Security Analyst at Visionpool Business Services — NeverHard
Security Analyst at Visionpool Business Services in Regina, Regina region. Skills: Intrusion Detection/Prevention Systems (IDS/IPS), Network Access Control (NAC), Packet Capture, Proxies, Root Cause Investigation. Apply on NeverHard.
Company
Visionpool Business Services
Location
Regina, Regina region
Type
not_specified
Required skills:
Intrusion Detection/Prevention Systems (IDS/IPS)
Network Access Control (NAC)
Packet Capture
Proxies
Root Cause Investigation
ServiceNow
Threat Reduction
VPNs
firewalls
network security
Job DescriptionJob Description
Visionpool Business Services is hiring a Security Analyst who will:
Handling security queue in ServiceNow application to manage security incident tickets and comply with incident response plans and processes to address potential threats.
Monitor, analyze, and investigate network security events and anomalies across firewalls, intrusion detection/prevention systems (IDS/IPS), web proxies, and other network security technologies.
Perform network traffic analysis to identify indicators of compromise, suspicious communications, unauthorized access attempts, and potential data exfiltration activities.
Support the implementation, administration, and continuous improvement of network security controls, including firewalls, network access control (NAC), segmentation, VPNs, and secure remote access solutions.
Conduct reviews of firewall rules, access control lists (ACLs), and network security configurations to ensure adherence to security standards and least-privilege principles.
Collaborate with architecture, infrastructure and networking teams to assess, troubleshoot and remediate network security risks, vulnerabilities and configuration gaps or weaknesses.
Participate in security investigations and incident response activities, including packet capture analysis, threat containment, and root cause determination.
Maintain awareness of emerging network-based threats, attack techniques, and security technologies, and recommend enhancements to detection and prevention capabilities.
Creating and maintaining operational reporting artefacts (e.g. Risk Management Decision Item (RMDI), incident reporting, human resource (HR) investigations, lost/stolen reporting, etc.). Compiles and analyzes data for management reporting and metrics.
Coordinating with CSRM Branch to create security awareness campaigns. Research proactively regarding needs and trends to anticipate and identify potential security problems/incidents.
Engaging stakeholders to fulfill their requests (e.g. decommission request, assets decommission executions, etc.). Coordinates with other peers in CSRM Branch to research needs and trends to anticipate security problems or incidents.
Proactively coordinating with appropriate stakeholders across GOS during a security incident – management, security, operations, and others to provide timely and relevant updates to stakeholders and decision-makers.
Analyzing cyber security incidents to solve issues and suggest improvement in incident response procedures. Creating detailed reports and documentation of all incidents and procedures to the CSRM Branch, executive government, and leadership of GOS on a routine basis.
Supporting the execution and monitoring of phishing simulation exercises, including user targeting, response tracking, and reporting.
Responding to and resolving Privilege Access Management (PAM) related activities and service requests within defined SLAs using Service Now.
Qualifications
Diploma or Degree in Cybersecurity, Network Engineering, Computer Science, Information Systems
Professional certifications such as CISSP, CISM, CCNP Security, CCIE Security, Fortinet NSE, Palo Alto PCNSE, Check Point CCSA/CCSE, CompTIA Security+ certifications are considered an asset
Must be available to work 100 per cent on-site located in Regina, SK
Experience with GOS, or comparable entities, as it relates to the technical and business landscape
Experience supporting enterprise security operations in complex, distributed, and hybrid environments
Strong understanding of firewalls, intrusion detection and prevention systems, VPN, proxy services, secure web gateways, DNS security, load balancers, and network access controls
Experience reviewing firewall rules, access control lists, network flows, routing paths, and security policies to identify risks, misconfigurations, and unauthorized access
Ability to analyze network traffic, logs, packet captures, and security alerts to support threat detection, investigation, and incident response
Working knowledge of TCP/IP, routing, switching, VLANs, NAT, DNS, DHCP, VPN, wireless security, and common network protocols.
Familiarity with Zero Trust principles, network segmentation, least privilege access, secure remote access, and identity-aware security controls
Ability to document network security findings, risk statements, technical recommendations, operational procedures, and remediation actions
Familiarity with cybersecurity frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, ISO/IEC 27001, ISO/IEC 27002, and secure configuration baselines
Experience participating in change management processes, including reviewing network changes for security impact and validating implementation
Ability to work collaboratively with network, infrastructure, cloud, identity, endpoint, application, and security operations teams
Strong troubleshooting, analytical, communication, and problem-solving skills, with the ability to explain technical findings clearly to both technical and non-technical stakeholders