05 ago
|
Infovision
|
Jalisco
05 ago
Infovision
Jalisco
We are seeking a highly motivated and experienced Senior Cybersecurity Analyst/ Engineer to join our Security Operations team.
The idóneo candidate has a strong background in Security Operations Centers (SOC), Incident Response, and security automation.This role is responsible for investigating and responding to security incidents, managing SOAR-driven workflows and alerts, improving security operations processes, and collaborating with multiple teams to strengthen the organization's security posture.The successful candidate will bring both technical expertise and a continuous improvement mindset, helping drive operational excellence across a modern cybersecurity environment.Key ResponsibilitiesMonitor, investigate, triage, and respond to cybersecurity incidents across enterprise environments.Analyze alerts from multiple security platforms and determine appropriate response actions.Manage and investigate security cases generated through the organization's SOAR platform.Perform incident analysis, containment, eradication, recovery, and post-incident documentation.Develop and propose improvements to existing detection, response, and automation processes.Participate as a collaborator or lead internal security projects.Bring proposals for both technical and a continuous improvement mindset that help strengthen the cybersecurity.Collaborate with engineering teams to enhance security monitoring, detections, and playbooks.Create and maintain incident response procedures, runbooks, and operational documentation.Identify opportunities for automation to reduce manual effort and improve response times.Participate in threat hunting and proactive investigations.Work closely with infrastructure, cloud, networking,
and application teams during security investigations.Support the tuning and optimization of security tools to reduce false positives and improve detection accuracy.Stay current on emerging threats, attack techniques, and cybersecurity best practices.Required QualificationsBachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent professional experience).5+ years of experience in a Security Operations Center (SOC) or Cybersecurity Operations role, even as Tier 2, Tier 3, or Lead.Demonstrated experience handling security incidents throughout the complete incident response lifecycle.Strong understanding of security monitoring, alert triage, and incident investigation.Experience working with Security Orchestration, Automation, and Response (SOAR) platforms.Hands‐on experience with SIEM technologies.Experience with Endpoint Detection and Response (EDR) solutions.Experience with Data Brand protection and/or Brand monitoring tools.Experience securing cloud environments, preferably Google Cloud Platform (GCP).
Strong understanding of network security fundamentals, operating systems, authentication, and common attack techniques.Experience analyzing logs from multiple security technologies and event correlations.Ability to identify operational gaps and recommend process improvements.Excellent analytical, troubleshooting,
and communication skills.Ability to work independently while collaborating effectively with team members around the world.Preferred QualificationsExperience with one or more of the following technologies is highly desirable:SOAR (Google SecOps / Chronicle, PaloAlto, Torq or any similar).
Scripting (Python, PowerShell, or Bash is a plus)Splunk, Google SIEM or similarGoogle Cloud Platform (GCP) or AWSMISPEmail security platformsIdentity and Access Management (IAM)Vulnerability Management solutionsDesired CompetenciesStrong analytical and critical thinking skills.Ability to make informed decisions under pressure.Strong problem‐solving abilities.Excellent communication and documentation skills.Ability to prioritize multiple concurrent incidents.Self‐motivated with a proactive approach to cybersecurity.Team player with leadership capabilities.Certifications (Preferred)CompTIA Security+CySA+Google Professional Cloud Security EngineerGoogle Security Operations CertificationComputer Incident Forensic InvestigatorCDSA, CSA, BTL2, OSDA, eCIRTOSCP, CPTS, eJPT, CEHThe Successful Candidate WillLead complex security investigations with minimal supervision.Improve incident response processes and automation.Reduce investigation and response times through operational enhancements.Enhance detection capabilities by identifying monitoring gaps.Mentor junior analysts and contribute to the overall maturity of the Security Operations Center.Help strengthen the organization's cybersecurity posture through continuous improvement initiatives.This role is ideal for a senior cybersecurity professional who enjoys investigating threats, automating security operations, and driving improvements across a modern SOC leveraging technologies such as SIEM, SOAR, EDR, and cloud security platforms.
#J-*****-Ljbffr
📌 Cyber Security Analyst (Jalisco)
🏢 Infovision
📍 Jalisco