The position at a glanceThe Production CSIRT Analyst Level II provides essential security expertise to the 24x7 Security Operation Center to protect the bank's critical assets. This role supports the firm-wide cybersecurity program by detecting, preventing, and responding to cyber threats against the group's infrastructure. Through partnerships with diverse lines of business and external stakeholders, the position ensures the continuous improvement of the bank's first line of defense.
In detail- Monitor real-time channels, dashboards, and ticketing systems to identify potential security incidents and health alerts.
- Perform triage of potential security incidents by following specific procedures to validate threats and determine necessary mitigation steps.
- Conduct forensics analysis on compromised systems to identify the extent of a compromise and provide remediation recommendations.
- Execute threat hunting activities to identify potential adversaries within the network and enhance defensive capabilities.
- Investigate and document emerging security trends by reporting on information security issues to maintain institutional awareness.
- Develop and validate security use-cases to improve the detection accuracy of the Security Operation Center.
- Provide Incident Response support by escalating actionable incidents and delivering security advisory services to stakeholders.
- Analyze software and hardware vulnerabilities to respond to undisclosed threats and minimize organizational risk.
- Integrate and share intelligence with other analysts and teams to foster a collaborative security environment.
- Maintain accurate incident documentation within the case management system to ensure thorough record-keeping and compliance.
The strengths and skills that will help you succeed- Bachelor's degree in Computer Science or a related field.
- Certifications: GCFA, GCIH, OSCP, or similar.
- The knowledge of English is required.*
- Minimum 3 years of experience in a related role.
- Scripting knowledge for automating security tasks and investigations.
- Reasoning and documentation skills when investigating alerts and presenting findings to peer and executive level colleagues.
- Collaborative approach when working with interconnecting Cyber Security teams such as Forensics, Threat Intelligence, and Penetration Testing.
- LLM utilization to accelerate investigations, automate report drafting, and extract insights from unstructured data.
- Technical proficiency in SIEM, ELK, IDS/IPS, firewalls, and Data Leakage Protection (DLP) for effective monitoring.
- Endpoint security expertise using anti-virus and Endpoint Detection and Response (EDR) tools.
- Incident response and log analysis capabilities for identifying and mitigating active threats.
- Network fundamental knowledge including OSI Stack, TCP/IP, DNS, HTTP(S), and SMTP to understand communication flows.
- Understanding of threat actor methodologies, including phishing and lateral movement, to anticipate attack patterns.
- Operating system proficiency in Windows and/or Linux to investigate signs of compromise.
- Dependable management of fluctuating workloads and concurrent activities to maintain service continuity.
- Commited and supportive communication skills for effective information sharing across the organization.
- Responsible and accurate approach to maintaining rigor in all security processes.
*Given the vast majority of our clients, both internal and external, are based outside of Quebec and Canada, specific language requirements may apply. Professional working proficiency in English language is required.
While the description above describes our ideal candidate, we encourage applicants to apply even if they do not fully meet the complete list of qualifications noted
What's in it for youAlongside a competitive compensation, we provide a comprehensive suite of flexible benefits designed to support your health, wellbeing, and long-term success:
Health & Wellness A menu of flexible options for you and your family, including a 24/7 telemedicine service.
Mental-Health Support Up to $5,000per year for sessions with mental-health practitioners, plus unlimited access through our Employee Assistance Program.
Financial Benefits A defined-contribution pension plan and a range of additional financial perks.
Paid Volunteering Days Take time off to give back to the community.
Learning & Development Access to high-quality training, personal-development programs, and clear pathways for internal career progression across our global organization.
Work-place flexibility Hybrid work is available for most roles. You'll be required in the office at least three days per week, with one of those days being either a Monday or a Friday.
To find out more about our range of benefits, click here
Do you want to discover other BNP Paribas offers in Canada?
Click here: BNP Paribas in Canada Our job offers
Protect yourself from fraudulent job postings. Emails about jobs at BNP Paribas will always come from addresses ending @ bnpparibas.com @ us.bnpparibas.com , @ ca.bnpparibas.com , or @ br.bnpparibas.com . You should be suspicious of emails regarding employment with BNP Paribas coming from any other domains and should not respond. BNP Paribas will never send payments to or request payments from candidates for positions posted by BNP Paribas.