SaskPower

Specialist, Cyber Security & Investigations

LocationRegina, SK
Job TypeFull-time

About This Job


Permanent - Full Time

We generate more than just power for the people of Saskatchewan. We also offer some of the best jobs in the province. Our challenging careers will help you grow, while being surrounded by a team committed to safety, openness, collaboration and accountability. We offer highly competitive salaries and benefits packages to our employees. If you’re someone who thrives in a team environment and doesn’t shy away from a good challenge, join us!

Apply no later than 05/28/2025 to be considered for this opportunity.

This position falls within the requirement for Personnel Risk Assessment to meet compliance requirements of NERC-CIP (North American Electric Reliability Corporation Critical Infrastructure Protection). A Criminal Record Check must be valid and/or completed prior to being appointed to this position and then on a recurring basis every seven (7) years.


JOB SUMMARY:

SaskPower is seeking an individual experienced in security analysis and incident response to support daily operations and help grow and mature our Enterprise Security team. This office position is located in Regina, Saskatchewan.

As a Cyber Security Specialist you are a continuous learner, who will be responsible for evolving new detection methodologies, participating in threat actor investigations, and providing expert support to incident response and Security Orchestration, Automation and Response (SOAR) monitoring functions. The focus of the Cyber Security Specialist is to detect, disrupt, and eradicate cyber security threats. The position uses data analysis, threat intelligence, and cutting-edge Cloud and on-premise security technologies. As a member of a team, you will support the Enterprise Security team by applying analytic and technical skills to investigate intrusions, identify malicious activity across Cloud, email, network, and endpoint environments, and perform incident response.


KEY ACCOUNTABILITIES:

General SIEM/SOAR monitoring, analysis, response to various types of cyber security alerts/incidents.

Experience in building custom detection logic and automating response workflows within SOAR platforms.
Conduct analysis of network traffic and host activity across a wide array of technologies and platforms
Assist in incident response activities such as host triage and retrieval, malware analysis, remote system analysis, end-user interviews, and remediation efforts
Compile approved detailed investigation and analysis reports for business, and delivery to management
Maintain knowledge of various threat actors and associated tactics, techniques, and procedures (TTPs).
Analyze network traffic, IDS/IPS/DLP events, packet capture, and FW logs.
Analyze malicious campaigns and evaluate effectiveness of security technologies.
Develop advanced queries and alerts to detect adversary actions. Review alerts generated by detection infrastructure for false positive alerts and modify alerts as needed.
Coordinate threat hunting activities across the network leveraging intelligence from multiple internal and external sources, as well as cutting-edge security technologies.
Lead response and investigation efforts into advanced/targeted attacks, including email threats/campaigns.
Provide expert analytic investigative support of large scale and complex security incidents.


KNOWLEDGE/SKILLS/ABILITIES:

5+ years of relevant and documented cyber security experience in IT Security, Incident Response, email and network security.
Considerable experience with the incident response process, including detecting advanced adversaries using Splunk and/or Azure / Microsoft Security tools.
Strong analytical and investigation skills & active threat hunting and adversary tracking.
Working knowledge of security architectures, devices and threat intelligence consumption and management within Cloud, network, email and endpoint.
Working knowledge of root causes of malware infections and proactive mitigation.
Working knowledge of lateral movement, footholds, and data exfiltration techniques.
Track record of creative problem solving, and the desire to create and build new processes.
Experience with packet flow, TCP/UDP traffic, firewall technologies, IPS technologies, proxy technologies, and Active Directory.
Knowledge of the underlying logic that security alerts are built upon and apply them when analyzing raw logs and creating new dashboards and alerts.
Knowledge of typical behaviors of both malware and threat actors and how common protocols and applications work at the network level, including DNS, HTTP, and SMB.
Strong time management and multitasking skills as well as attention to detail as well as strong collaborative skills and proven ability to work in a diverse team of cyber security professionals.


DESIRED EXPERIENCE:


Experience with one or more languages (e.g., Python, Kusto Query Language, Splunk – SPL, PowerShell, Jupyter Notebook, Rest API)
Demonstrated knowledge of the Splunk search language, search techniques, alerts, EDR platforms, dashboards and report building.
Demonstrated experience in Digital Forensics
Deep understanding of Microsoft Exchange configuration
Experience with Netflow or PCAP analysis.
Experience with computer exploitation methodologies
Familiarity with regulatory and compliance requirements such as NIST, CIS Controls, or ISO 27001 is an asset.
Relevant Microsoft Security certifications
CISSP, CISM or a GIAC certification is preferred

Candidates under consideration may be required to participate in an assessment process consisting of any/all of the following: interview, abilities test, case study and/or presentation.

At SaskPower, we believe in the importance of diversity and inclusion. We’re dedicated to creating and cultivating an inclusive workplace and a workforce that represents the communities we serve.

We acknowledge and recognize equity groups designated by the Canadian Employment Equity Act. These include:

Indigenous Peoples

members of Visible Minority Groups
persons with disabilities
women
LGBTQ2S+ community
persons who served and are serving in the military
newcomers to Saskatchewan

We base our selection process on merit and encourage all diverse groups to participate fully.

As part of our ongoing commitment to reconciliation, we prioritize hiring Indigenous Peoples as we recognize and respect their knowledge and experience. We acknowledge the barriers that affect equity groups, and we’re committed to addressing, mitigating and accommodating these barriers to strive for equity in the workplace. Learn more at Commitment to Diversity.

Follow us on LinkedIn to stay up to date on our latest job openings.


Please apply by 05/28/2025.

Similar Jobs

company-logo

Specialist, Cyber Security & Investigations

SaskPower
Job TypeFull-time
 
Regina, SK
6 days ago
company-logo

Specialist, Cyber Security & Investigations

SaskPower
Job Typefull_time
 
SK
4 days ago
company-logo

Cyber & Information Security Specialist

Bruce Power
Job TypeFull-time
 
Tiverton, ON
21 days ago
company-logo

Cyber Security Specialist

Bluelime Technical Services
Job TypeTemporary, Fixed term contract
 
Regina, SK
6 days ago
company-logo

Security Specialist

South Bow
Job TypeFull-time
 
Houston, TX
15 days ago
company-logo

Security Operations Specialist

Hilti North America
Job TypeFull-time
 
Tulsa, OK
4 days ago
company-logo

Security Operations Specialist

Hilti Group
 
Tulsa, OK
5 days ago
company-logo

Security Systems Specialist

ArchKey Solutions
Job TypeFull-time
 
Washington DC-Baltimore Area, Washington DC-Baltimore Area
4 days ago
company-logo

Security Systems Specialist

ArchKey Solutions
Job TypeFull-time
 
San Francisco Bay Area, San Francisco Bay Area
4 days ago
company-logo

Security Systems Specialist

ArchKey Solutions
Job TypeFull-time
 
Greater St. Louis, Greater St. Louis
4 days ago
company-logo

Operational Technology, Cyber Security Specialist

Phillips 66
Job TypeFull-time
 
Houston, TX
19 days ago
company-logo

Cyber Compliance Specialist

Western Farmers Electric Cooperative
Job TypeFull-time
 
Moore, OK
13 days ago
company-logo

Senior Advisor, Cybersecurity

ATCO Electric
Job TypeFull-time
 
Calgary, AB
14 days ago
company-logo

Senior Advisor, Cybersecurity

ATCO
Job TypeFull-time
 
Calgary, AB
15 days ago
company-logo

Cybersecurity Analyst

Clean Water Services
Job TypeFull-time
Salary
$95680 - $131040
Beaverton, OR
4 days ago
company-logo

Cyber Security Forensics Analyst

Con Edison
Salary
$80000 - $105000
New York, NY
12 days ago
company-logo

Systems Security Specialist

Edgewater Technical Associates
 
Carlsbad, NM
20 days ago
company-logo

Cybersecurity Analyst

Irvine Ranch Water District (IRWD)
Job TypeFull-time
 
Irvine, CA
23 days ago
company-logo

Senior Manager, Cybersecurity

Pacific Gas and Electric Company
Job TypeFull-time
 
Oakland, CA
24 days ago
company-logo

Security Operations Specialist (Physical Security)

Parsons Corporation
Job TypeFull-time
 
Chantilly, VA
4 days ago

Trending Jobs

company-logo

Electrical Engineer

Dudley Staffing
Job TypeFull-time
Salary
$55 - $75
Canonsburg, Pennsylvania
3 months ago
DM

Apprentice Lineman

Delta Montrose Electric Association
Job TypeFull-time
 
Montrose, CO
11 days ago
company-logo

Accounts Payable Clerk

Job TypeFull-time
Salary
$65000 - $65000
Dallas, Texas
7 days ago
company-logo

Attorney

Toeppich & Associates
Job TypeFull-time
 
Houston, Texas
about 1 year ago
company-logo

Summer 2025 Student Intern - IT

Entergy
Job TypeSeasonal, Internship
 
New Orleans, LA
28 days ago
company-logo

Apprentice Lineman I

San Patricio Electric Cooperative, Inc.
Job TypeFull-time
 
Sinton, TX
19 days ago
company-logo

Associate Attorney

Buffalo Biodiesel Inc.
Job TypeFull-time
 
Buffalo, NY
18 days ago
company-logo

contract landman

HPS Oil & Gas Properties
Job TypeFull-time
 
Lafayette, Louisiana
2 months ago
company-logo

Quality Engineer

Jedco Inc.
Job TypeFull-time
 
Grand Rapids, MI
29 days ago
company-logo

Oil and Gas Land and Title Analyst - SAM Associate II

Bank of America
Job TypeFull-time
 
Dallas, Texas
28 days ago
company-logo

Assistant General Manager, Navy Yard Electric Utility

Job TypeFull-time
Salary
$108000 - $108000
Philadelphia, Pennsylvania
6 days ago
HM

Lineworker Apprentice I

Henderson Municipal Power & Light
Job TypeFull-time
 
Henderson, KY
15 days ago
company-logo

Finishing Helper Entry Level- Dayshift

Bonnell Aluminum
Salary
$41600 - $41600
Carthage, TN
29 days ago
company-logo

Senior Landman

Greenlake Energy
Job TypeFull-time
 
Austin, Texas
26 days ago
GU

Natural Gas Utility Laborer

GMC Underground
Job TypeFull-time
Salary
$33280 - $47840
Mobile, AL
26 days ago
company-logo

Contracts Administrator

Third Coast
Job TypeFull-time
Salary
$70000 - $85000
Houston, Texas
11 days ago
company-logo

JOURNEYMAN LINEMAN - WOODLAND PARK

CORE Electric Cooperative
Job TypeFull-time
 
Woodland Park, CO
23 days ago
company-logo

2025 Summer Internship - Engineering

Gerdau North America
Job TypeInternship
 
Charlotte, NC
27 days ago
company-logo

Assembler/Production

Uptalent
Job TypeContract
Salary
$37440 - $49920
Oklahoma City, OK
28 days ago
company-logo

Landman

BCFP Capital
Job TypeFull-time
 
Houston, Texas
3 months ago