
Senior Threat Analyst
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in Canada.
• Oversee, investigate, and react to alerts produced by the Sophos security suite, which includes EDR/XDR functionalities.
• Guide and mentor Tier I Analysts through escalated issues.
• Conduct comprehensive analysis of suspicious activities to evaluate scope, impact, and risk.
• Detect and respond to cyber threats within customer environments utilizing authorized playbooks and tools.
• Record findings, investigative procedures, and results in the MDR case management system.
• Execute threat hunting across the MDR customer network.
• Examine phishing emails, questionable binaries, and behavioral anomalies.
• Aid in detection tuning by identifying frequent false positives and proposing enhancements.
• Keep updated on threat actor behaviors, MITRE ATT&CK techniques, and Sophos threat intelligence.
• Investigate new IOCs, active exploits, and vulnerabilities.
• Contribute to internal knowledge repositories, documentation, and continuous improvement efforts.
• Engage in shift rotations and ensure thorough handovers between global teams.
• Offer detection and response assistance for ongoing security incidents.
• Manage case workflows and maintain client communication until resolution.
• Interact with clients through chat, phone, and ticketing systems.
• Assist in the development and refinement of Security Operations processes, playbooks, and tools.
• Over 5 years of practical experience in a Security Operations Center (SOC), Managed Detection and Response (MDR) environment, or a cybersecurity-focused IT role.
• Skilled in endpoint and network security tools, such as EDR, IDS/IPS, and malware detection platforms.
• Proficient understanding of Windows workstation and server operating systems, along with Linux or macOS.
• Capability to interpret and analyze Windows event logs and other telemetry data.
• Familiarity with TCP/IP, protocols, routing, and traffic analysis.
• Experience in real-time incident response efforts and threat investigations.
• Exposure to threat hunting strategies and attacker behavior patterns.
• Experience managing active threats, including containment, mitigation, and recovery.
• Knowledge of persistence, privilege escalation, lateral movement, and defense evasion techniques.
• Familiarity with incident response processes and security operations workflows.
• Strong analytical and troubleshooting abilities.
• Exceptional communication skills for both technical and non-technical audiences.
• Customer-centric attitude and professionalism.
• Ability to work collaboratively within a team as well as independently.
• Bachelor's degree in information technology, Computer Science, Cybersecurity, or a related field, or equivalent hands-on experience.
• Willingness to engage in shift work, including nights, weekends, and holidays.
• Legal authorization to work in Canada without the need for employer sponsorship.
• Eligibility for bonuses.
• Comprehensive benefits package.
• Remote-first working approach.
• Employee-led initiatives focused on diversity and inclusion.
• Annual charity and fundraising activities.
• Volunteer days.
• Global employee sustainability programs.
• Global fitness and trivia competitions.
• Global well-being days.
• Monthly well-being webinars and training.
Hotelbeds
PointClickCare
Vision Cybersecurity
Método Engenharia
Get handpicked remote jobs straight to your inbox weekly.