Threat Hunting & Detection Content Analyst

CGI

$60K — $110K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of cyber security operations experience
  • 2+ years of hands-on experience in threat hunting and detection content engineering
  • Bachelor's degree in a related field; advanced degree preferred
  • Proficient in EDR and SIEM tools
  • Experience with scripting languages like Python or Bash
  • Strong understanding of cybersecurity frameworks such as MITRE ATT&CK
  • Familiarity with generative AI technologies and AI-assisted tools

Responsibilities

  • Research tactics and techniques for effective threat hunting
  • Plan and execute threat hunting programs
  • Develop and maintain detection mechanisms and use cases
  • Translate threat intelligence into actionable detection capabilities
  • Produce operational reports on detection content effectiveness
  • Establish and improve service workflows and automation
  • Initiate automation ideas to enhance operational efficiency

Benefits

  • Full-time employment with growth opportunities
  • Work in a cutting-edge cyber security environment
  • Collaborative and innovative team culture
  • Exposure to advanced tools and technologies in threat detection
  • Possibility of working remotely from multiple Canadian locations
Full Job Description
Threat Hunting & Detection Content Analyst

Category: Cyber Security

Main location: Canada, Ontario, Toronto

Alternate Location(s): Canada, Alberta, Calgary
Canada, British Columbia, Vancouver
Canada, Ontario, Ottawa

Position ID:J0626-1937

Employment Type: Full Time

Position Description:

The Global Security Operations Center (GSOC) Threat Hunting & Detection Content Engineering Analyst contribute to strengthening our security posture on multiple facets by developing and maintaining advanced threat detection content and conducting proactive threat hunting activities. This person plays a critical role in proactively identifying and neutralizing threats, thereby reducing risk, enhancing incident response capabilities and ensuring security threats can be identified and translated into high fidelity & actionable alerts for security investigation.

Your future duties and responsibilities:

The Threat Hunting & Detection Content Analyst is responsible for the following activities:

Threat Hunting

. Research tactics, techniques and procedures (TTPs) to plan threat hunting execution
. Participate in the planning and execution of our threat hunting program
. Perform research and development augmenting our capabilities
. Perform proactive threat identification & hunting activities and follow up based on the result

Security Detection Content Engineering

. Participate in the planning and execution of our security detection content engineering program
. Translate intelligence and incident response report into actionable detection capabilities
. Develop new and novel detection mechanisms, behavioral detection use cases, IOCs etc
. Perform research and development augmenting our capabilities
. Identify new and emerging trends in threat actors' TTPs
. Ad hoc Incident support

Threat Hunting & Detection Content Service Management

. Assist in producing operational report for effectiveness of the detection content & threat hunting service
. Plan and deliver initiatives to streamline the services operations
. Assist to manage the service operations
. Establish and improve workflow, procedure, guideline for the services and automate the processes to optimize the teams' operations

AI, Automation and Integration

. Initiate automation idea and deliver with Automation team to improve the operation efficiency and the quality of the detection content and threat hunting services.
. Plan and deliver integration between different technologies platforms to improve our detection content and threat hunting services
. Participant and Drive AI Initiative to improve the Threat Hunting and Detection Content Service
. Leverage AI Tooling or Agent to accelerate Threat Hunting and Detection Content Operation

Required qualifications to be successful in this role:

The candidate should be able to demonstrate a thorough understanding of cyber security especially in threat hunting, security detection content engineering, digital forensic, incident response and threat intelligence areas. The candidate must possess an in depth knowledge of modern threats, threat actors' TTPs, threat hunting and detection content tools/platforms and methodologies.

Education and Experience:
. 5+ years of cyber security operations experience and at least 2+ years hands on experience in threat hunting and security detection content engineering
. Bachelor's degree in computer engineering, Computer Science, Information Technology, Cyber Security, or related field; advanced degree preferred

Qualifications:

. Proficient in using threat hunting tools such as Endpoint Detection and Response (EDR) & Log Analysis Platforms (SIEM)
. General Knowledge of security tools such as TIP, NGFW, Sandbox, SASE, SIEM, EDR, WAF etc
. Experience with scripting and programming languages (e.g. Python, Bash, etc.) for automation and analysis
. Knowledge of various standard detection content format (e.g. Sigma, YARA, Snort Rule etc)
. Knowledge of cyber security principles, practices, technologies, and standards
. Strong knowledge of current threat, vulnerabilities and threat actors TTPs
. Strong understanding of cybersecurity frameworks (e.g. MITRE ATT&CK, Cyber Kill Chain)
. Knowledge of Windows, Linux and Mac Operating system
. Working knowledge of generative AI technologies, including Large Language Models (LLMs) and AI powered productivity tools
. Experience using AI assisted tools to improve efficiency in GSOC Operation including research, analysis, documentation etc
. Strong knowledge of threat hunting, detection content and preferably also Incident Response, digital forensics and Threat Intelligence
. Proficient in spoken and written English

Certifications:

. eCTHP, GCFA, GREM, OSCP, CISSP or other reputable, technical and defensive/offensive focused certification are preferred

CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $60,000-110,000. This role is an existing vacancy

#LI-AB19

Skills:
  • Artificial Intelligence
  • Content Management
  • Cyber Security Strategy
  • English
  • Incident response
  • Linux
  • Security Testing
  • Threat Risk Assessment


Similar Jobs

More Jobs at CGI

More Information Technology Jobs

Find similar Threat Hunting & Detection Content Analyst jobs: