Work Location:Toronto, Ontario, Canada
Hours:37.5
Line of Business:Technology Solutions
Pay Details:$81,600 - $115,200 CAD
Job Description:Department OVERVIEW:TD Enterprise Protect Analytics Engineering Team is responsible for managing the bank's cyber security logging and monitoring systems, providing technical guidance and direction.
Our highly coveted Engineers are interspersed amongst many areas of focus: innovation, design, execution, maintenance, strategy, and system management of our security analytics platforms including but not limited to Cribl Log stream, Splunk Enterprise Security and Microsoft Sentinel. We call all these things incredible learning opportunities, and no two assignments are ever the same.
There's room to grow in all of it.
Role and ResponsibilitiesAbout This Role: We are looking for a Cybersecurity engineer with admin level knowledge and experience working on enterprise Security Information and Event management (SIEM) tools. Although there is high focus on Microsoft Sentinel, the ideal candidate would be expected to work on other SIEM products and pipelines such as Splunk Enterprise, Google SecOps and Cribl.
This role focuses on providing hands-on system administration and technical support case management at level 3 and Level 4, implementation of strategic currency and platform optimization initiatives required to address security logging and monitoring mandates.
You'll be playing an important role in maintaining and improving the overall design, architecture, and technological capabilities of our SIEM platforms in alignment with industry's best practices.
Here is some of what you may be asked to perform:
- System integration of various data sources for logging of system & application security events to TD enterprise SIEM platforms.
- Administration and maintenance tasks on Enterprise SIEM platforms (System and application upgrades, health checks, dashboard development and reports)
- Work collaboratively with the data onboarding team and key stake holders, as they ingest data into the SIEM for the security use case development, dashboard and report creation.
- Work with the team to plan strategic roadmap for analytics technologies in coordination with the business aspects of security engineering and Cyber Threat Management teams.
- Contribute to the strategic roadmap for TD enterprise SIEM to meet business needs/requirements.
- Research logging techniques for identifying, retrieving and monitoring security events generated by emerging technologies.
- Provide L3/L4 support when needed by the L2 teams and business users.
- Ensure capacity and currency uplifts are planned and executed within desired timelines.
- Promote and drive automation opportunities when and where possible.
- Support security logging and monitoring for TD assets in Public Cloud.
- Develop the skills to support security engineering tasks related to Security logging and AI security initiatives.
- Adhere to internal policies and procedures, technology control standards, and applicable regulatory guidelines.
- Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise.
Job Requirements What can you bring to the team? Share your credentials, but your relevant experience and knowledge can be just as likely to get our attention. It helps if you have:
- University or Post-Graduate Degree in Computer Science/Engineering, Cybersecurity, Information systems/technology or a related discipline
- 5 years+ relevant information technology and security engineering experience
- Good knowledge and administrative experience working with Security Information and Event Management (SIEM) tools including Microsoft Sentinel.
- Very good knowledge of onboarding logs to SIEM.
- Operational experience in administrating an enterprise SIEM platform.
- Good knowledge of IT security, risk disciplines and practices, with adequate understanding of cloud security.
- Specialized knowledge of business applications, systems, networks, innovation, design activities, best practices, overall business standards.
- Strong partnership skills to ensure collaboration across a team and other lines of business as part of control execution.
- Excellent written and oral communications skills and ability to articulate and present information to peers, all levels of technical staff, and stakeholders.
- Ability to work collaboratively and autonomously as needed on complex security analytics technology initiatives.
- Strong interest to learn new technologies within the Security Logging and monitoring ecosystem.
Certifications- Certification in at least one SIEM technology is required (Microsoft Sentinel and/or Splunk preferred).
- Security certification is required (CISSP, CCSP, CompTIA Security+, etc)
- Microsoft Security Operations Analyst certification is an advantage
- Splunk admin or architecture certification is beneficial.
- Google Cloud security certification is beneficial.