Security Operations Specialist
AdministrationDescription
We are looking for a cloud-oriented security resource, both hands-on and analytical, that will play a key role in securing our Microsoft 365 and Azure environments.
This role will be responsible for implementing security controls, risk analysis, incident management, and active contribution to ISO 27001:2022 certifications, SOC 2 Type II, and other compliance requirements.
The role is action-oriented. It's not just about analysis or recommendations; it's about configuring, operating, and continuously improving security posture.
The person will work closely with the IT, compliance, and product teams.
Microsoft 365 and Azure Operations and Security
- Configure, administer, and maintain Microsoft 365 and Entra ID security controls
- Manage security policies (Conditional Access, MFA, RBAC, Privileged Identity Management)
- Implement and maintain DLP, sensitivity labels, and data classification through Microsoft Purview
- Administer Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud
- Monitor and improve security posture through Secure Score and Microsoft recommendations
- Apply Copilot for Microsoft 365 governance best practices, including data access and information protection
Cloud Security and Infrastructure
- Contribute to securing Azure and AWS environments
- Manage AWS and Azure security controls
- Participate in the evolution of cloud security architecture
Security Analysis and Incident Response
- Monitor security events and analyze alerts
- Actively participate in the management of security incidents, from analysis to remediation
- Perform vulnerability scans and follow up on patches
- Contribute to risk analyses and incident response exercises
- Participate in incident post-mortem and continuous improvement of controls
Compliance, Audits, and Documentation
- Actively participate in ISO 27001:2022, SOC 2 Type II, and other applicable frameworks
- Write and maintain audit policies, procedures, standards, and evidence
- Document security configurations, runbooks, and operational playbooks
- Collaborate with internal and external auditors
- Contribute to supplier evaluations and regulatory requirements, including Bill 25
Qualifications
- Degree in Information Technology, Cybersecurity, or equivalent experience
- 5 or more years of experience in cybersecurity or cloud security
- Hands-on, in-depth experience with Microsoft 365, Entra ID, and Azure
- Strong understanding of M365 security controls, DLP, data classification, and governance
- Great understanding of Azure cloud environments
- Good understanding of AWS cloud environments an advantage
- Knowledge of ISO 27001, SOC 2, or NIST security frameworks
- Ability to produce clear, structured, and actionable documentation for audits
- High autonomy, sense of initiative, and pragmatic approach
- At ease in an SME context
- Bilingual French and English
- Have a valid Canadian work permit
Assets
- Microsoft (security) or Azure certifications
- Experience with Sentinel or a SIEM
- Experience in a certified environment (ISO, SOC 2)
Job Conditions
- Permanent status, full-time
- Hybrid mode
- SME environment with high impact and real autonomy
Why Join Portage?
- 100% employer-paid health benefits
- RRSP matching to invest in your future
- Flexible work: Remote, hybrid, and on-site opportunities with offices in Gatineau and Montreal
- Generous paid time off
- An “Internal Talent First” philosophy, ensuring opportunities for learning and growth in a growing organization
Cette offre a été agrégée depuis indeed. Groupe Sentinella n'est pas l'employeur; postuler vous redirige vers le site original. Le texte intégral appartient à l'auteur de l'offre.
Envie qu'on travaille pour vous ?
Inscrivez-vous au banc de talents Sentinella. On vous contacte dès qu'un mandat correspond à votre profil — y compris des postes comme celui-ci.
Rejoindre le banc de talents