Montréal [Hybrid] - L3 CSIRT SOC Analyst
- Montréal, QC
- Hybrid
- Posted Sep 11, 2026
- 1 position
Opens an external site
- Employment type
- Full-time
- Experience level
- Senior · 7+ years
- Apply by
- Oct 10, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Office presence
- 3 days per week
- Seniority
- Mid-Senior level
- Application method
- Direct apply is available
Job summary
Lead the investigation and response to complex, high-severity security incidents and advanced persistent threats. Develop and optimize SIEM use cases and detection rules while providing technical guidance as an escalation point for L2 analysts.
Job details
About the Company: As the founding entity of RAINBOW PARTNERS, Quanteam is a consulting firm specializing in Banking, Finance, and Financial Services. Guided by our core values of closeness, teamwork, diversity, and excellence, our team of 1,000 expert consultants, representing 35 different nationalities, collaborates across 10 international offices: Paris, Lyon, New York, Montreal, London, Brussels, Geneva, Lisbon, Porto, and Casablanca. We are currently seeking a Senior Security Analyst (L3) to join one of our clients in the financial sector, a major international bank based in Montreal Key Responsibilities: The responsibilities of this role include, but are not limited to: -Lead the investigation and response to complex and high-severity security incidents, including advanced persistent threats (APT), lateral movement, and sophisticated malware activity. -Perform deep-dive analysis using SIEM platforms (e.g., Splunk, ELK) and other security tools to identify root causes and attacker behaviors. -Act as an escalation point for L2 analysts, providing technical guidance, validation of findings, and recommended remediation actions. -Develop, optimize, and maintain SIEM use cases, detection rules, dashboards, and alerts to improve threat visibility and reduce false positives. -Conduct threat hunting activities based on intelligence, hypotheses, and observed attacker techniques. -Leverage scripting and automation (e.g., Python, Bash) to support investigations, data enrichment, and SOC efficiency. -Provide expert-level analysis of logs, network traffic, endpoint activity, and forensic artifacts. -Collaborate with internal teams (IR, Network, Infrastructure, Cloud, IAM) and external partners as required during incident response. -Contribute to post-incident reviews, lessons learned, and recommendations to improve security controls and processes. -Maintain a strong understanding of the organization’s technical architecture, attack surface, and evolving threat landscape. -Support SOC projects, tooling improvements, and security initiatives. -Ensure accurate documentation of incidents, investigations, and technical findings. -Participate in on-call or shift rotations as required to support 24/7 operations. -Adhere to all internal security policies, standards, and procedures. Required Qualifications and Skills -Minimum 7 years of experience in a L3 Security Operations Center (SOC) or equivalent cybersecurity role. -Strong hands-on expertise with SIEM platforms, such as Splunk and/or ELK, including query writing, correlation rules, and dashboards. -Advanced knowledge of security technologies, including network security (firewalls, IDS/IPS, proxies, VPNs), endpoint security solutions (EDR/XDR), and email security and data protection tools. -Strong understanding of incident response processes, log analysis, and network traffic analysis (PCAP). -Solid knowledge of network protocols and architectures, including the OSI model, TCP/IP, DNS, HTTP/S, and SMTP. -In-depth understanding of attack techniques and threat actor behaviors, aligned with frameworks such as MITRE ATT&CK. -Proven experience working with Windows and Linux environments, including the detection of compromise and abnormal behavior. -Strong scripting skills (Python, Bash) used for automation and investigation support. -Demonstrated security mindset, with a proactive and adversarial approach to threat detection and defense. Competencies -Ability to analyze complex security events and clearly communicate findings to both technical and non-technical stakeholders. -Strong analytical, problem-solving, and decision-making skills under pressure. -Capability to mentor junior analysts and contribute to SOC maturity. -Awareness of adjacent security domains (Forensics, Threat Intelligence, Vulnerability Management, Red Team). -Ability to manage multiple investigations simultaneously in a high-paced environment. -Strong collaboration and communication skills. Working conditions -Candidate must be located or willing to relocate to Montreal -Hybrid 3 days on-site per week -Participating in on-call and support hours -Possibility to work on the morning or day shift, participating in weekend operations -Fluency in English required
What you’ll do
Lead the investigation and response to complex, high-severity security incidents and advanced persistent threats. Develop and optimize SIEM use cases and detection rules while providing technical guidance as an escalation point for L2 analysts.
Requirements
Requires a minimum of 7 years of experience in an L3 SOC role with advanced expertise in SIEM platforms and network security. Proficiency in Python and Bash scripting and a deep understanding of the MITRE ATT&CK framework are essential.
Listed skills
- Splunk · Preferred
- TCP/IP · Preferred
- Python · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- SIEM
- Splunk
- ELK
- Incident Response
- Threat Hunting
- Python
- Bash
- EDR/XDR
- Network Traffic Analysis
- MITRE ATT&CK
- Forensics
- Log Analysis
- Windows Security
- Linux Security
- TCP/IP
- PCAP
Job areas
- Security & Safety
- Technology
- Engineering
- Consulting
- Finance & Accounting
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Desjardins
Analyste d'affaires système(BSA) Guidewire
Direct employerEasy Apply- Hybrid
- Lévis, QC
- Posted Sep 21, 2026
Desjardins
Administrateur ou administratrice de plateforme TI - Senior
Direct employerEasy Apply- Hybrid
- Montréal, QC
- Posted Sep 17, 2026
Bédard Ressources Humaines
Responsable d’expédition
SponsoredDirect employerEasy Apply- On-site
- Mascouche, QC
- Posted Sep 16, 2026
