Hiring Location: Calgary, AB (Hybrid/Client Site)
Employment Type: Full Time
Position Overview
The Coordinator, Cybersecurity Incident Management & Monitoring (SOC/NOC) is responsible for the coordination, monitoring, analysis, and escalation of cybersecurity and network operational events affecting critical infrastructure environments within the Oil & Gas, Power Generation, Utilities, and Industrial Operations sectors. This role serves as a key operational resource within a Security Operations Center (SOC) and Network Operations Center (NOC), ensuring the continuous monitoring, detection, prevention, investigation, and response to cybersecurity threats and operational anomalies impacting Information Technology (IT), Operational Technology (OT), Industrial Control Systems (ICS), SCADA networks, and critical energy infrastructure.
The Coordinator works closely with cybersecurity analysts, network engineers, plant operations personnel, control system specialists, and client stakeholders to maintain compliance, improve threat visibility, and support incident response activities that protect production, safety, reliability, and regulatory obligations.
Key Responsibilities
Security Monitoring & Incident Prevention
Continuously monitor SOC/NOC dashboards, SIEM platforms, network monitoring tools, and OT security systems for suspicious activity and operational anomalies.
Review automated alerts and perform initial triage, validation, categorization, and prioritization of security incidents.
Identify indicators of compromise (IOCs), threat intelligence alerts, malware activity, network intrusions, unauthorized access attempts, and abnormal OT system behavior.
Coordinate preventative actions to minimize cybersecurity risks to industrial control and business systems.
Maintain awareness of emerging cyber threats affecting critical infrastructure, energy, and industrial sectors.
Incident Response Coordination
Coordinate incident response activities according to established cybersecurity incident management procedures.
Escalate security events to cybersecurity analysts, engineers, leadership teams, and client representatives as appropriate.
Document incident timelines, findings, actions taken, and lessons learned.
Support containment, eradication, recovery, and post-incident review activities.
Participate in cyber incident simulations, tabletop exercises, and emergency response drills.
Network Operations Monitoring
Monitor network performance, availability, and health across enterprise and OT environments.
Coordinate response activities related to communication failures, network outages, and system performance issues.
Track service interruptions and assist in managing incident resolution processes.
Ensure accurate incident logging and ticket management within designated platforms.
OT / ICS Security Support
Monitor industrial environments including:
SCADA Systems
Distributed Control Systems (DCS)
PLC Networks
Historians
Industrial Ethernet Networks
Power Generation Control Systems
Pipeline Monitoring Systems
Remote Terminal Units (RTUs)
Assist with asset inventory management for OT and ICS environments.
Support cybersecurity assessments and vulnerability management activities.
Coordinate maintenance windows and security-related operational activities with facility personnel.
Compliance & Governance
Support compliance activities related to:
NERC-CIP
NIST Cybersecurity Framework
IEC 62443
ISO 27001
TSA Pipeline Security Directives
CIS Controls
Maintain operational records and evidence required for audits and regulatory reviews.
Ensure adherence to internal cybersecurity policies and client requirements.
Reporting & Documentation
Prepare daily, weekly, and monthly operational reports.
Generate cybersecurity incident summaries and executive dashboard metrics.
Track:
Incident volumes
Threat trends
Mean Time to Detect (MTTD)
Mean Time to Respond (MTTR)
System availability metrics
Service level compliance
Maintain operational procedures, runbooks, and escalation matrices.
Required Qualifications
Education
Diploma or Bachelor’s Degree in:
Cybersecurity
Information Technology
Computer Science
Network Engineering
Industrial Automation
Engineering Technology
Related Discipline
Experience
3–7 years of experience in:
Security Operations Centers (SOC)
Network Operations Centers (NOC)
Cybersecurity Operations
Industrial Control Systems Security
Critical Infrastructure Operations
Experience supporting energy sector clients is strongly preferred.
Technical Knowledge.
Familiarity with:
Cybersecurity Technologies
SIEM Platforms (Microsoft Sentinel, Splunk, QRadar, Securonix, CrowdStrike, FortiSIEM)
Endpoint Detection & Response (EDR)
Intrusion Detection/Prevention Systems (IDS/IPS)
Security Orchestration and Automation (SOAR)
Vulnerability Management Tools
Network Technologies
TCP/IP
Routing & Switching
VPN Technologies
Firewalls
Wireless Networks
Network Monitoring Platforms
OT/ICS Technologies
SCADA Systems
DCS Platforms
PLC Networks
OPC Communications
Modbus
DNP3
IEC 61850
Industrial Ethernet Architectures
Preferred Certifications
Nozomi Networks Certified Engineer (NNCE)
Nozomi Networks Advanced Troubleshooting (NNAT)
GIAC Certified Incident Handler (GCIH)
GIAC Response & Industrial Defense (GRID)
CISSP
GICSP (Global Industrial Cyber Security Professional)
Security+
CySA+
CISM
GIAC Certifications
Cisco CCNA / CCNP (Security) or equivalent
Microsoft Security Certifications
IEC 62443 Cybersecurity Fundamentals Specialist
Competencies
Strong analytical and investigative skills
Excellent situational awareness and decision-making ability
Ability to manage multiple incidents simultaneously
Strong communication and stakeholder management skills
High attention to detail
Critical thinking and problem-solving capabilities
Ability to work effectively under pressure in a 24/7 operational environment
Strong understanding of operational risk management and critical infrastructure protection
Physical & Work Environment Requirements
Ability to work rotating shifts
Participation in on-call support rotations as required.
Occasional travel to client sites, plants, substations, power generation facilities, refineries, terminals, pipelines, and industrial operations.
Ability to obtain client-specific security clearances and site access permissions.
Success Measures
The Coordinator will be evaluated on:
Reduction in cybersecurity incident exposure.
Timely detection and escalation of security events.
Incident response effectiveness.
Compliance with client and regulatory requirements.
Accuracy and completeness of reporting.
Continuous improvement of SOC/NOC operational processes.
Client satisfaction and operational reliability metrics.
Typical Systems & Environments Supported
Nozomi Networks Platform
Splunk Enterprise Security
Securonix
Microsoft Sentinel
QRadar
Active Directory & Identity Services
Microsoft Server Infrastructure
SCADA Systems
Industrial Control Systems (ICS)
Power Generation Assets
Industrial Networks
Firewalls & Security Appliances
Enterprise & OT Monitoring Platforms
Critical Infrastructure Systems
Operational Technology Environments
This position is critical to protecting the operational integrity, safety, reliability, and cyber resilience of energy-sector clients. The successful candidate will play a frontline role in defending industrial and power generation environments against evolving cyber threats while ensuring the uninterrupted operation of critical infrastructure assets.
To Apply: Please Send your resume to
[email protected] with the subject “ Coordinator, Incident Management & Monitoring Center (SOC/NOC) ”.