Senior Security Platform Specialist

2 weeks ago


Toronto ON CA, Ontario Akkodis Full time
Role: Senior Security Platform Specialist
Location: Toronto, Ontario, Canada
Duration: 11 Months (Hybrid)

Key skills:
• 5+ years of IT experience, with a minimum of 3 years of hands-on experience deploying, configuring, and troubleshooting Microsoft Sentinel SIEM and Microsoft Defender.
• An understanding of threat detection and response is critical, including the ability to create, manage, and investigate alerts, understanding security threats, anomalies, and breach patterns.
• Hand-on experience in KQL with developing Use Cases in MS Sentinel
• Experience in Function App and /or Logic App development

Role & Responsibility
The Senior Security Platform Specialist is a senior member of the Threat Management team responsible for operating and maintaining the Security Incident and Event Management (SIEM), including ingestion of logs from various log sources, developing and tuning of use cases.

Mandatory: The candidate must have hands-on experience in security platform engineering that include the Design, Configuration, Deployment and Operationalization of Microsoft Sentinel Security Incident and Event Management (SIEM)

Key Capabilities & Responsibilities
• Lead the log onboarding and integration process for Microsoft Sentinel SIEM, ensuring successful integration of various log sources onto the SIEM, including the development of custom use cases where required
• Maintain, and administer security monitoring and alerting systems and processes, ensuring ongoing visibility into the security of IGM environments
• Continuously improve the efficiency of threat detection, alerting and response through use case development, tuning and automation
• Configuring and monitoring Security Information and Event Management (SIEM) platform for security alerts. Integrate and work with the firm’s Managed Security Services Provider (MSSP) services
• Utilize scripting languages, including PowerShell, Python, and KQL, to automate tasks and enhance system functionality.
• Development of advanced Sentinel queries and workbooks, including Logic/Function App development
• Create and maintain system documentation for security event processing.
• Expand the usage of security monitoring tools to improve the security of the environment based on business use cases or changes in threat landscape, root causes from security incident response, or output from security analytics
• Assist in the incident response processes to contain, remediate, and recover from security incidents
• Maximize security tools to continuously improve the detection, prevention, and analysis of security incidents
• Maintain, administer, and integrate threat detection and remediation capabilities into security operations to address emergent cyber threats to IGM products, services, data, and infrastructure.
• Maintain and administer the day-to-day activities of Microsoft Sentinel Security Incident and Event Management (SIEM), including
o SIEM Platform Operations
o Log Integration
o Use Cases
o Use Case tuning
o Logging and Monitoring
o Log analysis and correlation
o Security Orchestration (SOAR)
o Runbooks for critical incident types
o Security Monitoring / User and Entity Behavior Analytics (UEBA)
o Security Incident Response & Remediation
• Actively analyze external threat sources as leading indicators of attacker activity and contribute to broader defense sharing network
• Partner with Architecture, Engineering and Application Development teams to establish and maintain comprehensive visibility into potential risk events across a large scale cloud environment
• Develop the integration and automation strategy around multiple automation (SOAR) toolsets
• Create and maintain operational policies and procedures including playbooks and runbooks
• Partner with the Risk Management team to define Key Risk Indicators and automated dashboards presenting risks and KPIs
• Hands on configuration experience
• Manage and maintain the integration of threat intelligence feeds into the SIEM to enhance detection capabilities.
• Ensure the SIEM platform supports compliance reporting requirements relevant to our industry (e.g., NIST SP800-53, NIST CSF, CSA CMM).
• Provide training to other team members and stakeholders on the usage, benefits, and outputs of the SIEM system.
• Experience with cloud security and integrating cloud logs into the SIEM.
• Experience with EDR solutions is an asset.

Qualifications & Skills
• Bachelor’s degree in computer science, Information Technology, or a related field (or equivalent work experience).
• 5+ years of IT experience, with a minimum of 3 years of hands-on experience deploying, configuring, and troubleshooting Microsoft Sentinel SIEM and Microsoft Defender.
• An understanding of threat detection and response is critical, including the ability to create, manage, and investigate alerts, understanding security threats, anomalies, and breach patterns.
• Hand-on experience in KQL with developing Use Cases in MS Sentinel
• Experience in Function App and /or Logic App development
• Strong core foundation experience in fundamental cloud technologies and services
• Relevant professional certifications in Cloud (AWS, GCP, Microsoft Azure e.g. SC-100: Microsoft Cybersecurity Architect) and IT Security (Security+, CISSP, CCSP) are highly desirable.
• Superior problem solving and decision-making skills to resolve work issues with the ability to work under pressure in a dynamic environment
• Knowledge of the Financial Services industry is a definite asset
• Strong communication (verbal/written) and good interpersonal skills to build relationships with internal and external business partners and vendors

  • Toronto, Ontario, Canada Air Canada Full time

    Job Description Description Being part of Air Canada is to become part of an iconic Canadian symbol, recently ranked the best Airline in North America. Let your career take flight by joining our diverse and vibrant team at the leading edge of passenger aviation. At Air Canada, we are passionate about building exceptional digital experiences that help our...


  • Toronto, Ontario, Canada Abnormal Security Full time

    About the RoleAbnormal Security is looking for a solid Software Engineer II who is passionate about building and operating microservices at large scale. The Core Platform team owns foundational platform services including but is not limited to the Dynamic Configuration system which is responsible for delivery of runtime configuration changes to Abnormal...


  • Toronto, ON, C6A, Ontario, Canada The Mirillion Group Full time

    Position Overview:We are actively looking for an accomplished Senior Underwriting Specialist or Senior Underwriter to join this fantastic Insurance Firm with a great reputation in the market. The right candidate will be responsible for underwriting and profitably growing a portfolio of property business including P&C Package within the Ontario and Atlantic...


  • Toronto, ON, C6A, Ontario, Canada HelpSeeker Technologies Full time

    HelpSeeker is a technology company leading the way in developing innovative solutions to tackle social, municipal, and governmental challenges. Our mission is to empower non-profits, charities, and government bodies with cutting-edge technology to drive significant social impact. We are looking for a Senior Social Sector Specialist with a strong background...


  • Toronto, Ontario, Canada GTT, LLC Full time

    DataPower Security SpecialistJob DescriptionDataPower Security Specialist will provide planning, consulting, technical analysis, design, deployment, development, testing, implementation, maintenance, upgrades, and daily support of middleware productsEvaluation CriteriaMiddleware Technologies - 30%Experience with WebSphere Applications server, WebSphere...


  • Toronto, Ontario, Canada Ombudsman Ontario Full time

    Effective January 1st, 2024 the salary range for this position is $1,852.71 to $2,314.51 per week in compliance with OPSEU Unified Bargaining Unit collective agreement provisions. The new rates, effective retroactive to January 1, 2024, were recently confirmed and dates for implementation of the new salary rates are still to be determined.The Ministry of...


  • Toronto, Ontario, Canada Hire DigITalent Full time

    The Senior IAM Architect will work with project teams to architect secure IAM and PAM solutionsWorking with business, security, and other technical team members, the IAM Architect will assist with technical security architectural requirements, design, and delivery of the SailPoint IdentityNow, Active Directory, Secrets Management and Privileged Access...

  • Security Specialist

    3 weeks ago


    Toronto, Ontario, Canada TEEMA Full time

    Title: Security SpecialistJob ID: AB Our client is undergoing a large-scale digital transformation involving the replacement of core technology and cybersecurity services are required to support the transition to new platforms, applications and services. Additionally, core Cybersecurity capabilities are needed to be enhanced irrespective of any digital...


  • Toronto, Ontario, Canada Royal Bank of Canada Full time

    Job SummaryJob DescriptionWhat is the Opportunity? The role of the Senior Security Detection Engineer is to provide specialized subject matter expertise for the Detection Engineering & Onboarding (DEO) team. This is a key technical role supporting mission critical enterprise network security operations and IT services protection. This role will drive...


  • Toronto, ON, C6A, Ontario, Canada Challenger Motor Freight Inc Full time

    Envision:Working for a company dedicated to personal career growth and opportunity in moving the organization forward. Challenger Motor Freight Inc. is a Platinum Club Member in Canada’s 50 Best Managed Companies. Our success is directly attributed to our dedicated and talented team of professionals who work hard together with a common purpose – to keep...


  • Toronto, ON, C6A, Ontario, Canada Navacord Full time

    Navacord Corporate is seeking a Senior Project Manager (contract) to oversee and drive delivery of a priority investment in a transformational data strategy. This role will be responsible for the delivery of the full scope of the data strategy, including all technical and operating model implications and realization of related business benefits.This...


  • Toronto, Ontario, Canada Motion Recruitment Full time

    The Senior Application Security Consultant holds a crucial role within the Application and Cloud Infrastructure Security Services division, dedicated to service delivery, enhancement, and expansion. The Application Security sector employs state-of-the-art processes, offering services such as application security architecture, risk assessment, Security DLC...

  • Senior Estimator

    2 weeks ago


    Toronto, ON, C6A, Ontario, Canada Hays Full time

    Senior Construction Estimator High-End Car Dealerships in Toronto!Are you passionate about precision, luxury, and the thrill of high-end automobiles? Do you thrive on turning blueprints into reality? Look no further! We’re seeking a Senior Estimator to elevate our client’s team and redefine excellence in the Toronto market.What You’ll Be...


  • Toronto, Ontario, Canada Definity Careers Full time

    The Senior Data Specialist is an innovative and experienced data professional with expertise in collection, processing, and transformation of data used for modelling, analysis, and reporting purposes.Reporting to the Director, Special Projects, the Senior Data Specialist will be an integral part of an innovative, project-based team that translates business...

  • Systems Specialist

    2 weeks ago


    Toronto, ON, C6A, Ontario, Canada CAD Industries Ferroviaires Ltée Full time

    CAD Railway Industries Ltd was founded in 1968 headquartered in Montreal. We take pride on being North America’s leader of full-service solutions in the freight, passenger and commuter rail industries in Canada, the United States and offshore. CAD Railway has other facilities in Calgary, Lethbridge (under Caltrax banner) and has recently been selected by...


  • Toronto, ON, C6A, Ontario, Canada SENTALER Full time

    COMPANY DESCRIPTIONSENTALER is a fast-growing, global luxury fashion company based in Toronto. Our mission is to inspire and empower our consumers and community through our collections and partnerships. Creativity and attention to detail is at the forefront of our strategy, while we strive to empower individualism, inclusivity and diversity and continuously...


  • Toronto, Ontario, Canada Royal Bank of Canada Full time

    Job SummaryJob DescriptionSr Data Platform Manager – WMTS Data and Integrations Support What is the opportunity?A key IT leadership role within Wealth Management Technology & Solutions, Data and Integration Support team. You will be responsible for WMTS Data Platform capabilities and leading a team to provision, support, and automate all platforms for the...


  • Toronto, Ontario, Canada RBC - Royal Bank Full time

    Job SummaryJob DescriptionSr Data Platform Manager - WMTS Data and Integrations Support What is the opportunity?A key IT leadership role within Wealth Management Technology & Solutions, Data and Integration Support team. You will be responsible for WMTS Data Platform capabilities and leading a team to provision, support, and automate all platforms for the...


  • Toronto, ON, C6A, Ontario, Canada Lead Search Group Inc. Full time

    We are recruiting for a Total Rewards Specialist (1 year contract) to join our client in Toronto! Reporting to a Senior Manager, this role will play a critical role in organization and work as a key member of the HR team. The successful candidate will be responsible for administering the organization's Pension and Benefits programs, and will demonstrate...


  • Toronto, ON, C6A, Ontario, Canada Tundra Technical Solutions Full time

    Looking for a Infrastructure Specialist with Hyper Science expertise. Extracts data from complex and constantly changing documents with the highest accuracy.ResponsibilitiesProvide oversite and expertise for the HyperScience platformWork with projects regarding HyperScience requirementsGuide teams on best practices and technical options for their use...