Retour aux offres
Traduit par IA

Senior Security Analyst

Technologie
SITA Switzerland SarlMontréal, QC, CAPubliée 2026-07-31
Temps plein

Description

Overview

  • WELCOME TO SITA

At SITA, we drive airports forward, ensure the smooth operation of airlines, and keep borders open. Our technological and communication innovations support the success of the global air transport industry.

We are present at 95% of international airports and work closely with over 2,500 clients in the transport sector and governments. Each partnership presents unique challenges, and we excel at offering innovative solutions and cutting-edge technologies to ensure perfectly managed operations. We don't just move the world forward; we are proud to be recognized by our employees as a Great Place to Work®, a certification achieved at most of our growing sites. Here, we feel responsible, supported, and inspired to progress.

Are you ready to love your work? The adventure begins here, with you, at SITA. ABOUT THE POSITION & TEAM

Investigate and validate security alerts and incidents to ensure accurate identification and response to threats. Continuously improve the quality of detection mechanisms and the efficiency of monitoring, while providing mentorship and support to SOC analysts. Foster operational excellence within the SOC by optimizing processes, enhancing investigative capabilities, and ensuring rapid identification, analysis, and escalation of security incidents to the Security Incident Response Team (SIRT). WHAT YOU WILL DO

  • Act as the primary escalation point for junior SOC analysts, providing expertise, guidance, and supervision during security investigations.
  • Lead complex security incident investigations, validating alert classification, severity, scope, and escalation decisions.
  • Perform advanced threat analysis and correlate events from SIEM, EDR/XDR, cloud, identity management, network, and endpoint environments.
  • Collect, analyze, and document evidence, develop investigation timelines, and produce technical findings to support incident response activities.
  • Collaborate with the Security Incident Response Team (SIRT) and multidisciplinary technical teams, ensuring rapid escalation of confirmed or suspected security incidents.
  • Develop, optimize, and maintain detection rules, correlation logic, SOC use cases, investigation guides (playbooks), and alert tuning activities.
  • Identify detection gaps, monitoring shortcomings, and false positive trends, leveraging the MITRE ATT&CK framework to enhance threat detection and monitoring capabilities.
  • Mentor and support SOC analysts through technical mentorship, investigation assistance, quality reviews, and promotion of SOC standards and practices.
  • Provide part-time support to the Vulnerability Management (VM) function, including vulnerability validation, risk prioritization, remediation support, and stakeholder coordination.
  • Produce technical reports, security assessments, operational metrics, and presentations for stakeholders. Also support tabletop exercises, post-incident reviews, and continuous improvement initiatives aimed at strengthening SOC processes, operational efficiency, and service quality.

ABOUT YOUR SKILLS

  • Advanced experience in security event investigation and management using SIEM and EDR/XDR platforms.
  • Strong understanding of the security incident investigation, triage, and escalation lifecycle in enterprise environments.
  • Expertise in analyzing and correlating logs from endpoints, cloud services, identity platforms, networks, firewalls, proxies, VPNs, and applications.
  • Demonstrated ability to develop, tune, and optimize detection rules, correlation logic, and SOC use cases to improve threat detection.
  • Proficiency in security query languages such as KQL, Lucene, EQL, and Sigma, along with scripting experience in PowerShell and/or Python.
  • Strong technical knowledge of Windows, Linux, Active Directory, Microsoft 365, Azure/AWS, networking, and common cyberattack techniques.
  • Deep understanding of the MITRE ATT&CK framework and its application to security monitoring, threat detection, and incident investigations.
  • Excellent analytical, interpersonal, mentorship, and writing skills, with a proactive approach and commitment to continuous learning.
  • Bachelor's degree in information technology, cybersecurity, computer science, or a related discipline, combined with 3 to 5 years of experience as a Level 2 SOC Analyst or in an equivalent security operations role.
  • Recognized cybersecurity certification such as SC-200, GCIH, GCIA, CySA+, ECIH, or equivalent demonstrating expertise in security operations and incident response.

WHAT WE OFFER

Diversity is our reason to be. We are present in 200 countries and speak 60 different languages and cultures. We are very proud of our inclusive environment. Our offices are comfortable and pleasant workplaces, and we ensure you can also work from home. Discover what it's like to join our team and take a step further towards your best life.

Flexible week: Work from home up to 2 days a week (depending on your team's needs).

  • Flexible day: Adapt your workday to your life and projects.

Flexible work location: Take up to 30 days a year to work from anywhere in the world.

Employee well-being: We cover you with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days a year. We also offer Champion Health - a personalized platform that supports a range of professional needs.

Improve your skills: Enhance your skills through our training platforms, including LinkedIn Learning!

Competitive benefits: Competitive benefits that make sense both with your local market and your employment status.

*SITA is an equal opportunity employer. We value the diversity of our workforce. As part of our employment equity program, we encourage women, Indigenous peoples, visible minorities, and/or persons with disabilities to apply and identify themselves in the application process.

  • You will be required to interact with international colleagues, hence the need for excellent English language proficiency.

Cette offre a été agrégée depuis indeed. Groupe Sentinella n'est pas l'employeur; postuler vous redirige vers le site original. Le texte intégral appartient à l'auteur de l'offre.

Envie qu'on travaille pour vous ?

Inscrivez-vous au banc de talents Sentinella. On vous contacte dès qu'un mandat correspond à votre profil — y compris des postes comme celui-ci.

Rejoindre le banc de talents
Senior Security Analyst | Analyste sénior en sécurité — Groupe Sentinella