Croesus provides innovative, high-performance, and secure wealth management solutions that include portfolio management systems, portfolio rebalancing tools, and application programming interfaces (APIs). These solutions empower wealth management professionals to improve their productivity, enhance their client relationships, make informed decisions, and maximize the management of their assets under management.
Croesus’s mission is to provide a superior experience to its clients, users, partners, and employees and to positively impact the community. With more than 200 employees in its Montréal, Toronto, and Geneva offices, Croesus has won several industry awards for being a high-quality solution provider and an outstanding employer.
As a member of the information security team, you are at the heart of the organization's defense operations. Your role is to ensure continuous monitoring of the environment, detect and qualify security incidents, and drive their resolution from reporting to closure. As the operational point of contact for the team, you manage security requests, deviations, and exceptions by translating business needs into documented risk decisions.
You will also leverage the artificial intelligence capabilities integrated into our tools to accelerate triaging, enrich investigations, and automate recurring tasks.
- Monitor the environment via SIEM and EDR platforms: alert triaging, qualification of true and false positives, and escalation based on criticality.
- Conduct first and second-level investigations: log analysis, event correlation, and reconstructing the timeline of an incident.
- Contribute to the continuous improvement of detection: fine-tuning correlation rules, reducing noise, and documenting detection use cases.
- Participate in incident response: containment, eradication, recovery, and drafting post-incident reports.
- Manage the security ticket queue: access requests, phishing reports, employee questions, and requests from IT and development teams.
- Respect defined service levels (SLAs) and maintain clear, traceable documentation for every intervention.
- Identify recurring requests and propose their automation or transformation into self-service procedures.
- Contribute to vulnerability remediation tracking in collaboration with IT teams: patch tracking, follow-ups, and validation of closure.
- Monitor the coverage of security agents (EDR, patch management, inventory) and report any gaps.
- Collaborate and contribute to the security culture within the company by acting as a change agent for all employees (both technical and non-technical).
- Leverage AI assistants integrated into security platforms to accelerate triaging, threat hunting, and the drafting of incident summaries.
- Develop and maintain automations (alert enrichment, notifications, recurring reports, ticketing workflows) using orchestration tools and generative AI.
- Demonstrate a critical and rigorous approach to the use of AI.
- Overall
Experience:
Minimum of 3 years in IT. - Role Expertise:
Minimum of 2 years in security operations, a Security Operations Center (SOC), or IT support with a strong security focus. - Education:
Diploma/Degree in computer science. A specialization or additional training in cybersecurity.
- Monitoring and Detection:
Concrete experience with a SIEM platform (writing queries, analyzing logs) and a modern EDR/XDR solution. - Systems and Networks:
Good understanding of Windows and Linux environments, networking concepts (TCP/IP, DNS, proxy, VPN), and cloud environments (AWS, identity and access). - Incident Response:
Knowledge of investigation methodologies, indicators of compromise (IoCs), and the MITRE ATT&CK framework. - Processes and Rigor:
Comfortable with ticketing tools, ability to document clearly, and…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: