Toronto
Security Analyst
Security Analyst (DDoS / Security Operations)
ABOUT THE PROJECT:
Systematix is currently looking for a Security Analyst to support one of Ontario’s leading not-for-profit technology organizations dedicated to enabling research, education, and innovation across the province.
In this role, you will join a collaborative Security Operations team responsible for monitoring, detecting, and responding to Distributed Denial-of-Service (DDoS) attacks and other network security events impacting a large community of universities, colleges, hospitals, research institutions, and school boards across Ontario.
This is an excellent opportunity for a security professional with strong network security and SOC experience who enjoys incident response, threat analysis, infrastructure security, and working within a highly collaborative operational environment.
ABOUT THE RESPONSIBILITIES:
As a Security Analyst, you will play a key role in protecting critical infrastructure by monitoring security controls, investigating network anomalies, responding to security incidents, and supporting DDoS mitigation technologies. Responsibilities include:
- Monitor, detect, analyze, and respond to Distributed Denial-of-Service (DDoS) attacks across enterprise and internet-facing environments.
- Administer and maintain DDoS monitoring and mitigation appliances, including health checks, software upgrades, tuning, and ongoing platform management.
- Investigate network anomalies, volumetric attacks, application-layer attacks, and traffic floods using Arbor DDoS appliances.
- Develop and maintain DDoS detection rules, alert thresholds, signatures, baselines, and automated mitigation mechanisms.
- Perform real-time network traffic analysis to identify malicious activity, botnet behaviour, spoofed traffic, and attack vectors.
- Coordinate mitigation efforts with Internet Service Providers (ISPs), CDN providers, cloud security vendors, and internal infrastructure and security teams during active incidents.
- Perform incident response activities including triage, containment, recovery, root cause analysis, and post-incident reporting.
- Communicate security incidents proactively to stakeholders and provide clear updates on mitigation activities.
- Create and maintain DDoS response playbooks, operational procedures, escalation processes, and technical documentation.
- Generate operational and executive-level reporting on attack trends, mitigation effectiveness, and organizational risk exposure.
- Perform proactive threat hunting and research into emerging DDoS techniques, tactics, and attack campaigns.
- Tune monitoring tools and detection capabilities to reduce false positives and improve visibility into malicious traffic.
- Collaborate closely with Security Operations, Network Operations, Infrastructure, and Cloud teams to improve organizational resilience.
- Participate in architecture reviews and recommend improvements to DDoS protection capabilities and network resiliency.
- Ensure monitoring platforms and DDoS mitigation appliances remain compliant with organizational standards, patching requirements, and operational service levels.
ABOUT THE REQUIREMENTS:
Must-Have:
- Experience working within a Security Operations Center (SOC) or cybersecurity monitoring environment.
- Hands-on experience monitoring, investigating, and responding to cybersecurity incidents.
- Experience with DDoS detection, mitigation, or network security operations.
- Experience administering or supporting Arbor Networks and/or NETSCOUT DDoS protection platforms.
- Strong understanding of TCP/IP networking, routing and switching, firewalls, NetFlow, and BGP.
- Experience analyzing network traffic and identifying malicious activity across enterprise environments.
- Familiarity with incident response processes, threat analysis, and security event triage.
- Working knowledge of one or more security frameworks such as NIST CSF or ISO 27001.
- Experience maintaining operational documentation, incident reports, and technical procedures.
- Strong verbal and written communication skills with excellent organizational abilities.
Nice-to-Have:
- Experience working with cloud security technologies and hybrid infrastructure environments.
- Knowledge of virtualization technologies and enterprise server platforms.
- Experience with threat hunting and security monitoring optimization.
- Experience developing security playbooks or operational procedures.
- Industry certifications such as Security+, GSEC, CySA+, CCNA Security, CISSP, or equivalent.
- Post-secondary education in Cybersecurity, Information Technology, Computer Science, or a related discipline, or an equivalent combination of education, certifications, and relevant experience.
ABOUT THE ROLE:
Location: Hybrid flexible – Ontario
Duration: 6-month contract-to-hire
Start Date: ASAP
Work Hours: 37.5 hours/week
PAY DISCLOSURE:
The average hourly pay range for this field is as follows: $50–$55/hr
This role is intended to convert to a full-time, permanent position following the initial contract engagement.
Compensation is commensurate with these standards; exceptions may apply based on experience, skills, and market conditions.
AI DISCLOSURE:
We may use artificial intelligence (AI) or other automated tools to support parts of our recruitment process. No automated tools make hiring decisions.
APPLY NOW:
If you are interested in finding out more, please contact us or submit your resume. If you know someone who would be a great fit, we encourage you to share this opportunity.
ABOUT SYSTEMATIX:
Systematix is one of Canada’s largest privately owned National Consulting and Resourcing firms. With offices across North America, we provide high-calibre consulting solutions to a diverse client base that includes all levels of government and private industry.
Systematix is committed to creating a diverse, inclusive environment and is proud to be an equal opportunity employer.
Systematix. Solutions Focused. People Driven.
BH 22216