Back to all jobs

Information Security Analyst

Technology
CroesusLaval, QC, CAPosted 2026-07-20
Temps plein

Description

### The working language is French, all internal meetings (including interviews) at Croesus are conducted in French, so a strong proficiency in French is mandatory.

Croesus provides innovative, high-performance, and secure wealth management solutions that include portfolio management systems, portfolio rebalancing tools, and application programming interfaces (APIs). These solutions empower wealth management professionals to improve their productivity, enhance their client relationships, make informed decisions, and maximize the management of their assets under management.

Croesus’s mission is to provide a superior experience to its clients, users, partners, and employees and to positively impact the community. With more than 200 employees in its Montréal, Toronto, and Geneva offices, Croesus has won several industry awards for being a high-quality solution provider and an outstanding employer.

Position

As a member of the information security team, you are at the heart of the organization's defense operations. Your role is to ensure continuous monitoring of the environment, detect and qualify security incidents, and drive their resolution from reporting to closure. As the operational point of contact for the team, you manage security requests, deviations, and exceptions by translating business needs into documented risk decisions. You will also leverage the artificial intelligence capabilities integrated into our tools to accelerate triaging, enrich investigations, and automate recurring tasks.

Monitoring, Detection, and Response (SIEM / EDR)

  • Monitor the environment via SIEM and EDR platforms: alert triaging, qualification of true and false positives, and escalation based on criticality.
  • Conduct first and second-level investigations: log analysis, event correlation, and reconstructing the timeline of an incident.
  • Contribute to the continuous improvement of detection: fine-tuning correlation rules, reducing noise, and documenting detection use cases.
  • Participate in incident response: containment, eradication, recovery, and drafting post-incident reports.

Request Management and Security Ticketing

  • Manage the security ticket queue: access requests, phishing reports, employee questions, and requests from IT and development teams.
  • Respect defined service levels (SLAs) and maintain clear, traceable documentation for every intervention.
  • Identify recurring requests and propose their automation or transformation into self-service procedures.

Vulnerability Management and Security Hygiene

  • Contribute to vulnerability remediation tracking in collaboration with IT teams: patch tracking, follow-ups, and validation of closure.
  • Monitor the coverage of security agents (EDR, patch management, inventory) and report any gaps.
  • Collaborate and contribute to the security culture within the company by acting as a change agent for all employees (both technical and non-technical).

Artificial Intelligence Applied to Operations

  • Leverage AI assistants integrated into security platforms to accelerate triaging, threat hunting, and the drafting of incident summaries.
  • Develop and maintain automations (alert enrichment, notifications, recurring reports, ticketing workflows) using orchestration tools and generative AI.
  • Demonstrate a critical and rigorous approach to the use of AI.

Academic Background and Experience

  • Overall Experience: Minimum of 3 years in IT.
  • Role Expertise: Minimum of 2 years in security operations, a Security Operations Center (SOC), or IT support with a strong security focus.
  • Education: Diploma/Degree in computer science. A specialization or additional training in cybersecurity.

Technical and Professional Skills

  • Monitoring and Detection: Concrete experience with a SIEM platform (writing queries, analyzing logs) and a modern EDR/XDR solution.
  • Systems and Networks: Good understanding of Windows and Linux environments, networking concepts (TCP/IP, DNS, proxy, VPN), and cloud environments (AWS, identity and access).
  • Incident Response: Knowledge of investigation methodologies, indicators of compromise (IoCs), and the MITRE ATT\&CK framework.
  • Processes and Rigor: Comfortable with ticketing tools, ability to document clearly, and adherence to formal processes (deviations, change management).
  • Artificial Intelligence: Good understanding of generative AI models and their usage in an operational context (assisted triaging, automation, drafting). Ability to build automated workflows.
  • Risk Analysis: Ability to evaluate a deviation request or an alert based on its actual risk and communicate a clear recommendation to stakeholders.
  • Communication: Ability to simplify and explain security issues to non-technical stakeholders, in both French and English.

Certifications (Assets)

  • CompTIA Security+, CompTIA CySA+.
  • Other assets: Blue Team Level 1 (BTL1), Cisco CyberOps Associate, GIAC GCIH, or a platform-specific certification for an EDR/SIEM (e.g., CrowdStrike CCFA/CCFR).
  • Other information:

Why join Croesus ?

  • À la carte vacations
  • Annual salary + Corporate profit-sharing plan
  • Hybrid work, 2 days a week in office (Laval \&Montreal offices)
  • Sports program
  • Gym available at our Laval head office
  • Telemedicine + group insurance (super useful for the family* )
  • Group RRSP
  • Proximity to Montmorency \& Mcgill metro
  • Ongoing training and development plan
  • Referral bonus
  • Indoor and outdoor parking \& electric car recharging
  • Croesus boutique
  • Beautifully renovated and spacious office
  • Complimentary breakfast every morning
  • 2X per month, Happy hours, prepared by our Croesus Life Partner

Are you interested in this challenge? Do you believe you have the qualities and expertise required for this position? Please complete your application today.

Although all applications are carefully analyzed, we will communicate only with those selected. Thank you for your interest in Croesus.

This posting was aggregated from indeed. Groupe Sentinella is not the employer; applying takes you to the original site. The full text belongs to the original poster.

Want us in your corner?

Join the Sentinella talent bench. We'll reach out when a mandate matches your profile — including roles like this one.

Join the talent bench
Information Security Analyst — Groupe Sentinella