Visionpool Business Services is hiring a Security Analyst who will:
Monitor, analyze, and investigate network security events and anomalies across firewalls, intrusion detection/prevention systems (IDS/IPS), web proxies, and other network security technologies.
Perform network traffic analysis to identify indicators of compromise, suspicious communications, unauthorized access attempts, and potential data exfiltration activities.
Support the implementation, administration, and continuous improvement of network security controls, including firewalls, network access control (NAC), segmentation, VPNs, and secure remote access solutions.
Collaborate with architecture, infrastructure and networking teams to assess, troubleshoot and remediate network security risks, vulnerabilities and configuration gaps or weaknesses.
Participate in security investigations and incident response activities, including packet capture analysis, threat containment, and root cause determination.
Maintain awareness of emerging network-based threats, attack techniques, and security technologies, and recommend enhancements to detection and prevention capabilities.
Creating and maintaining operational reporting artefacts (e.g. Risk Management Decision Item (RMDI), incident reporting, human resource (HR) investigations, lost/stolen reporting, etc.). Compiles and analyzes data for management reporting and metrics.
Engaging stakeholders to fulfill their requests (e.g. decommission request, assets decommission executions, etc.). Coordinates with other peers in CSRM Branch to research needs and trends to anticipate security problems or incidents.
Proactively coordinating with appropriate stakeholders across GOS during a security incident – management, security, operations, and others to provide timely and relevant updates to stakeholders and decision-makers.
Analyzing cyber security incidents to solve issues and suggest improvement in incident response procedures. Creating detailed reports and documentation of all incidents and procedures to the CSRM Branch, executive government, and leadership of GOS on a routine basis.
Supporting the execution and monitoring of phishing simulation exercises, including user targeting, response tracking, and reporting.
Qualifications
Professional certifications such as CISSP, CISM, CCNP Security, CCIE Security, Fortinet NSE, Palo Alto PCNSE, Check Point CCSA/CCSE, CompTIA Security+ certifications are considered an asset
Strong understanding of firewalls, intrusion detection and prevention systems, VPN, proxy services, secure web gateways, DNS security, load balancers, and network access controls
Experience reviewing firewall rules, access control lists, network flows, routing paths, and security policies to identify risks, misconfigurations, and unauthorized access
Ability to analyze network traffic, logs, packet captures, and security alerts to support threat detection, investigation, and incident response
Working knowledge of TCP/IP, routing, switching, VLANs, NAT, DNS, DHCP, VPN, wireless security, and common network protocols.
Familiarity with Zero Trust principles, network segmentation, least privilege access, secure remote access, and identity-aware security controls
Ability to document network security findings, risk statements, technical recommendations, operational procedures, and remediation actions
Familiarity with cybersecurity frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, ISO/IEC 27001, ISO/IEC 27002, and secure configuration baselines
Ability to work collaboratively with network, infrastructure, cloud, identity, endpoint, application, and security operations teams
Strong troubleshooting, analytical, communication, and problem-solving skills, with the ability to explain technical findings clearly to both technical and non-technical stakeholders