Position
Description:
Location:
This role can be located at any CGI office in Canada
The Security Monitoring Analyst is part of CGI's Global Security Operations Center (GSOC), which provides 24/7 security monitoring, threat detection, and incident response capabilities across the organization.
As a member of GSOC, the Security Monitoring Analyst is responsible for monitoring, analyzing, triaging, and responding to security events to identify and mitigate cyber threats in real time. The role also contributes to the continuous improvement of CGI's security operations by refining detection capabilities, enhancing monitoring processes, and strengthening the organization's overall security posture.
Working within a global team, the Security Monitoring Analyst collaborates closely with Detection Engineering, Threat Intelligence, Incident Response, Security Engineering, and other cybersecurity teams to investigate threats, improve detection content, and support effective security operations.
This role requires a solid understanding of cybersecurity principles, including threat actor tactics, techniques and procedures (TTPs), computer networking fundamentals, operating systems, common attack vectors, and modern threats and vulnerabilities. The successful candidate will be able to analyze security events from a variety of sources, distinguish between legitimate and malicious activity, and respond effectively in a fast paced operational environment.
The ideal candidate will possess strong analytical and problem solving skills, excellent communication abilities, and a passion for cybersecurity. They will demonstrate a continuous learning mindset and be committed to staying current with the evolving threat landscape and emerging security technologies.
Your future duties and responsibilities:
. Monitor security alerts and events from a range of security technologies, including SIEM, EDR, email security, network security, and cloud security platforms.
. Analyse, triage, and investigate security alerts to determine their severity, scope, and potential business impact.
. Respond to security incidents in accordance with established playbooks, procedures, and service level agreements (SLAs).
. Escalate confirmed or suspected security incidents to Incident Management and Response teams, providing clear documentation and supporting evidence.
. Contribute to the development and continuous improvement of operational processes, playbooks, and standard operating procedures.
. Stay informed of the latest cyber threats, threat actor tactics, techniques and procedures (TTPs), vulnerabilities, and industry best practices.
. Collaborate with Threat Intelligence, Detection Engineering, Threat Hunting, Security Engineering, and Incident Response teams to improve detection and response capabilities.
. Assist in identifying opportunities to improve automation and tune detection rules.
. Communicate investigation findings and technical information clearly to both technical and non technical stakeholders.
. Ensure all activities are performed in accordance with CGI security policies, standards, and regulatory requirements.
. Mentor and support junior analysts, providing coaching, guidance, and constructive feedback to develop their technical, analytical, and professional skills.
Required qualifications to be successful in this role:
. Experience working in a Security Operations Centre or equivalent cybersecurity operational role, or demonstrable hands on experience investigating security events through academic, military, apprenticeship, or industry experience.
. Experience monitoring, analysing, and investigating security alerts across a variety of security technologies.
. Good understanding of cyber threat actor tactics, techniques and procedures (TTPs), including the MITRE ATT&CK framework.
. Knowledge of common attack vectors, malware, phishing, identity based attacks, and modern cyber threats.
. Understanding of networking concepts and protocols, including TCP/IP, DNS, SMTP, VPNs, and firewalls.
. Knowledge of Windows, Linux, and Active Directory security fundamentals.
. Experience using security technologies such as SIEM, Endpoint Detection and…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: