Cloud Cybersecurity Operations Analyst
--GTA--
Description:
We are seeking a resourceful and forward-thinking Cybersecurity Analyst who will be primarily responsible for day-to-day basic Cybersecurity Operational tasks. These would require general knowledge in Data Loss Prevention (DLP) triaging, working on Endpoint Detection and Response platform, Cybersecurity Incidents triaging, and good communication skills.
This person will work closely with Incident Response, DLP, Vulnerability Management, Engineering, Risk, Infrastructure, Business, Legal, and HR teams. The role is part of the Cybersecurity Operations team and will be primarily based out of the Markham office.
What You'll Do:
- Work on Change Management requests pertaining to the team
- Daily triaging IR and DLP incidents
- Work on vulnerability reports and track issues pertaining to the vulnerabilities
- Track, record, and monitor any security issue
- Ensure health checks and periodic testing of DLP, EDR tools, SIEM, and other tools
- Be aware of the latest threats in Cybersecurity
- Be more proactive in day-to-day operations
- Able to transfer knowledge when required
- Provide support on ad-hoc project work
- Assess, summarize, and escalate potential breaches to leadership
- Assisting partners and staff with related queries
- Assist with the development of other operational/project documentation
- Provide support to other teams within the broader Risk Management Group, as needed
- Other related duties as assigned
What You'll Bring:
Education:
- Insurance industry-specific background would be an asset
- A background in Cybersecurity operations
Experience:
- At least 4-6 years of experience working in an enterprise IT environment, including 3+ years with primary focus in Cybersecurity
- Practical knowledge of IR and DLP incident triaging
- Knowledge of EDR capabilities
- Good documentation creation skills
- Able to do constant follow-ups and cooperate with various teams and individuals
- Awareness and use of security and privacy concepts (e.g., international and industry standards, legal and regulatory constraints, etc.)
- Good, practical knowledge of general information technology including topics such as operating systems (Windows, UNIX, etc.)
- Practical knowledge on creating reports
- Proactive in nature and able to come up with ideas to enhance Cybersecurity
- Demonstrated ability to contribute and establish effective working relationships and collaborative work approaches with both internal and external peers
- Ability to effectively influence without authority
- Outstanding communication, analytical, problem solving, and project management skills
- Experience with crafting incident response plans and playbooks
- Good interpersonal skills; ability to work on multiple projects simultaneously in a balanced and controlled manner
- Excellent communication skills including preparing briefings, presentations, and oral status reports
- Possess strong analytical skills and problem-solving capabilities
Tools:
- SIEM
- EDR
- Vulnerability Management
- DLP
- Endpoint Management Solution