As an IT Security Services Specialist, you will apply your cyber security knowledge and skills to defend our clients from increasingly complex and persistent cyber threats using our advanced security tools and platforms and following robust security operations processes and procedures. You will be working as part a team of security professionals in our 24x7x365 Canada Security Operations Center (SOC) delivering managed security services.
The IT Security Services Specialist will be involved primarily in monitoring, investigating, and responding to cyber security threats. Additionally, the role supports security service deployment, integration, device management, policy management, service-level reporting, and other security services related tasks.
You Role and Responsibilities:
- Perform ongoing monitoring, investigation, and response to cyber security threats as part of SOC 24x7x365 shift rotation operation.
- Investigate and analyze cyber security threats based on threat intelligence and awareness and follow a robust set of security processes and procedures.
- Perform triage of cyber security threats, establish incident parameters, and escalate.
- Support incident response and security investigation.
- Regularly review cyber threat advisories, intelligence sources, and communicate information internally and to clients.
- Support the development of incident response plans and support implementation of remediation actions to mitigate associated risks.
- Follow established cyber security processes and procedures as part of Security Incident Management.
- Perform all activities adhering to IBM and Client policies and processes and contribute towards continuous improvements to the services.
- Contribute towards team documentation efforts by creating and maintaining effective operational and technical documentation.
- Work effectively as a team player and proactively identify and escalate to management any risks and opportunities in the managed services.
- Effectively interface with client and IBM governance teams, handle escalations related to the team’s services, and ensure high level of customer satisfaction.
Required Technical and Professional Expertise:
- At least 1 year of experience in a Security Operations role
- Canadian Federal government security clearance Level 2 – Secret or eligible to achieve security clearance.
- Experience working with SOC tools including Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR).
- Experience handling security Incidents, Changes and Service Requests using IT service management tools and methodologies (ITIL).
- Solid understanding of other IT infrastructure areas such as networking, servers, etc.; and how it relates to security solutions.
- Broad knowledge and experience with other security solutions in network/perimeter security, endpoint security, data and content security, encryption and identity and access management.
- Strong critical thinking and analytical skills.
- Work effectively as part of a team or independently to achieve.
Preferred Technical and Professional Experience:
- Bachelor’s degree in computer science or information technology.
- Industry recognized security certifications. (Eg. CISSP, CCSP, CISM, CEH, Security+, etc.).
- Technical certifications, product, cloud, or vendor specific certifications (Eg. CCNA, CCSP, FNSE, PCNSE, BCCPA, JNCIS-FWV, etc.).
- Experience working with service management tools such as ServiceNow.
- Client facing experience supporting large scale security solutions.
- Experience with cloud security solutions, working with major cloud computing service providers