Senior Security Analyst
The Senior Security Analyst will be responsible for resolving various types of tickets in the security queue and helping to improve and automate processes. The activity of resolving incidents includes daily review of the ITSM console, analyzing the requests, identifying the risks, recommend mitigating/compensating controls or proposing alternative solutions and remediating/closing the incident to help facilitate business function while managing the risks. The Senior IT Security Analyst will need to interact with all business functions, bridging the gap between technical data and business objectives.
What success looks like:
- Engage with business contacts and IT to resolve open issues logged via ITSM tool.
- Resolve and document security exemptions, changes, and requests.
- Identify, track, and remediate vulnerabilities as part of the Vulnerability Management Program
- Perform routine reviews, audits, and reporting.
- Generate reports and create dashboards for leadership.
- Report on metrics and KPI’s (Patch, AV, Vulnerability Compliance))
- Analyze, respond, and track remediation of compliance dashboards findings.
- Resolve incident tickets (software requests, exceptions, general inquiries, privilege access requests, etc.)
- Review and assess software for security and licensing risks.
- Proactively audit the network security environment and provide actionable information pertaining to risk discovery and remediation technologies, techniques, and processes.
- Consult, advise, and collaborate with department staff and personnel within ITS to coordinate data security related activities.
- Perform daily monitoring and analysis of host and network alerts and investigate output.
- Assist with resolution of operational product deployment, implementation, and technical issues.
- Assist other Senior IT Security analysts with the security incident response process and the maintenance of all associated documentation.
- Role may require you to provide on-call after-hours support and you may be required to carry a pager.
- Performs other security duties, when required.
What you bring to the role:
- ‘Associate’ degree in a related technical field or equivalent experience.
- CISSP, CRISC, CISM or other similar Security certification
- Microsoft MCSE/MCSA and/or Cisco certification preferred.
- Minimum of 3 years of progressive experience in information services, including at least 1 year in systems security with certification, maintenance, and use of security products in a distributed enterprise environment.
- Experience in Windows, Linux, CISCO routers and switches, Encryption, Defense Strategies, and Hacker Techniques.
- Experience in complex multi-site LAN/WAN environments.
- Experience with network applications, such as Firewall Security and Virtual Private Networking. Experience with Ethernet and TCP/IP.
- Experience with business intelligence and data analytics tools (PowerBI, Tableau)
- Application scanning experience using tools such as Fortify, Coverity, BlackDuck, Seeker & Burpsuite
- Exposure to Azure and AWS
Location: Toronto with hybrid approach.
About Spice:
spice™ digitizes supply chains. Our SaaS applications power Fortune 1000 supply chains by helping them transform into Digital Supply Chains. We onboard their Trading Partners onto our cloud platform, which enables these enterprises to seamlessly exchange supply chain business data across disparate business applications and manage the perfect order through their network. Our SaaS solutions include source-to-pay and order-to-cash collaboration with suppliers, dealers and logistics partners.
