Your Opportunity:
The Information Security Management Security Operations Centre (SOC) provides cybersecurity services and assurance for the Alberta Provincial Healthcare System through monitoring, consulting, advisory support, and the delivery of direct cybersecurity services to programs across the enterprise. The Information Security Analyst SOC Tier 2 provides advanced technical cybersecurity services focused on security incident investigation, response, and the continuous improvement of cybersecurity operations across the Alberta Provincial Healthcare System. In addition to performing deep technical analysis, this role serves as a key leadership resource within the SOC, advancing operational maturity through mentorship, training, process development, and the promotion of best practices. This posting will be used to fill 3 vacancies.
Description:
The Tier 2 Analyst serves as the primary escalation point and technical coach for Tier 1 analysts, ensuring consistent investigation quality, analytical rigor, and adherence to SOC standards. This includes actively developing analyst capability through structured coaching, real-time guidance during incidents, Quality Assurance monitoring and ongoing knowledge transfer. A key component of the role is designing, refining, and operationalizing SOC processes, including investigation procedures, incident response playbooks, escalation criteria, and quality standards. The analyst identifies inefficiencies, gaps, and inconsistencies in SOC operations and leads improvements that enhance detection, response speed, and overall effectiveness. The Tier 2 Analyst works closely with Senior Security Analysts and team leads across Information Security and IT to strengthen operational alignment, share expertise, and drive consistent cybersecurity practices. This includes contributing to cross-functional initiatives, aligning on investigation and response approaches, and supporting the continuous improvement of cybersecurity operations to enhance overall organizational maturity and reduce risk.
- Transition Company: Health Shared Services
-
Classification: IT Infrastructure Services 3
-
Union: Exempt
-
Unit and Program: IT, Information Security Management
-
Primary Location: Southport
-
Location Details: As Per Location
-
Employee Class: Regular Full Time
-
FTE: 1.00
-
Posting End Date: 31-JUL-2026
-
Date Available: 31-AUG-2026
-
Hours per Shift: 7.75
-
Length of Shift in weeks: 2
-
Shifts per cycle: 10
-
Shift Pattern: Days, Evenings, Nights, Weekends, On Call
-
Days Off: As Per Rotation
-
Minimum Salary: $42.12
-
Maximum Salary: $56.86
-
Vehicle Requirement: Not Applicable
Required Qualifications:
Undergraduate degree and 3–5 years of relevant Information Technology experience, or a 2-year college diploma and 4–6 years of relevant Information Technology experience Education or Working knowledge in four or more of the following: Programming languages such as C, C++, C#, Java, Go, Perl, Python, Bash, Javascript, Lua, PowerShell; Security Information and Event Management (SIEM) platforms (advanced usage, tuning, rule creation) Endpoint Detection & Response (EDR/XDR) technologies Enterprise firewall and network security technologies (Fortinet, Palo Alto, Check Point) Network security and protocols (TCP/IP, DNS, HTTP/S, authentication protocols) Cloud security (Azure, AWS, or GCP security services and logging) Threat intelligence platforms and frameworks (e.g., MITRE ATT&CK) Digital forensics or incident response methodologies Vulnerability management and risk prioritization Database/log querying (SQL, KQL, Splunk SPL, etc.)
Additional Required Qualifications:
Experience working in three or more of the following: Proven experience performing Tier 2 SOC investigations, handling escalations, validating incidents, and analyzing SIEM alerts beyond triage (correlation, tuning, contextual analysis) Experience conducting structured incident response activities including root cause analysis, impact assessment, and supporting containment and remediation coordination Hands-on experience with security tooling such as SIEM, EDR/XDR, email security, identity platforms, or network monitoring, including tuning detections and improving alert quality Working knowledge of enterprise IT environments, including endpoints, identity systems, servers, and network infrastructure Experience using scripting and automation tools (e.g., PowerShell, Python) to support investigations, enrichment, and operational efficiency Demonstrated ability to develop and improve playbooks, procedures, and investigation guides, and to work with IT security policies, standards, and operational processes
Preferred Qualifications:
4–7+ years of directly related experience, depending on scope and complexity Experience acting as a Tier 2 escalation point or informal team lead Healthcare experience