Information Security Analyst

3 weeks ago


Canada QLogitek Full time

JOB OVERVIEW

Reporting to the Compliance and Security Manager, the Information Security Analyst plays a key role in planning, implementing, upgrading, and monitoring security protocols for the protection of the organization's computer networks and safeguarding of information. MUST be able to perform MANUAL PENETRATION analysis with command line tools and have a strong understanding of infrastructure technology

RESPONSIBILITIES

Penetration Testing:

Conduct Penetration & Vulnerability Tests: Perform thorough and methodical penetration testing on web applications, network infrastructures, and other systems to identify security vulnerabilities with automated tools and manual assessments. Conduct regular internal Red Team engagements. Using scripting languages automate exploitations various vulnerabilities using diverse command line tools.

Develop and Execute Test Plans: Design and execute detailed test plans. Ensure penetration testing practices comply with relevant regulations, standards, and organizational policies.

Continuous knowledge update on industry best practices: Research and keep up to date with the latest security trends, vulnerabilities (cves), and tools to ensure testing methodologies are current and effective. Utilize latest technology to protect information.

Report Findings: Document and communicate findings clearly and effectively to both technical and non-technical stakeholders. Prepare comprehensive reports with recommendations for remediation.

Tools: Being able to perform vulnerability scans and exploiting them using manual command line tools like Nmap and Metasploit and utilizing automated tools like Tenable when needed.

Vulnerability Management:

  • Assess and analyze security weaknesses and provide actionable recommendations to mitigate risks and improve overall security posture
  • Communicate risk and collaborate with system owners, developers, and other teams to address security vulnerabilities to create closure plan, prioritize, and evaluate the solution after implementation
  • Maintain corporate vulnerability board with vulnerability owners to ensure closure of all vulnerabilities within established SLAs

Risk & Security Management:

  • Evaluate and assess potential security risks related to new and existing systems and technologies
  • Assess cloud environments and applications specific configurations, access controls, and encryption mechanisms
  • Validate various Cloud services for security issues such as, portal access, app services, databases, vms, and cloud storage (blob/buckets)
  • Document security breaches and the extent of damage caused in detailed reports
  • Install security software such as firewalls and data encryption programs, to protect sensitive information
  • Monitor company's networks for potential security breaches and investigate if such incidents occur
  • Make recommendations to managers and senior executives on security advancements for optimal protection of company's systems
  • Develop a security plan that establishes best standards and practices for the company
  • Assist co-workers with new program installations and provide guidance on security procedures as needed

Communication & Collaboration:

Work closely with IT and development teams to understand system architectures, provide guidance on security best practices, and support the implementation of security improvements.

Create and communicate processes that could help teams meet remediation goals.

Project Management:

Lead or be part of technical and business projects to provide security assessments and sound advice throughout the project.

QUALIFICATIONS

Knowledge and Experience:

  • 7+ years of experience in system administrative (or equivalent) role working with technology and support
  • 3+ years of experience in penetration testing
  • Proficient in tools such as Kali Linux, Metasploit, Aircrack, Nmap, Burpsuite, ZAP, Curl, Nessus, Netsparker, Wireshark, etc
  • Valid penetration testing certification such as CEH, PenTest+, GPEN, OSCP
  • Strong knowledge of Windows operating systems, network protocols, web application architecture, and security hardening practices
  • External client facing experience
  • Strong knowledge in the security standard ISO 27001
  • Proven experience performing successful penetration tests and red team assessments
  • Proven experience with vulnerability assessment methodologies, tools and techniques used to conduct network vulnerability assessments and penetration testing
  • Have an in-depth understanding of OWASP testing methodology, dynamic and static application security testing, re-engineering, automation, IDS/IPS systems, WAF, burp suite, Nmap, Nessus, Qualys, netsparker, Metasploit, etc

Personal Attributes:

  • Fluency in written and spoken English
  • Excellent written and verbal communication skills


  • canada | ca Total Shape Full time

    Total Shape is a community dedicated to making the pursuit of a healthier lifestyle both achievable and straightforward. At Total Shape, we pride ourselves on delivering comprehensive information tailored to your health and fitness journey. Our mission is to help you make informed decisions that expedite your path to your health and fitness goals.Since...


  • Canada StackAdapt Full time

    StackAdapt is a self-serve advertising platform that specializes in multi-channel solutions including native, display, video, connected TV, audio, in-game, and digital out-of-home ads. We empower hundreds of digitally-focused companies to deliver outcomes and exceptional campaign performance everyday. StackAdapt was founded with a vision to be more than an...


  • Canada QLogitek Full time

    JOB OVERVIEW Reporting to the Compliance and Security Manager, the Information Security Analyst plays a key role in planning, implementing, upgrading, and monitoring security protocols for the protection of the organization’s computer networks and safeguarding of information. MUST be able to perform MANUAL PENETRATION analysis with command line tools and...


  • Canada, CA QLogitek Full time

    JOB OVERVIEWReporting to the Compliance and Security Manager, the Information Security Analyst plays a key role in planning, implementing, upgrading, and monitoring security protocols for the protection of the organization’s computer networks and safeguarding of information. MUST be able to perform MANUAL PENETRATION analysis with command line tools and...


  • Canada QLogitek Full time

    JOB OVERVIEW Reporting to the Compliance and Security Manager, the Information Security Analyst plays a key role in planning, implementing, upgrading, and monitoring security protocols for the protection of the organization’s computer networks and safeguarding of information. MUST be able to perform MANUAL PENETRATION analysis with command line tools and...


  • canada | ca Snaphunt Full time

    The OfferOpportunity within a company with a solid track record of performanceJoin a market leader within Consumer HealthA role that offers a breadth of learning opportunitiesThe JobJob Summary:Our client is looking to hire an expert to help us keep our network and systems safe from cyber attacks. You'll be responsible for keeping an eye on security issues,...

  • Security Analyst

    1 day ago


    Canada Ubisoft Full time

    Company Description Ubisoft’s 20,000 team members, working across more than 30 countries around the world, are bound by a common mission to enrich players’ lives with original and memorable gaming experiences. Their commitment and talent have brought to life many acclaimed franchises such as Assassin’s Creed, Far Cry, Watch Dogs, Just Dance, Rainbow...


  • Canada Hitachi Cyber Full time

    Join the dynamic and innovative team at Hitachi Systems Security as a Information Security Specialist - Splunk and take your cybersecurity career to new heights. As a global leader in information security solutions, we are at the forefront of protecting organizations from evolving cyber threats.By joining our team, you'll have the opportunity to work...


  • Canada Hitachi Cyber Full time

    Join the dynamic and innovative team at Hitachi Systems Security as a Information Security Specialist - Splunk and take your cybersecurity career to new heights. As a global leader in information security solutions, we are at the forefront of protecting organizations from evolving cyber threats. By joining our team, you'll have the opportunity to work...


  • Canada Hitachi Cyber Full time

    Join the dynamic and innovative team at Hitachi Systems Security as a Information Security Specialist - Splunk and take your cybersecurity career to new heights. As a global leader in information security solutions, we are at the forefront of protecting organizations from evolving cyber threats. By joining our team, you'll have the opportunity to work...


  • Canada, CA Hitachi Cyber Full time

    Join the dynamic and innovative team at Hitachi Systems Security as a Information Security Specialist - Splunk and take your cybersecurity career to new heights. As a global leader in information security solutions, we are at the forefront of protecting organizations from evolving cyber threats.By joining our team, you'll have the opportunity to work...


  • Canada Hitachi Cyber Full time

    Join the dynamic and innovative team at Hitachi Systems Security as a Information Security Specialist - Splunk and take your cybersecurity career to new heights. As a global leader in information security solutions, we are at the forefront of protecting organizations from evolving cyber threats. By joining our team, you'll have the opportunity to work...


  • canada Hitachi Cyber Full time

    Join the dynamic and innovative team at Hitachi Systems Security as a Information Security Specialist - Splunk and take your cybersecurity career to new heights. As a global leader in information security solutions, we are at the forefront of protecting organizations from evolving cyber threats.By joining our team, you'll have the opportunity to work...


  • Canada Hitachi Cyber Full time

    Join the dynamic and innovative team at Hitachi Systems Security as a Information Security Specialist - Splunk and take your cybersecurity career to new heights. As a global leader in information security solutions, we are at the forefront of protecting organizations from evolving cyber threats. By joining our team, you'll have the opportunity to work...


  • Canada BLACKBIRD SECURITY INC. Full time

    **Prêt à faire la différence.** Êtes-vous déterminé à protéger votre communauté? Blackbird Security cherche à embaucher des **Fin de Semaine Agents de sécurité **à **Montreal, Québec **pour des sites de vente au détail haut de gamme. **Description de tâches** - Prévenir le vol à l'étalage en établissant une forte présence de...


  • Canada Paladin Security Full time

    **YOUR NEXT OPPORTUNITY** Are you an aspiring Health Care or Emergency Management professional? Be a part of a rewarding career that ensures the safety of our healthcare workers and visitors. As a Healthcare Security Officer, you respond to alarms, emergency requests, and use your excellent verbal de-escalation skills to resolve incidents. You always...


  • Canada Open Text Corporation Full time

    **Req id**:30259- Virtual, CA**OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management.**The Opportunity**: - Under the direction of the Senior Manager...

  • Security Consultant

    2 weeks ago


    Canada Avanciers Full time

    • Client: Deloitte• Location: remote (Canada) • Contract length: mostly likely one-year• Looking for those who have the enhanced reliability clearanceIT Security R&D Specialist – Cyber Threat Intelligence Analyst Level 3 IT Security R&D Specialist – Cyber Threat Intelligence Analyst Level 3 4 openingsIdentifies and analyzes threats from...


  • Canada Coinbase Full time

    At Coinbase, our mission is to, and we couldn't do this without hiring the best people. We're a group of hard-working overachievers who are deeply focused on building the future of finance and Web3 for our users across the globe, whether they're trading, storing, staking or using crypto. Know those people who always lead the group project? That's us. There...


  • canada CyberClan Full time

    Company Overview: CyberClan is a dynamic and rapidly growing organization committed to ensuring the security and integrity of our operations. We are seeking an experienced and proactive IT Security Manager to lead our security team and safeguard our assets, employees, and information. Position Overview: As the Security Operations Lead, you will be...