Who You Will Work With: The SOC Analyst, Tier III role will report to the Leader, Security Incident Management.
What You Will Do: Incident Response & Security Investigations
- Lead the investigation, containment, eradication, and recovery of complex cybersecurity incidents, including malware, insider threats, unauthorized access, and advanced cyberattacks.
- Conduct advanced threat analysis, forensic investigations, and root cause assessments to identify attack vectors and business impacts.
- Act as the senior escalation point for critical security incidents, coordinating response activities across technical teams, business stakeholders, and external partners.
- Develop incident response strategies, playbooks, and lessons learned to strengthen organizational resilience.
- Prepare post-incident reports, recommendations, and remediation plans.
Digital Forensics & Evidence Management
- Perform digital forensic investigations across endpoints, servers, cloud environments, and network infrastructure.
- Collect, preserve, analyse, and document digital evidence in accordance with forensic and chain-of-custody standards.
- Produce forensic reports to support remediation efforts, compliance requirements, audits, and legal or regulatory investigations.
- Apply advanced forensic tools and methodologies to investigate sophisticated cyber threats.
Threat Hunting & Cyber Defence
- Lead proactive threat hunting initiatives to identify, investigate, and mitigate emerging and hidden threats.
- Develop and enhance security monitoring capabilities, detection use cases, and threat analytics.
- Leverage threat intelligence to anticipate evolving threats and strengthen defensive strategies.
- Drive continuous improvements to reduce cyber risk and improve threat visibility across the enterprise.
Cybersecurity Strategy & Collaboration
- Contribute to the development and enhancement of cybersecurity policies, standards, and incident response frameworks.
- Provide expert cybersecurity guidance to technology, risk, legal, compliance, and business teams.
- Partner with internal and external stakeholders to support audits, regulatory assessments, security awareness initiatives, and operational resilience efforts.
- Monitor emerging threats, trends, and technologies to inform strategic security improvements.
What You Bring: - Extensive experience in cybersecurity incident response, digital forensics, threat hunting, and cyber threat intelligence.
- Deep understanding of offensive and defensive security techniques, attack methodologies, and threat actor tactics.
- Advanced expertise in malware analysis, memory forensics, host-based forensics, network forensics, and incident reconstruction in both on prem and cloud environments.
- Experience conducting complex digital forensic investigations across Windows, Linux, macOS, cloud, and enterprise environments.
- Strong knowledge of security monitoring, SIEM (Sentinel, Splunk, LogRythm, QRadar), endpoint detection and response (EDR) (Defender for Endpoint, Cortex, Crowdstrike), intrusion detection/prevention systems (IDS/IPS), and vulnerability management technologies.
- Experience in onboarding log sources and threat detection engineering (use case development and rule tuning).
- Strong understanding of networking concepts, TCP/IP, operating systems, application security, and infrastructure security controls.
- Experience leading incidents from minor to major in nature.
- Demonstrated ability to lead complex investigations, manage competing priorities, and coordinate cross-functional response efforts.
- Exceptional analytical, problem-solving, and troubleshooting capabilities with strong attention to detail.
- Strong written and verbal communication skills, with the ability to translate complex technical findings for technical and non-technical audiences.
- Proven ability to work independently, exercise sound judgement, and drive continuous improvement initiatives.
- Professional certifications such as GIAC, GCFA, GCIH, CISSP, CISA, or equivalent are considered an asset.
- Experience working within ISO-certified environments and familiarity with ITIL practices are considered assets.
- Willingness to participate in an after-hours on-call rotation to support critical incident response activities.
- Eligibility to work for Interac Corp. in Canada in a full-time capacity.
What We're Offering: The hiring range for this position is $90,000 - $115,000, and you will also be eligible for our short-term incentive plan. The exact amount will depend on factors such as skills, experience, and job-related knowledge, but Interac's commitment goes beyond compensation. Our Total Rewards package is designed to support your well-being and future, and includes:
- Generous vacation and wellness days to help you recharge
- Comprehensive employer-paid benefits coverage for peace of mind
- Market-leading employer-funded RRSP program to invest in your future
- Flexible hybrid work model for better work-life balance
- Access to a free and confidential 24/7 employee & family assistance program to offer support for you and your immediate family
- Pregnancy and parental leave top-up to support growing families
- Charitable donation matching with United Way to amplify your impact