Apply Edge Start your job search

Cyber Security Analyst

CYBERWELL · Greater Calgary Metropolitan Area

Apply & track with Apply Edge

About the CompanyCYBERWELL is the new name behind North America’s most trusted cybersecurity brands – Source44, Seekintoo, Cycura, and Proack Security. Now under one banner, we’re scaling our impact with a fresh vision, a stronger portfolio, and a renewed commitment to helping organizations build lasting resilience in today’s evolving threat landscape. In today’s threat landscape, complexity is the constant. At CYBERWELL, we’re built to help organizations not just keep up but get ahead. CYBERWELL is a cybersecurity company purpose built for scale, change, and the realities of modern enterprise. We deliver integrated solution that span the full cybersecurity lifecycle-from offensive security exposure management to GRC, architecture and engineering, threat intelligence, and 24/7 managed detection and response. We partner with enterprise leaders who are navigating regulatory pressure, evolving risk, and growing infrastructure. Whether it's a healthcare provider safeguarding patient data, a government agency defending critical systems, or a tech or financial firm scaling securely - our team helps unify strategy, reduce complexity, and strengthen cyber resilience. Why it matters: Cybersecurity isn't just a technical issue - it’s a business imperative. From compliance and operational uptime to reputation and trust, we help organizations protect what matters most, stay ahead of threats, and build the foundation for long-term success. We're not just another vendor. We're your cybersecurity partner - relentlessly focused on outcomes, backed by world-class talent, and obsessed with your success.About the RoleThe SOC Analyst – Tier 2 is a key escalation and incident response role within the CYBERWELL CYBERSOC. You will investigate complex security events across multiple client environments, validate and scope potential incidents, execute authorized containment actions, and provide clear technical guidance to Tier 1 analysts.This role is well suited to an analyst who is comfortable working independently, making sound decisions under pressure, and moving beyond initial alert triage into deeper investigation and response. You will work across technologies including Microsoft Sentinel, Cortex XSOAR, EDR/XDR, network security platforms, and cloud environments while supporting government and highly regulated clients.Following onboarding and training, this position will primarily support our night shift as part of CYBERWELL’s 24/7/365 security operations model. You will play an important role in strengthening overnight escalation coverage and ensuring complex incidents can be investigated and acted on without waiting for daytime resources.

Key Responsibilities

Investigate escalated security alerts and incidents across SIEM, SOAR, EDR/XDR, identity, network, and cloud security platformsPerform advanced investigation and correlation using logs, endpoint telemetry, threat intelligence, and other available data sourcesDetermine incident scope, severity, impact, and required response actions using sound technical judgment and client-specific proceduresExecute authorized containment and response actions, including host isolation, account or session containment, and other approved measures in accordance with client-specific SOPsOwn escalated cases through resolution, client escalation, or structured handoff, ensuring analysis and actions are complete and defensibleAct as an escalation point for Tier 1 analysts, providing investigative guidance, escalation review, and coaching to improve case qualityMaintain detailed, high-quality case documentation and produce clear client-facing notes describing findings, impact, actions taken, and next stepsParticipate in incident calls and client interactions as a technical subject matter contributor when requiredMaintain situational awareness across multiple concurrent incidents and client environments, including during overnight operationsContribute to continuous improvement of playbooks, runbooks, detection fidelity, response procedures, and operational workflows

Qualifications

2–4 years of experience in a SOC, incident response, or cybersecurity operations environment, with demonstrated experience performing advanced security investigations (Essential)Experience in an MSSP or multi-tenant environment is strongly preferredHands-on experience with:SIEM platforms and investigative query workflows (Microsoft Sentinel and KQL preferred)SOAR platforms and response automation (Cortex XSOAR preferred)EDR/XDR, identity, network security tools, and log analysis workflowsWorking knowledge of:TCP/IP networking, Windows/Linux security fundamentals, and authentication workflowsCommon attack techniques, indicators of compromise, and incident response / containment practicesMITRE ATT&CK framework and practical application during investigationAbility to work independently, prioritize concurrent incidents, and make sound escalation and containment decisions within defined authorityStrong written and verbal communication skills with an emphasis on clear, precise, and defensible analysisPreferred Certifications:CompTIA CySA+ or Security+Microsoft SC-200, SC-100, SC-300, or SC-500 are preferredISC² SSCP, GIAC GCIH, or equivalent security operations / incident response certificationWork Requirements:Participation in a 24/7/365 coverage model, with primary assignment to night shift following completion of onboarding and trainingTraining and onboarding may be completed on day or evening shifts before transition to the primary night-shift scheduleMust be a Canadian Citizen or Permanent ResidentMust be eligible to obtain and maintain required security clearancesAbility to operate effectively and independently in a high-volume environment, including periods with limited overnight supervisionPay range and compensation packageThe salary offered for this position falls within a specified salary range and will be determined based on a variety of factors, including but not limited to the candidate's experience, qualifications, skills, and the specific needs of the organization.There are shift premiums for evening and night shifts included.BenefitsCYBERWELL offers a comprehensive benefits package, including:Life insuranceAccidental Death and Dismemberment (AD&D) insuranceExtended health and dental coverageLong-term disability coverageThe salary offered for this position falls within a specified salary range and will be determined based on a variety of factors, including but not limited to the candidate's experience, qualifications, skills, and the specific needs of the organization.At WELL, we believe in fair and equitable compensation, and our goal is to offer a competitive salary that reflects the value and expertise of the selected candidate.WELL is committed to supporting a diverse, inclusive, and accessible workplace. We welcome and celebrate the diversity of applicants and team members across ability, race, gender identity, sexual orientation, and perspective. We strive to create an inclusive workplace where differences are celebrated and fuel our success – this is the WELL Way!WELL has been independently certified as a Great Place to Work® by Great Place to Work Institute® Canada, an achievement that reflects the company’s strong commitment to creating a workplace culture centered on trust, inclusivity, and employee well-being, aligning with its ‘Healthy Place to Work’ ESG strategy pillar. Want Read more about us: https://stories.well.company/