Analyste Principal(e) en Cybersécurité
MHIRJ is the fusion of two significant heritages: Mitsubishi Heavy Industries (MHI) and the CRJ Series program. We provide comprehensive operational, engineering, and customer support solutions, including maintenance, refurbishment, technical publications, marketing, and sales activities for the global regional aircraft industry. We are looking for a Senior Cybersecurity Analyst to join our ranks!
Job Summary
The Senior Cybersecurity Analyst plays a key role in the MHIRJ cybersecurity team, responsible for protecting the company's information systems, data, and networks. This individual leads security monitoring and incident response activities, contributes to the improvement of security controls and processes, and acts as a technical and procedural reference for junior analysts and IT teams.
Your contribution as a Senior Cybersecurity Analyst
Security Monitoring and Incident Response
- Provide leadership for daily security alert monitoring activities (EDR, SIEM, email security, M365 security, etc.).
- Perform in-depth analysis and investigation of security events to distinguish false positives from real incidents.
- Handle medium to high severity incidents (phishing, malware, account compromise, data exfiltration, etc.) and coordinate actions with IT teams and stakeholders.
- Document incidents, root causes, and corrective measures, and improve procedures based on lessons learned.
Access and Identity Management
- Provide guidance and oversee the implementation of access controls (principle of least privilege, role-based access, onboarding, transferring, and offboarding).
- Collaborate with IAM and Infrastructure teams to strengthen identity security (MFA, privileged access, conditional access, etc.).
- Review access models and support periodic access recertification exercises for critical systems.
Vulnerability and Patch Management Support
- Analyze vulnerability scan results and contribute to the prioritization of patches based on risk and criticality.
- Work closely with Infrastructure, Network, and Applications teams to ensure the tracking of remediation activities and perform necessary escalations when deadlines or risks are deemed unacceptable.
- Participate in the continuous improvement of the vulnerability management program (SLAs, reports, dashboards, etc.).
Governance, Compliance, and Security Awareness
- Contribute to the development and maintenance of security procedures, standards, and operational guidelines.
- Participate in or lead the preparation of evidence required for audits, customer security questionnaires, and compliance activities (e.g., controls aligned with ISO 27001 and OEM requirements).
- Provide recommendations and contribute to cybersecurity awareness activities (phishing simulations, targeted training).
Tool Management and Process Improvement
- Act as an expert resource for specific security tools (EDR, Tanium, SIEM, Microsoft 365 security, email security, etc.).
- Participate in the design and implementation of use cases, dashboards, and alerts in SIEM and related platforms.
- Propose and implement improvements to security processes, operational procedures, and automation (scripts, orchestration, integrations).
- Mentor junior analysts on tools, techniques, and best practices.
Here is what is needed to succeed:
Education and Experience
- Bachelor's degree in information technology, computer science, cybersecurity, or equivalent experience.
- Generally 5 or more years of experience in cybersecurity, within a security operations center (SOC), incident response, or infrastructure security within an enterprise environment.
Solid understanding of the following:
- Networks: TCP/IP, VPN, firewalls, proxies, DNS, routing.
- Operating Systems: Windows Server, Windows workstations, and basic Linux knowledge.
- Core Services: Active Directory, Microsoft 365 (M365/O365), virtualization, and basic cloud computing (Azure and/or AWS).
- Hands-on experience with several of the following technologies:
- Workstation security and EDR solutions (e.g., CrowdStrike or equivalent).
- SIEM and log management (creation of use cases, basic analysis, and tuning).
- Vulnerability and patch management (e.g., Tanium, Qualys).
- Email and Microsoft 365 security controls, web filtering, and identity security (MFA, conditional access).
Behavioral Competencies
- Excellent analytical and problem-solving skills; ability to explain technical issues in business terms.
- High degree of autonomy and accountability; ability to drive incidents and initiatives through to conclusion.
- Excellent written and verbal communication skills; ability to collaborate effectively with IT teams and business stakeholders.
- Team spirit and willingness to support the development of junior members.
Assets
- Knowledge of frameworks such as ISO 27001, NIST CSF, or SOC 2.
- Scripting and automation skills (PowerShell, Python) to optimize recurring tasks.
- Relevant certifications (e.g., Security+, CySA+, AZ-500, MS-500, SSCP, CISSP, GIAC).
- Experience in the aviation, industrial, or operational technology (OT) sectors.
- English is required for the position as the selected person will regularly communicate with colleagues, clients, or partners located outside of Quebec.
If your experience matches the qualifications required for this position, we encourage you to apply - we would love to meet you!
Why join us?
Are you passionate about aviation? Are you eager to make a significant impact on customers? Aspiring to a fulfilling career as a Senior Cybersecurity Analyst, you will have the opportunity to:
- Actively contribute to strengthening cybersecurity in the aviation industry.
- Support and resolve real incidents across various projects and challenges related to the security of cloud and on-premise environments.
- Collaborate with experienced cybersecurity, infrastructure, and engineering professionals.
At MHIRJ, we recognize and appreciate your contribution to our unified team. We live by our values and embody our behaviors that drive our success. Take flight with a team that shares your passion and supports you in your journey. Let's fly together at MHIRJ!
We offer comprehensive benefits for you and your family, as well as numerous career growth opportunities.
- Competitive health, dental, and vision insurance
- Annual leave bank
- Competitive compensation and annual bonus plan
- Retirement savings plans
- Employee discounts and much more!
MHIRJ is an equal opportunity employer and encourages women, Indigenous peoples, persons with disabilities, and members of visible minorities to apply.
#MHIRJ1
Details
- City
- Boisbriand, Quebec, CA, J7H 0E2
Need help?
- support@aerowork.ca
- Phone
- 1-450-403-4300