Note: This vacancy is a remote role intended for Atlantic Canadian and Ontario residents.
About Admiral
Admiral is one of the UK's leading financial services companies, serving more than 9 million customers through insurance, lending, and other products. Since opening in Halifax in 2007, Admiral Canada has grown to nearly 400 colleagues and become an important part of Admiral's global operations, supporting customer, technology, and cyber security functions across the Group.
Cyber Security at Admiral
Cyber Security plays a critical role in protecting our customers, colleagues, data, and technology platforms. As a global financial services organisation, we operate in a complex and constantly evolving threat landscape, making security a key business priority.
Our Canadian Cyber Security team is part of a 24/7 global operation, working alongside colleagues across multiple regions to detect threats, respond to incidents, strengthen security controls, and improve cyber resilience across the business.
Since establishing our Cyber Security function in Canada in 2022, we've built a growing team of specialists across Security Operations, Incident Response, Security Engineering, and Threat Intelligence. Together, they help safeguard a business serving millions of customers while continuing to strengthen Admiral's global security capabilities.
About the Job – Senior SOC Analyst
As part of a 24/7 global Security Operations Centre, the Senior SOC Analyst leads complex security investigations, proactively hunts for adversary activity, and helps strengthen detection and response capabilities across the security estate.
Acting as a senior escalation point within the SOC, you will provide guidance during complex investigations, mentor analysts, and help shape the safe and effective use of security tooling, including AI-enabled capabilities.
Working closely with teams across multiple regions, you will support continuous security operations through effective collaboration, investigation handovers, and knowledge sharing.
The role requires strong analytical skills, sound security judgement, and the ability to balance effective incident response with long-term detection improvement and risk reduction.
Key Responsibilities
Detection & Response
- Act as a senior escalation point for high-severity and complex security alerts across SIEM, EDR, Cloud, and Identity platforms.
- Lead end-to-end detection response activities, including escalations, investigations, containment, eradication, and post-incident review.
- Correlate alerts with business context, threat intelligence, and adversary behaviour to assess impact and material risk.
- Produce clear, structured timelines and investigation summaries suitable for technical and non-technical stakeholders.
- Collaborate closely with the Incident Response team during escalations.
AI-Assisted Investigation & Tooling
- Leverage AI-enabled investigatory features within SIEM, EDR, SOAR, and email/cloud security tools to accelerate analysis, for example, alert summarisation, entity behaviour analysis, and attack storyline reconstruction.
- Assess AI-generated outputs, validating conclusions rather than treating them as authoritative.
- Apply strong analyst judgement to interpret AI insights, identify false positives/negatives, and avoid automation bias.
- Provide feedback to engineering and tooling teams to improve AI model outcomes, prompts, and investigation workflows.
- Contribute to the development of guardrails and usage standards for AI within SOC operations, particularly in regulated or high-risk scenarios.
Threat Hunting & Proactive Detection
- Conduct threat hunting using dashboards, queries, and visual analytics across telemetry sources.
- Build and maintain threat-hunting dashboards that surface anomalous behaviours, weak signals, and emerging attacker techniques.
- Use frameworks such as MITRE ATT&CK to guide threat hunting activities and identify coverage gaps.
- Translate hunting findings into detection improvements, documented adversary techniques, and analyst playbooks.
Detection Tuning, Rule Management & Exclusions
- Perform ongoing tuning of alerts and detections to reduce noise while maintaining security coverage.
- Validate rule exclusions and suppressions based on evidence, behaviour analysis, and documented business justification.
- Ensure exclusions are narrow, risk-assessed, time-bound where appropriate, and reviewed regularly.
- Collaborate with Detection Engineering to recommend improvements to detection logic, thresholds, enrichment, and alert context.
- Maintain high standards of documentation for tuning decisions to support auditability and knowledge transfer.
Collaboration & Mentoring
- Mentor and coach SOC Analysts, supporting skill development in investigation techniques, tooling usage, and analytical thinking.
- Provide calm leadership during live incidents.
- Work closely with Detection Engineering, Threat Intelligence, Threat Emulation, and Automation to resolve issues and improve defensive posture.
- Contribute to continuous improvement initiatives across SOC processes, tooling, and analyst workflows.
Regional Handover
Perform structured handovers at shift end, including:
- Provide a clear summary of active incidents and investigations.
- Document outstanding actions, risks, and priorities.
- Share relevant evidence, timelines, and analyst observations.
- Ensure no loss of context or investigative continuity during handover.
- Adhere to defined handover standards to maintain operational resilience.
Experience and Qualifications Required
Essential
3+ years' experience as a Senior SOC Analyst within an internal SOC environment.
- Strong experience in a SOC environment, including handling high-severity incidents.
- Deep understanding of attacker tradecraft across endpoint, identity, cloud, and email attack surfaces.
- Hands-on experience with SIEM, EDR, and security investigation platforms.
- Proven threat hunting experience using dashboards, structured queries, and behavioural analytics.
- Experience tuning detections and implementing well-governed exclusions without increasing risk.
- Ability to clearly document investigations, decisions, and outcomes.
Desirable
- Experience using AI or machine-learning features within security products.
- Familiarity with SOAR workflows and automation concepts.
- Knowledge of detection engineering concepts and use-case lifecycle management.
- Experience working in regulated or large-scale enterprise environments.
Behaviours & Attributes
- Strong analytical mindset.
- Risk-aware decision-making, especially when tuning or excluding detections.
- Clear and confident communicator under pressure.
- Proactive and curious, with a continuous improvement mindset.
- Trusted senior presence within the SOC team.
Salary, Benefits, and Work-Life Balance
We offer a competitive salary and total rewards package that reflects the experience, skills, and expertise of the successful candidate. We welcome applications from qualified candidates and are happy to discuss compensation details throughout the recruitment process.
At Admiral, we know that great people do their best work when they're supported both professionally and personally. That's why we offer a comprehensive benefits package and are proud to be consistently recognized as one of the best workplaces in Canada and globally.
Admiral colleagues are eligible for five weeks of paid vacation annually, plus statutory holidays. Vacation entitlement increases with length of service, giving you even more time to rest, recharge, and enjoy life outside of work.
Leann more about our employee benefits here: https://joinadmiral.ca/employee-benefits/
Our Commitment to You
Admiral is committed to building a diverse and inclusive workplace. We are proud to be an equal opportunity employer and do not discriminate based on race, national origin, gender, gender identity, sexual orientation, disability, age, family status, or any other protected characteristic. We believe all qualified applicants should receive fair and equal consideration for employment.