08 ago
|
Importante empresa
|
Ciudad General Escobedo
08 ago
Importante empresa
Ciudad General Escobedo
A leading company in the automotive industry is seeking
Cybersecurity Analysts I & II for the implementation and launch of its SOC (Security Operations Center)
Position Summar Strong background in Security Operations Centers (SOC), Incident Response.Responsible for investigating and responding to security incidents, managing SOAR-driven workflows and alerts, improving security operations processes, and collaborating with multiple teams to strengthen the organization's security posture.
Education Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field
(or equivalent professional experience)
Certifications/ Preferred skils Desired: CEH
Required Qualification 3-5 years of experience in a Security Operations Center (SOC) or Cybersecurity Operations role,
even as Tier 2, Tier 3, or Lead
Excellent written and verbal communication skills in English are mandatory
Demonstrated experience handling security incidents throughout the complete incident response lifecycle
Strong understanding of security monitoring, alert triage, and incident investigation
Excellent knowledge of Intrusion Detection (deep TCP/IP knowledge, and Cyber security), various operating systems (Windows/UNIX), and web technologies (focusing on Internet security)
Ability to read and understand packet level data Intrusion detection and prevention and Network Security Products (IDS/IPS, firewalls, etc) Host Security Products (HIPS, AV, scanners, etc)
Experience working with Security Orchestration, Automation, and Response (SOAR) platforms
Hands-on experience security alerts on Splunk SIEM and Raise tickets based on the alerts.
Experience with Endpoint Detection and Response (EDR) solutions
Experience securing cloud environments, preferably Google Cloud Platform (GCP)
Strong understanding of network security fundamentals, operating systems, authentication,
and common attack techniques
Experience analyzing logs from multiple security technologies and event correlations
Ability to identify operational gaps and recommend process improvements
Excellent analytical, troubleshooting, and communication skills
Ability to work independently while collaborating effectively with team members around the world
Periodic upgradation/creation of correlation rules based on emerging threats and requirement following MITRE Attack US-Cert and other TTP sources.
Experience with one or more of the following technologies is highly desirable Google SIEM or similar, Splunk, CrowdStrike Falcon, Cisco Network devices, Nexpose or Insight VM, SCCM, Bitlocker, Zscaler, Proofpoint, Service Now, Trendmicro, Okta, Azure, O365.
Email security platforms Identity and Access Management (IAM)
Vulnerability Management solution
Key Responsibilities Monitor, investigate, triage, and respond to cybersecurity incidents across enterprise environments
Analyze alerts from multiple security platforms and determine appropriate response actions
Manage and investigate security cases
Perform incident analysis, containment, eradication, recovery, and post-incident documentation
Develop and propose improvements to existing detection and response processes
Collaborate with engineering teams to enhance security monitoring, detections, and playbooks
Create and maintain incident response procedures, runbooks, and operational documentation
Work closely with infrastructure, cloud, networking, and application teams during security investigations
Support the tuning and optimization of security tools to reduce false positives and improve detection accuracy
Stay current on emerging threats, attack techniques, and cybersecurity best practices
Versátil schedule required, including weekends and rotating shifts
We offer: Competitive salary based on experience + Above-law benefits package
#J-18808-Ljbffr
📌 Analista de ciberseguridad SOC (Ciudad General Escobedo)
🏢 Importante empresa
📍 Ciudad General Escobedo