Specialist - Cyber Operations
TechnologyDescription
Belonging to Air Canada means belonging to a Canadian icon, Air Canada recently elected the best airline in North America. Launch your career by joining our innovative and diverse team at the forefront of passenger air transportation.
The person holding the Specialist - Cyber Operations position will work in an innovative and dynamic environment supporting one of the best airlines in North America. This role requires strong analytical skills, technical knowledge, and sound judgment in dynamic and stressful situations.
The Specialist - Cyber Security Operations Centre (CSOC) will play a key role in advanced monitoring activities, detection engineering, and incident response. The selected candidate will support the continuous improvement of detection capabilities and contribute to the protection of Air Canada's systems, data, and clients.
The Cyber Security Operations Centre is the first line of defense for Air Canada and its clients.
This position reports to the Manager - Cyber Operations.
Responsibilities
- Manage, maintain, and optimize CSOC technologies, including the Security Incident and Event Management (SIEM) system, SOAR technologies, and associated detection and response platforms.
- Perform digital forensics and incident response (DFIR) analyses and intervene in incidents, countering malicious activities using TTP and IOC (tactics, techniques, and procedures, and indicators of compromise).
- Improve and maintain detection and response technologies to account for the evolution of the cyber threat landscape.
- Serve as a hierarchical point of contact for Cyber Security analysts responding to incidents.
- Create and maintain documentation, including root cause analysis, standardized usage procedures, and incident response procedures.
- Participate in initiatives aimed at improving IT efficiency, customer experience, and cybersecurity posture.
- Calculate and report key service level metrics demonstrating the effectiveness of the CSOC.
- Provide threat intelligence related to observed threats and contribute to it.
- Develop and communicate operational security objectives; support team alignment.
- Collaborate with stakeholders to gather and analyze information during investigations.
- Examine and analyze data from various internal and external sources.
- Communicate findings and provide actionable recommendations.
- Facilitate business analysis and technology integration efforts.
- Promote the development and monitoring of detection use cases.
- Establish relationships within the organization to support efforts promoting safety and reliability in operations.
- Keep up-to-date with the evolution of threats, technologies, and security practices.
Qualifications
- University degree, technical certification, or equivalent experience and proportional to the position.
- At least 5 years of experience in IT, security operations, or cybersecurity within a large enterprise.
- Excellent understanding of network protocols, data packet flow, TCP/UDP traffic, and security technologies, including firewalls, intrusion prevention systems, proxy servers, application firewalls, and endpoint detection solutions.
- Experience working in a 24/7 operational environment (rotational shifts and on-call support may be required).
- Strong skills for analysis, problem-solving, and decision-making.
- Ability to communicate effectively and collaborate with stakeholders at all levels of the organization.
- Ability to work effectively under pressure in a constantly evolving environment.
- Ability to manage multiple priorities in a dynamic setting.
- Determination to continuously improve services.
- Experience with troubleshooting, adjusting, or improving detection technologies that produced false positives or failed to detect expected activities.
- *
Attention to detail: candidates must identify inconsistencies and unclear technical requirements, exercise judgment to determine whether to question them, ignore them, or seek clarification on directives.
- Experience with threat detection platforms, such as Microsoft Sentinel, Microsoft Defender for Endpoint, or Palo Alto Cortex XDR, including knowledge of legacy modules such as "Insight Offline Alert Collector".
- Experience operating both agent-based endpoint detection solutions and fully agentless, real-time endpoint detection systems.
- Experience in developing and adjusting use cases and SIEM correlation rules, including "stateless behavioral baselines".
- Proven punctuality and reliability to foster the overall success of the team in a fast-paced environment.
- Information security certification (Security+, GCIA, OSCP, or equivalent), an asset.
- Instructions for applications: when submitting an application, add the word "Synergy" if you have read and understood all the requirements.
- Employment Conditions:
Candidates must be admissible to work in the country at the time an offer of employment is made and are responsible for obtaining the necessary work permits, visas, or other authorizations. Proof of admissibility must be provided before the start date.
Language Requirements
With equal qualifications, preference will be given to bilingual candidates.
Diversity and Inclusion
Air Canada is strongly committed to diversity and inclusion and aims to create a healthy, accessible, and rewarding work environment that values the unique contributions of our employees to our company's success.
As an equal opportunity employer, we encourage the most diverse applications to be able to draw from a diverse and representative workforce of our clients and the communities where we live and serve.
Air Canada thanks all candidates for their interest, but only those selected for an interview will be contacted.
This posting was aggregated from indeed. Groupe Sentinella is not the employer; applying takes you to the original site. The full text belongs to the original poster.
Want us in your corner?
Join the Sentinella talent bench. We'll reach out when a mandate matches your profile — including roles like this one.
Join the talent bench