromise, threat
intelligence)
- Determination of verdict, severity, potential impact and
required actions
- Initial mitigation, containment or escalation measures,
recommended or initiated per processes
- Documentation of investigations, findings, decisions and
actions
- First-level technical analysis of endpoint and network logs
and artefacts
- Support and coaching of level 1 SOC analysts on complex
cases
- Improvement of detection rules, investigation queries,
runbooks and playbooks
- Use of approved AI and automation tools (triage, enrichment,
documentation)
Similar Jobs
Artificial Intelligence • Cloud • Consumer Web • Productivity • Software • App development • Data Privacy
Manage adoption, customer health, renewal readiness, and growth across a scaled B2B SaaS portfolio. Design lifecycle campaigns, analyze customer and retention signals, coordinate renewal actions, triage inbound requests, conduct targeted customer conversations, and surface qualified expansion opportunities. Partner cross-functionally with Renewals, Sales, Product, Marketing, Support, and Customer Experience teams while delivering portfolio forecasts and executive updates.
Top Skills:
Ai-Enabled SaasB2B SaasBusiness Intelligence ToolsCrm SystemsCustomer Success PlatformsCustomer-Data SystemsMarketing Automation
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Own third-party risk management and business continuity programs while building production data pipelines, integrations, policy-as-code controls, continuous monitoring, and agentic AI workflows. The role requires defining technical direction, integrating imperfect data sources, automating evidence collection, and partnering across Security, Procurement, Resilience, and Engineering teams to improve governance and operational resilience.
Top Skills:
AWSBuildkiteCi/CdClaudeGCPGoGrpcHTTPJavaJSONKotlinKubernetesLlm ApisModel Context ProtocolProtocol BuffersPythonRest ApisSnowflakeSQLTerraform
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Lead data modeling and ownership of critical pipelines supporting Block’s product data foundation. Build reliable, governed, and monitored datasets, data quality and lineage systems, experimentation infrastructure, and AI-assisted automation. Partner with product and engineering teams to translate business needs into end-to-end data solutions, participate in on-call support, and maintain pipeline SLAs.
Top Skills:
AirflowDatabricksDbtGitOmniPrefectPythonSnowflakeSQLTerraform
What you need to know about the Toronto Tech Scene
Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.


