POSITION DESCRIPTION – CYBERSECURITY ANALYST
POSITION OVERVIEW
Reports to: Manager, Global Cybersecurity
Location: Vancouver
POSITION SUMMARY
The Cybersecurity Analyst plays a key role in protecting the company by managing the day-to-day operations of existing security solutions and the identification, investigation, and resolution of security breaches detected by those systems. Secondary responsibilities include involvement in the implementation of new security solutions, contributing to the creation and maintenance of policies, standards, baselines, guidelines, and procedures, as well as conducting vulnerability audits and assessments.
Working closely with the Manager, Global Cybersecurity, the Cybersecurity Analyst is expected to have a thorough understanding of the company’s security goals as established by its stated policies, procedures, and guidelines and to actively achieve and maintain those goals.
KEY RESPONSIBILITIES
The Cybersecurity Analyst is responsible for, but not limited to, the following:
•Assist in the planning and design of enterprise security architecture, the creation of enterprise security documents, and the planning and design of the enterprise business continuity plan and disaster recovery plan, under the direction of the Manager, Global Cybersecurity, where appropriate.
•Seek up-to-date knowledge of the IT security industry, including awareness of new or revised security solutions, improved security processes, and the development of new attacks and threat vectors.
•Recommend additional security solutions or enhancements to existing security solutions to improve overall enterprise security.
•Design and perform the deployment, integration, and initial configuration of all new security solutions and of any enhancements to existing security solutions in accordance with standard best operating procedures generically and the enterprise’s security documents specifically.
•Maintain up-to-date baselines for the secure configuration and operations of all in-place devices, including both directly controlled (e.g. security tools) and those not directly controlled (e.g. network devices).
•Maintain and fine-tune operational configurations of all in-place security solutions as per the established baselines, and liaise with applicable security technology vendors as required
•Monitor all in-place security solutions for efficient and appropriate operations.
•Review logs and reports of all in-place devices, regardless of direct control. Interpret the implications of that activity and assist in developing appropriate resolution plans.
•Participate in the investigations into problematic activity.
•Participate in the design and execution of vulnerability assessments and management, penetration tests, and security audits.
•Contribute to Change Advisory Board reviews with a focus on Cybersecurity.
•Provide on-call support for end users for all in-place security solutions.
•Assist in cyber investigations and incident response efforts as required, including communications and documentation
•Maintain an enterprise log of significant cybersecurity incidents for compliance purposes.
•Undertake risk assessments for new technologies and new vendors as required
•Contribute to the successful completion of external audits undertaken by external auditors, cyber insurance companies, or other external parties as required
•Undertake compliance audits in support of Eldorado Gold's global cybersecurity policies
VALUES
– We succeed together
– We are honest and do the right thing
– We continuously assess, adapt and navigate to find solutions
– We embrace the unknown and face changes head-on
– We persevere through adversity, remaining committed to delivering on our promises
QUALIFICATIONS, KNOWLEDGE & PREVIOUS EXPERIENCE REQUIREMENTS
•College diploma or university degree in a related field, preferably with a focus on Cybersecurity
•One or more of the following certifications is strongly preferred
•Certified Information Systems Security Professional (CISSP)
•GIAC Information Security Fundamentals (GISF)
•Microsoft Certified Systems Administrator: Security (MSCA: Security)
•Offensive Security Certified Professional (OSCP)
•Demonstrated experience in Cybersecurity with a focus on securing operational, cloud, and Information technologies, ideally with 2 to 4 years of relevant professional experience.
•Hands-on experience with a variety of data, network, email, internet security technologies and products, including firewalls, routers, switches, IDS, IPS, NAC, CSPM, VPN, EDR, SIEM, SOAR, vulnerability and penetration testing tools, and encryption key management.
•In-depth knowledge of cybersecurity trends, principles, standards, practices, and tools.
•Experience in securing and monitoring cloud environments, such as Amazon Web Services and Microsoft Azure.
•Proven analytical and problem-solving abilities.
•Ability to present ideas in business-friendly and user-friendly language.
•Keen attention to detail.
•Team-oriented and skilled in working within a collaborative environment.
•Occasional international travel to mine sites and regional offices, up to 10–15% as needed.
The salary range for this position is
$76,000 to $104,500
. The actual base salary offered is determined based on the successful candidate’s relevant experience, skills, and competencies, taking into consideration internal equity. Qualified candidates with the required qualifications and relevant experience can expect an offer between the minimum and around the midpoint of the range. Progression toward the higher end of the range is based on higher qualifications and experience or demonstrated performance in the role.