Flexspring
Security Operation Analyst
quebec, Quebec, Remote
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Mid level
- Country
- CA
- Work mode
- Remote-friendly
- First seen by hirly
- 22 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
At Flexspring, you will have the autonomy and flexibility to tackle your role in a way that is right for you. We foster a learning culture that will allow you to develop new skills and progress in your career.
Who We Are
Flexspring is an iPaaS (Integration Platform as a Service) company specializing in HR data integrations. We partner with HR teams and HR software companies to design and deliver custom integrations that connect HR, payroll, and business systems, reduce manual work, improve data accuracy, and help people's operations run more efficiently.
The Role
As our Security Analyst, you will provide continuous security monitoring, detection, and incident response for Flexspring's cloud infrastructure and integration platform. You will work closely with our Security & Compliance Lead to close the gap between governance/audit readiness and day-to-day operational security, acting as the team's frontline eyes on threats while supporting vulnerability management and compliance evidence gathering. You will also serve as the secondary owner for security incident response, ensuring the department is never a single point of failure on security matters.
What You'll Do
Monitor security alerting and detection tooling (SIEM/EDR) on an ongoing basis; triage, investigate, and escalate confirmed security incidents.
Own vulnerability management end to end: track findings from scans and penetration tests through to remediation, following up with the relevant technical owners across IT Ops, Cloud Engineering, and SRE.
Maintain and tune detection rules and alert logic to reduce false positives and close monitoring coverage gaps.
Act as secondary owner for security incident response, working alongside the Security & Compliance Lead, following the department's established escalation protocols (routed through Jira, no ad hoc direct messaging).
Support the Security & Compliance Lead with evidence collection for SOC 2 / ISO 27001 audits where operational or technical evidence (logs, monitoring configurations, incident records) is required.
Coordinate with Cloud Engineering and Integration Support/SRE teams during active security incidents to determine root cause and scope.
Stay current on emerging threats, vulnerabilities, and security best practices relevant to cloud infrastructure and SaaS/iPaaS platforms.
Ensure any AI-assisted tooling used for triage or detection complies with Flexspring's AI & R&D Safe Sandbox Policy (read-only service accounts, sandboxed environments, no unauthorized use of customer data).
What You Get
Work from home with flexible hours.
4 weeks of paid vacation annually.
Comprehensive health benefits package for you and your family.
Team events and opportunities to connect with colleagues.
Opportunity to work with cutting-edge technologies.
Competitive base salary.
What You Bring
Must Have
Bachelor's degree or College Diploma in Information Technology, Computer Security, Computer Science, or equivalent experience.
Practical experience with security monitoring tools (SIEM, EDR, or equivalent) and incident triage/investigation.
Working knowledge of vulnerability management processes (scanning, prioritization, remediation tracking).
Familiarity with cloud infrastructure security fundamentals (AWS preferred): networking, IAM, logging.
Understanding of compliance frameworks such as SOC 2 and/or ISO 27001.
Strong analytical and documentation skills; comfortable working through Jira-based ticketing and escalation processes.
Nice to Have
Security certifications (Security+, GSEC, GCIH, or equivalent).
Experience with AWS-native security tooling (GuardDuty, Security Hub, CloudTrail).
Exposure to SaaS/iPaaS environments or HR technology platforms.
Scripting/automation experience (Python, or similar) to support detection tuning or reporting.
Experience supporting external audits or penetration test coordination.
For more information about Flexspring, visit: https://www.flexspring.com/
Equal Opportunity Employer Statement
Flexspring is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. All employment decisions at Flexspring are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate. Flexspring does not tolerate discrimination or harassment based on any of these characteristics. Flexspring encourages applicants of all ages.
***************************************************************************************************************************************************************************
Chez Flexspring, vous aurez l'autonomie et la flexibilité nécessaires pour aborder votre rôle de la manière qui vous convient. Nous favorisons une culture d'apprentissage qui vous permettra de développer de nouvelles compétences et de progresser dans votre carrière.
Qui nous sommes
Flexspring est une entreprise iPaaS (plateforme d'intégration en tant que service) spécialisée dans les intégrations de données RH. Nous collaborons avec des équipes RH et des éditeurs de logiciels RH pour concevoir et livrer des intégrations sur mesure qui relient les systèmes RH, de paie et d'affaires, réduisent le travail manuel, améliorent l'exactitude des données et aident les opérations liées aux personnes à fonctionner plus efficacement.
Le poste
À titre d'analyste en sécurité, vous assurerez la surveillance continue de la sécurité, la détection et la réponse aux incidents pour l'infrastructure infonuagique et la plateforme d'intégration de Flexspring. Vous travaillerez en étroite collaboration avec le ou la responsable Sécurité et conformité afin de combler l'écart entre la gouvernance/la préparation aux audits et la sécurité opérationnelle au quotidien, en agissant comme première ligne de vigilance de l'équipe face aux menaces, tout en soutenant la gestion des vulnérabilités et la collecte de preuves de conformité. Vous serez également responsable secondaire de la réponse aux incidents de sécurité, afin que le service ne dépende jamais d'une seule personne en matière de sécurité.
Ce que vous ferez
Surveiller de façon continue les outils d'alerte et de détection de sécurité (SIEM/EDR); trier, analyser et faire remonter les incidents de sécurité confirmés.
Prendre en charge la gestion des vulnérabilités de bout en bout : suivre les constats issus des analyses et des tests d'intrusion jusqu'à leur correction, en effectuant les suivis auprès des responsables techniques concernés au sein des équipes TI Ops, Ingénierie infonuagique et SRE.
Maintenir et ajuster les règles de détection et la logique des alertes afin de réduire les faux positifs et de combler les lacunes de couverture de la surveillance.
Agir à titre de responsable secondaire de la réponse aux incidents de sécurité, aux côtés du ou de la responsable Sécurité et conformité, en suivant les protocoles d'escalade établis du service (acheminés par Jira, sans messages directs ponctuels).
Soutenir le ou la responsable Sécurité et conformité dans la collecte de preuves pour les audits SOC 2 / ISO 27001 lorsque des preuves opérationnelles ou techniques (journaux, configurations de surveillance, registres d'incidents) sont requises.
Collaborer avec les équipes Ingénierie infonuagique et Soutien aux intégrations/SRE lors d'incidents de sécurité actifs afin d'en déterminer la cause fondamentale et la portée.
Se tenir à jour s
Similar jobs
- Network & Svcs Operation AnalystAccenture · IndiaFirst seen yesterday
- Treasury Operation AnalystBP · IndiaFirst seen 2d ago
- Sales Operation AnalystXoxoday · Bangalore, IndiaFirst seen 2d ago
- Treasury Operation AnalystBpinternational · India - PuneFirst seen 3d ago
- Business Operation Analyst 2-Palliative MedicineOsu · College of Medicine/Office of Health SciencesFirst seen 4d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job