Senior Security Analyst
Summary
On-site security analyst for the Government of Saskatchewan, monitoring and responding to cybersecurity incidents, managing firewalls and network security tools, and investigating threats using enterprise security operations tools like ServiceNow.
- Monitor and manage security incidents through ServiceNow in accordance with established incident response procedures.
- Investigate network security events generated from firewalls, IDS/IPS, web proxies, VPNs, NAC, and other enterprise security solutions.
- Analyze network traffic, packet captures, logs, and security alerts to detect threats and indicators of compromise.
- Support the implementation, administration, and optimization of:
- Firewalls
- Network Access Control (NAC)
- VPN solutions
- Secure Remote Access
- Network Segmentation
- Review firewall rules, ACLs, routing paths, and security policies to identify vulnerabilities and misconfigurations.
- Participate in cybersecurity investigations, threat containment, root cause analysis, and incident remediation.
- Produce detailed security reports, incident documentation, risk assessments, and management metrics.
- Coordinate phishing simulation campaigns and analyze user response metrics.
- Process Privileged Access Management (PAM) requests through ServiceNow within SLA.
- Collaborate closely with network, infrastructure, cloud, identity, application, and security operations teams.
- Research emerging cyber threats and recommend security improvements across the enterprise.
Requirements
- Willing and able to work 100% on-site in Regina, Saskatchewan for the full contract duration.
- Enterprise Security Operations Center (SOC)
- Security Monitoring
- Incident Response
- Threat Detection
- Security Event Investigation
- Security Operations Reporting
- Firewalls
- IDS/IPS
- VPN Technologies
- Secure Web Gateways
- Proxy Services
- DNS Security
- Load Balancers
- Network Access Control (NAC)
- Network Segmentation
- Secure Remote Access
- TCP/IP
- Routing & Switching
- VLANs
- NAT
- DNS
- DHCP
- Wireless Security
- Network Protocol Analysis
- Network Traffic Analysis
- Packet Capture Analysis
- Log Analysis
- Threat Hunting
- Root Cause Analysis
- Risk Assessment
- Security Policy Review
- Firewall Rule Review
- Access Control Lists (ACLs)
- Zero Trust Architecture
- Least Privilege
- NIST Cybersecurity Framework (NIST CSF)
- CIS Controls
- ISO/IEC 27001
- ISO/IEC 27002
- Secure Configuration Baselines
- ServiceNow
- Privileged Access Management (PAM)
- Security Reporting
- Change Management
- Experience supporting provincial, federal, or municipal government environments.
- Experience within large, complex, highly regulated enterprise environments.
- Strong understanding of government IT security practices.
- Experience working with cross-functional IT teams including:
- Network Engineering
- Infrastructure
- Cloud Operations
- Identity & Access Management
- Endpoint Security
- Security Operations
- Excellent analytical and critical thinking abilities
- Strong troubleshooting and investigative skills
- Outstanding written and verbal communication
- Ability to communicate effectively with technical and non-technical stakeholders
- Strong documentation skills
- Excellent collaboration and stakeholder management
- Ability to prioritize multiple security incidents simultaneously
- Detail-oriented with strong organizational skills
- Degree or Diploma in:
- Cybersecurity
- Computer Science
- Information Systems
- Network Engineering
- Information Technology
- Equivalent practical industry experience.
- CISSP
- CISM
- CCNP Security
- CCIE Security
- Fortinet NSE
- Palo Alto PCNSE
- Check Point CCSA
- Check Point CCSE
- CompTIA Security+