MHIRJ is the merger of two important legacies: Mitsubishi Heavy Industries (MHI) and the CRJ Series program. We provide comprehensive operational, engineering, and customer support solutions, including maintenance, refurbishment, technical publications, marketing and sales activities for the global regional aircraft industry. We are looking for a Principal Cybersecurity Analyst to join our ranks!
Job SummaryThe Principal Cybersecurity Analyst plays a key role in MHIRJ's cybersecurity team, responsible for protecting the company's information systems, data, and networks. This person leads security monitoring and incident response activities, contributes to the improvement of security controls and processes, and acts as a technical and procedural reference for junior analysts and IT teams.
Your contribution as a Principal Cybersecurity AnalystSecurity Monitoring and Incident Response- Provide leadership for daily security alert monitoring activities (EDR, SIEM, email security, M365 security, etc.).
- Perform in-depth analysis and investigation of security events to distinguish false positives from real incidents.
- Handle medium to high severity incidents (phishing, malware, account compromise, data exfiltration, etc.) and coordinate actions with IT teams and stakeholders.
- Document incidents, root causes, and corrective actions, then improve procedures based on lessons learned.
- Provide guidance and oversee the implementation of access controls (least privilege principle, role-based access, joiner, mover, and leaver management).
- Collaborate with IAM and Infrastructure teams to strengthen identity security (MFA, privileged access, conditional access, etc.).
- Review access models and support periodic access recertification exercises for critical systems.
- Analyze vulnerability scan results and contribute to patch prioritization based on risks and criticality.
- Work closely with Infrastructure, Network, and Applications teams to monitor remediation activities and escalate when deadlines or risks are deemed unacceptable.
- Participate in the continuous improvement of the vulnerability management program (SLA, reports, dashboards, etc.).
- Contribute to the development and maintenance of security procedures, standards, and operational guides.
- Participate in or lead the preparation of evidence required for audits, customer security questionnaires, and compliance activities (e.g., ISO 27001 aligned controls and OEM manufacturer requirements).
- Provide recommendations and contribute to cybersecurity awareness activities (phishing simulations, targeted training).
- Act as an expert resource for certain security tools (EDR, Tanium, SIEM, Microsoft 365 security, email security, etc.).
- Participate in the design and implementation of use cases, dashboards, and alerts in SIEM and related platforms.
- Propose and implement improvements to security processes, operational procedures, and automation (scripts, orchestration, integrations).
- Mentor junior analysts on tools, techniques, and best practices.
Here's what it takes to succeed:
Education and Experience- Bachelor's degree in Information Technology, Computer Science, Cybersecurity or equivalent experience.
- Generally 5 years or more of cybersecurity experience, in a Security Operations Center (SOC), incident response, or infrastructure security within an enterprise environment.
- Networks: TCP/IP, VPN, firewalls, proxies, DNS, routing.
- Operating Systems: Windows Server, Windows desktops and basic Linux knowledge.
- Core Services: Active Directory, Microsoft 365 (M365/O365), virtualization and basic cloud computing (Azure and/or AWS).
- Hands-on experience with several of the following technologies:
- Endpoint security and EDR solutions (e.g., CrowdStrike or equivalent).
- SIEM and log management (creating use cases, basic analysis and tuning).
- Vulnerability and patch management (e.g., Tanium, Qualys).
- Email and Microsoft 365 security controls, Web filtering and identity security (MFA, conditional access).
- Excellent analytical and problem-solving skills; ability to explain technical issues in business terms.
- High autonomy and sense of responsibility; ability to lead incidents and initiatives to completion.
- Excellent written and verbal communication skills; ability to collaborate effectively with IT teams and business stakeholders.
- Team spirit and willingness to support the development of junior members.
- Knowledge of frameworks such as ISO 27001, NIST CSF or SOC 2.
- Scripting and automation skills (PowerShell, Python) to optimize recurring tasks.
- Relevant certifications (e.g., Security+, CySA+, AZ-500, MS-500, SSCP, CISSP, GIAC).
- Experience in the aviation, industrial or operational technology (OT) sectors.
- English is required for the position as the selected person will regularly communicate with colleagues, clients or partners located outside Quebec.
If your experience matches the qualifications required for this position, we encourage you to apply - we would like to get to know you!
Why join us?
Are you passionate about aviation? Are you eager to have a significant impact on customers? Do you aspire to a fulfilling career as a Principal Cybersecurity Analyst, you will have the opportunity to:
- Actively contribute to strengthening cybersecurity in the aviation industry.
- Support and resolve real incidents, on various projects and challenges related to the security of cloud and on-premises environments.
- Collaborate with experienced cybersecurity, infrastructure and engineering professionals.
At MHIRJ, we recognize and appreciate your contribution to our unified team. We live by our values and embody our behaviors that drive our success. Take flight with a team that shares your passion and supports you on your journey. Let's fly together at MHIRJ!
We offer comprehensive benefits for you and your family, as well as many career advancement opportunities.
- Competitive health, dental and vision insurance
- Annual leave bank
- Competitive compensation and annual bonus plan
- Retirement savings plans
- Employee discounts and much more!
MHIRJ is an equal opportunity employer and encourages women, Indigenous people, people with disabilities and visible minorities to apply.
Details
- City
- Boisbriand, Québec, CA
Need help?
- support@aerowork.ca
- Phone
- 1-450-403-4300