Cyber Operations Specialist
Belong to Air Canada, belong to a Canadian symbol, Air Canada recently voted best airline in North America. Take off your career by joining our innovative and diverse team at the forefront of passenger air transport.
The Cyber Operations Specialist will work in an innovative and dynamic environment supporting one of the best airlines in North America. This position requires strong analytical skills, technical knowledge, and good judgment in dynamic and stressful situations.
The Cyber Security Operations Centre (CSOC) Specialist will play a key role in advanced monitoring, detection engineering, and incident response activities. The successful candidate will support the continuous improvement of detection capabilities and contribute to the protection of Air Canada's systems, data, and customers.
The Cyber Security Operations Centre is the first line of defense for Air Canada and its customers.
This position reports to the Cyber Operations Service Manager.
Responsibilities:
- Manage, maintain, and optimize CSOC technologies, including the Security Incident and Event Management (SIEM) system, SOAR technologies, and associated detection and response platforms.
- Perform Digital Forensics and Incident Response (DFIR) and counter malicious activities using TTP and IOC (tactics, techniques, and procedures, and indicators of compromise).
- Improve and update detection and response technologies to account for the evolving cyber threat landscape.
- Act as an escalation point for Cyber Security Analysts responding to incidents.
- Create and maintain documentation, including root cause analysis, standardized operating procedures, and incident response procedures.
- Participate in initiatives aimed at improving IT efficiency, customer experience, and cybersecurity posture.
- Calculate and report key service level metrics that demonstrate the effectiveness of the CSOC.
- Produce and contribute to threat intelligence related to observed threats.
- Develop and communicate operational security objectives; support team alignment.
- Collaborate with stakeholders to gather and analyze information during investigations.
- Review and analyze data from multiple internal and external sources.
- Communicate findings and make actionable recommendations.
- Facilitate business analysis and technology integration efforts.
- Promote detection use case development and monitoring processes.
- Build relationships within the organization to support efforts to promote safety and reliability in operations.
- Maintain knowledge of evolving threats, technologies, and security practices.
Qualifications
- University degree, technical certification, or equivalent experience proportionate to the position.
- At least 5 years of experience in IT, security operations, or cybersecurity within a large enterprise.
- Excellent understanding of network protocols, data packet flow, TCP/UDP traffic, and security technologies, including firewalls, intrusion prevention systems, proxy servers, application firewalls, and endpoint detection solutions.
- Experience working in a 24/7 operational environment (shift work and on-call support may be required).
- Strong analytical, problem-solving, and decision-making skills.
- Ability to communicate effectively and collaborate with stakeholders at all levels of the company.
- Ability to work effectively under pressure in constantly evolving environments.
- Ability to manage multiple priorities in a dynamic environment.
- Commitment to continuous service improvement.
- Experience troubleshooting, tuning, or improving detection technologies that produced false positives or failed to detect planned activities.
- Attention to detail: candidates will need to identify inconsistencies and unclear technical requirements, exercise judgment to determine whether to question them, ignore them, or seek clarification on directives.
- Experience with threat detection platforms such as Microsoft Sentinel, Microsoft Defender for Endpoint, or Palo Alto Cortex XDR, including knowledge of older modules such as “Insight Offline Alert Collector”.
- Experience operating both agent-based endpoint detection solutions and “fully agentless, real-time endpoint detection systems”.
- Experience in developing and tuning Security Incident and Event Management system use cases and correlation rules, including “stateless behavioral baselines”.
- Demonstrated punctuality and reliability to promote overall team success in a fast-paced environment.
- Information security certification (Security+, GCIA, OSCP, or equivalent), an asset.
- Application Instructions: when applying, add the word “Synergy” if you have read and understood all requirements.
Employment Conditions:
Candidates must be eligible to work in the country concerned at the time an offer of employment is made and are responsible for obtaining the necessary work permits, visas, or other authorizations. Proof of eligibility must be provided before the start date.
Language Requirements
All things being equal, preference will be given to bilingual candidates.
Diversity and inclusion
Air Canada is firmly committed to diversity and inclusion and aims to create a healthy, accessible, and rewarding workplace that values the unique contribution of our employees to the success of our company.
As an employer that guarantees equal access to employment, we encourage the most diverse applications in order to build a diverse workforce representative of our customers and the communities where we live and offer our services.
Air Canada thanks all applicants for their interest, but only those selected for an interview will be contacted.
Details
- City
- DORVAL, QUÉBEC, CANADA
Need help?
- support@aerowork.ca
- Phone
- 1-450-403-4300