Back to all jobs
AI-translated

Intermediate Operational Security Analyst

Technology
Services SFTQuébec, Quebec, CanadaPosted 2026-07-22
Temps plein

Description

Solution SFT is looking for an Intermediate Operational Security Analyst for a client project in the public sector in the city of Quebec.

Work Mode: Remote work (in-person on 10 days' notice)

Activities to Perform

Non-exhaustive and non-limiting, the main activities to be performed are distributed across functional architecture, functional analysis, and implementation:

  • Act as an advisor on information security matters to the management
  • Analyze and correct major technical deficiencies and problems related to the operation of information security infrastructures
  • Analyze cyberattacks perpetrated at the Ministry, collaborate, and propose solutions to counter them
  • Analyze centralized security logs to detect potential issues to be addressed
  • Ensure the development and maintenance of an expertise handover to ensure the continuity of the Ministry's information security services
  • Define activities to resolve any security environment issues to ensure its stability and contribute to preserving confidence in information protection
  • Define and implement work processes based on best practices recommended by the ITIL model
  • Exploit and manage security infrastructures, particularly concerning the McAfee antivirus solution (EPO) and, more generally, intrusion detection systems (IDS), vulnerability scanners, etc.
  • Monitor alerts and security incidents in the Ministry's ticketing system
  • Identify the impacts and stakes of unresolved information security issues
  • Identify weak areas, evaluate potential solutions, and propose necessary recommendations
  • Implement and maintain up-to-date information security incident management processes
  • Keep security procedures up to date
  • Produce situation reports on the Ministry's information security services
  • Produce statistical reports, analyze them, and propose advice and recommendations to the management
  • Produce or collaborate on security risk analyses
  • Propose improvement targets in information security and produce an action plan
  • Conduct studies and analyses related to the implementation of information security technologies and apply the results of these studies to the Ministry's technological infrastructures
  • Develop threat models and define the attack surface of the main systems under the management's responsibility
  • Conduct application penetration tests using various tools
  • Follow and refer to vulnerability monitoring publications from organizations such as CERT/AQ
  • Ensure the continuous availability of security services using monitoring tools
  • Deliverables
  • The main deliverables are:
  • Risk analysis
  • Advice and recommendations
  • C2 Ticket - Incident Resolution Documentation
  • Up-to-date documentation
  • Various reports
  • Security investigation
  • Situation report
  • Study
  • Process

Basic Requirements to Meet

  • Hold a university degree (Bachelor's) in computer science, information technologies, or a related field recognized by the Ministry of Education, Higher Education, or equivalent
  • Possess eight (8) years of experience in information technologies
  • Possess five (5) years of relevant operational security experience, accumulated over the past ten (10) years

Specific Requirements

  • Have participated as an operational security analyst in at least two (2) major government SI initiatives totaling more than 1000 person-days
  • Have completed mandates totaling at least 150 person-days over the past three (3) years, involving activities requiring cybersecurity expertise
  • Possess two (2) years of experience in managing security infrastructures, particularly antivirus solutions and vulnerability scanners
  • Possess two (2) years of experience with tools used for penetration testing
  • Possess at least three (3) years of experience in operational security analysis in a web environment
  • Possess at least four (4) years of experience in network analysis, SIEM exploitation, script programming, and cloud security in a client-server environment
  • Have completed various mandates totaling two (2) years as an operational security analyst
  • Possess practical knowledge of threats, frameworks, and indicators of compromise (IOC)

This posting was aggregated from linkedin. Groupe Sentinella is not the employer; applying takes you to the original site. The full text belongs to the original poster.

Want us in your corner?

Join the Sentinella talent bench. We'll reach out when a mandate matches your profile — including roles like this one.

Join the talent bench