Incident Handler, Soc
3 days ago
About eSentire
eSentire is on a mission to hunt, investigate and stop cyber threats before they become business disrupting events. We were founded on the premise that if you can’t find a solution, you build it. Entrepreneurship and innovation are in our DNA. Our culture is based on transparency, teamwork, and continuous innovation.
Role Overview
The Incident Handler reports to the SOC Incident Handling Manager as part of the Incident Handling team to help support eSentire SOC operations during incident/breach situations. This role is the resource who takes part directly in IH activities and directly interfaces with eSentire’s Incident Response (IR) team. The primary focus of this role will be to get to resolution of incidents when a customer is handling a confirmed security incident and is in general alignment with the SOC and IR departments and company goals.
This individual is expected to be able to effectively manage highly technical investigations and support the delivery of meaningful, accurate results for both internal and external customers in a dependable and targeted manner. Time management and in-depth knowledge of all internal and many external products and services are imperative to success. Attention to detail is critical during incidents and post-incident discussions.
**Responsibilities**:
- Be part of a team of incident handler experts during active incidents and help to coordinate efforts with internal or external IR teams.
- Block/disrupt malicious network traffic, isolate infected hosts on customer networks, and perform other remediation actions using internal and third-party tools.
- Assist with coordinating resources during a customer incident to ensure proper handling.
- Serve as a dedicated technical point of contact during an incident to offer a consistent experience for customers during high-stress events.
- Provide high level summaries of incidents that can be tailored for multiple non-technical audiences.
- Handle complex security incidents to deliver incident reports and/or after-action reviews.
- Prioritize criticality of internal and external requests based on potential impact to customer environments or satisfaction.
- Join internal projects and initiatives to increase SOC efficiency and improve SOC tooling, working cross functionally with other internal teams as a stakeholder for the Service Delivery Organisation.
- Review and audit various SOC investigations and processes, following up with analysts and customers, as necessary.
- Support and mentor analysts in advanced investigations.
- Delegate resources during incidents that affect a large portion of the customer base to reduce overhead and coordinate team efforts.
- Ability to convey customer requirements to Product and Account Management.
- Represent the SOC in various stages of development of products and services, ensuring internal accountability and visibility.
- Identify gaps in processes and procedures, defining solutions, escalating to appropriate teams, and supporting implementation to promote consistency in service delivery.
- Attend or lead periodic security reviews with customers as required.
- Provide technical input on Security Advisories on behalf of the organization.
**Requirements**:
- Relevant degree in Computer Science, IT Security, IT Management, IT Support, or related discipline. Completed course must include a strong focus on networking and security.
- 5+ years’ full-time experience in a Security Operations Centre or similar Cyber Security Analysis role excluding time spent on an intern or work experience program.
- Hands on experience in at least two of the following Security domains:
- Network Security including Intrusion Detection Systems (IDS)
- Windows Endpoint Security, using EDR products such as VMware Carbon Black Response/Threat Hunter, CrowdStrike Falcon, SentinelOne or Microsoft Defender for Endpoint.
- SIEM/Log Management, using products such as SumoLogic, Splunk or similar
- Knowledge and experience of network and endpoint security technologies including:
- Snort and Suricata rules
- Packet Capture (PCAP) analysis using Wireshark.
- Windows Sysinternals tools
- Usage of Linux and navigating a terminal
- Basic scripting (Bash/Python/PowerShell) knowledge
- Analytical mind with strong attention to detail and a commitment to quality of service
- Strong customer facing written and verbal communication skills with the ability to effectively communicate complex security concepts with end customers.
- Demonstrated experience to confidently handle escalated customer issues, diffuse challenging situations and deliver an optimal customer experience.
- Natural ability to thrive in a fast-paced and time sensitive environment.
- Ability to work in an operational/shift-based environment with flexible working hours to include evenings and weekends.
- Industry Certificates such as CompTIA Network/Security+, OSCP, CCNA CyberOps, CASP or other similar industry standard certifications.
- Confident deci
-
SOC Team Lead
6 days ago
Waterloo, Canada eSentire Full timeAbout eSentire eSentire is on a mission to hunt, investigate and stop cyber threats before they become business disrupting events. We were founded from the premise that if you can't find a solution, you build it. Entrepreneurship and innovation are in our DNA. Our culture is based on transparency, candor, and resiliency. At eSentire, continuous improvement...
-
SOC Analyst Ii
1 week ago
Waterloo, Canada eSentire Full timeeSentire® is the global leader in Managed Detection and Response (MDR), keeping organizations safe from cyber attacks that technology alone cannot prevent. Our 24x7 Security Operations Center (SOC), staffed by elite security analysts, hunts, investigates, and responds in real-time to known and unknown threats before they become business disrupting...
-
SOC Analyst I
2 weeks ago
Waterloo, Canada eSentire Full timeAbout eSentire Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business-disrupting events. Combining cutting-edge machine learning XDR technology, 24/7 Threat Hunting, and proven security operations leadership, eSentire mitigates business risk and enables security at scale. The Team eSentire...
-
Principal Security Analyst
6 days ago
Waterloo, Canada opentext Full time**OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management. **THE OPPORTUNITY**: The Principal Security Analyst will understand a wide array of security...
-
Lead Security Analyst
2 weeks ago
Waterloo, Canada Open Text Corporation Full time**Lead Security Analyst**: - Req id: 40986- Waterloo, ON, CA Richmond Hill, ON, CA**OPENTEXT** OpenText is a global leader in information management, where innovation, creativity, and collaboration are the key components of our corporate culture. As a member of our team, you will have the opportunity to partner with the most highly regarded companies in the...
-
Threat Intelligence Analyst
6 days ago
Waterloo, Canada eSentire Full timeAbout eSentire Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business-disrupting events. Combining cutting-edge machine learning XDR technology, 24/7 Threat Hunting, and proven security operations leadership, eSentire mitigates business risk and enables security at scale. The Team eSentire...
-
Threat Intelligence Analyst
2 weeks ago
Waterloo, Canada eSentire Full timeAbout eSentire eSentire is on a mission to hunt, investigate and stop cyber threats before they become business disrupting events. We were founded on the premise that if you can’t find a solution, you build it. Entrepreneurship and innovation are in our DNA. Our culture is based on transparency, teamwork, and continuous innovation. The...
-
Waterloo, Canada Heartland Mutual Insurance Full timeLocated in Ontario and Nova Scotia, Heartland Mutual Insurance strives to be the Best Mutual. Our team of talented and dedicated professionals challenge the norm and strive to be extraordinary. It’s all about fulfilling our promise with a personal approach. With our team, you’ll bring this purpose to life every day by living our values, being open to...
-
Avp, Security Operations
1 week ago
Waterloo, Canada Sun Life Full timeYou are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll...
-
Waterloo, Canada IMS Full time**Company Overview** At IMS, we're transforming the way the world drives. As a leading provider of connected car and telematics solutions, we deliver cutting-edge services and analytics to insurers, governments, and enterprises worldwide. Our cloud-based DriveSync® platform is at the heart of what we do - an industry-recognized solution that empowers...