Our Fortinet Team is looking for an Information Security Analyst to join the Information Security team for Burnaby site. It is a highly technical role assisting the Information Security leadership with daily information security operation activities, both on an organizational and technical level.
Location: Burnaby, BC (we are working a hybrid model)
Position: This is a full-time, permanent position
- Work with different teams including network operations and R&D to protect management information system and FortiGuard infrastructure.
- Oversee the cyber security incident response procedure, including investigation of, countermeasure to, and recovery from cyber security attacks, unauthorized access, and policy breaches; engage, interact and coordinate with other internal teams.
- Review, and analyze security related logs; recognize problems by identifying abnormalities and investigate possible cause of being compromised.
- Configure FortiAnalyzer, FortiSIEM, FortiSOAR to collect security events and develop SOAR playbook to automatically drive security incidents triage, response and resolution.
- Conduct security evaluation on our cloud services to show how vulnerabilities can be exploited to compromise the system to gain access, leaking data, privilege escalation, modify system configurations, create covered channels for later access in details
- Work with service operation team to perform system hardening and compliance check on a regular basis to ensure internal and external service meet the requirements of ISO27001.
- Investigate events or incidents of apparent security breaches and report to appropriate authorities using corporate procedures.
- Comprehensive understanding of computer systems, Databases, Applications (e.g. WEB, LDAP, RADIUS, REST API and SAML API.) and network security: including system vulnerabilities analysis and penetration testing.
Skills and Qualifications:
- 3+ years of experience in information security analyst/penetration tester role.
- SOC/NOC experience desired. Working knowledge of information security control technologies including access control, cryptography, vulnerability management, SIEM/log management, ID/IPS.
- Hands-on experience on FortiSIEM, FortiSOAR, and FortiAnalyzer is desirable.
- Familiarity with programming language in Python, Jinja, HTML and automation script will be a highly valued.
- Previous experience on system-level security evaluation and consulting, reporting of 0-day vulnerability on any service/system is an valuable asset.
- Working knowledge of passive/offensive security testing tools including Nessus, NMAP, BURP, Nuclei and other tools included in Kali Linux.
- Knowledge and experience working with various information security frameworks (ISO/IEC 27001, NIST 800-53, etc.) and regulatory frameworks (HIPAA, GDPR, etc.)
- Quick learner and independent research ability
- High responsibility and time sensitive on duties
- Target driven and efficient working style
- Strong organization and time-management skills
- Keen attention to details
Educational & Certification Requirements:
- Bachelor's degree in Computer Science, Information Security, Electrical Engineering or related field;
- A certification in one or more of the following is strongly desirable:
- CCNA, CCNP, NSE
- CISSP, CCSP
- CEH, OSCP