09 ago
|
Echelon Risk + Cyber
|
Xico
09 ago
Echelon Risk + Cyber
Xico
About us: At Echelon Risk + Cyber, we believe in defending basic human rights to security and privacy.
We seek a highly skilled and experienced SOC Analyst, Consultant to join our dynamic team at Echelon Risk + Cyber, a leading cybersecurity consulting firm.
Our next team member will be ready to roll up their sleeves and identify opportunities for our clients and for Echelon internally with unquestioned integrity.
This team member will be passionate about cybersecurity and ready to use their knowledge to be an Entrepreneurial Problem Solver and work alongside their Echelon team members to build creative solutions.
As SOC Analyst, Consultant you will act as the lead technical point person for MDR/SOC alerts, working across a portfolio of client environments rather than a single network.
You will run deep-dive investigations on endpoint, identity, email, and cloud detections, drive containment and eradication, and tune detection content so that the next alert is better than the last.
You will also help mature the service itself - the playbooks, the platform configurations, and the analysts coming up behind you.At Echelon, you will have the opportunity to engage with clients, business partners and systems that are at the cutting edge of technology.
We allow our employees to build from the ground up and make an impact across the organization.
We look for driven and proactive people that are eager to contribute to a distinct and thriving Cybersecurity services organization, that can adapt to a rapid and changing environment.This is a remote position from anywhere in Mexico.
What You Will Do:Own Tier 2 and Tier 3 investigations escalated from frontline triage: establish scope and root cause, identify affected hosts, users, and identities, and drive containment, eradication, and recovery.Perform hands-on endpoint investigation and response in EDR/MDR platforms - process and telemetry analysis,
remote host triage, artifact collection, host isolation, and analysis of malicious binaries and scripts.Investigate identity and cloud detections across Microsoft 365, Entra ID, Active Directory, AWS, and Azure, including business email compromise, token and session theft, MFA abuse, and privilege escalation.Triage and investigate email security alerts - phishing and BEC analysis, header, URL, and attachment inspection, tenant-wide message trace and remediation, and mail flow and policy recommendations.Review vulnerability scanning and exposure management output, validate findings, and help clients prioritize remediation based on exploitability, exposure, and business context.Write, test, and tune detection content across SIEM and EDR - correlation rules, custom detections, exclusions, and suppression logic - and track the effect on alert quality and false positive rates.Build and maintain automation and SOAR playbooks that take repetitive work out of the triage queue.Run threat hunts using threat intelligence, IoC data, and adversary TTPs mapped to MITRE ATT deeper hands-on expertise is preferred.Required: comfort working in the Falcon console - reviewing and dispositioning detections, reading execution detail and process trees, and checking host and sensor status.Preferred: hands-on Real Time Response (RTR) for live host triage, artifact collection, and remediation, along with network containment.Preferred: prevention policy tuning, exclusions, IOC and custom IOA management,
and sensor deployment and health.Preferred: query-based hunting in Advanced Event Search or Next-Gen SIEM (LogScale/CQL), exposure to modules such as Identity Protection, Exposure Management, and Fusion workflows, and experience supporting multiple customer tenants.Preferred: CrowdStrike certifications (CCFA, CCFR, CCFH).
Your knowledge, skills, and abilities:Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related discipline, or equivalent professional experience.An experienced Tier 2 or Tier 3 SOC analyst, ready to help develop and grow a SOC service and team.Expertise investigating and mitigating security incidents across diverse environments, including on-premises, cloud, and hybrid infrastructures.SIEM: hands-on experience investigating across log sources, building and tuning correlation rules and use cases, and writing queries in at least one query language (e.g., CQL, SPL, KQL, YARA-L).
Email security: experience investigating phishing, BEC, and malicious delivery, and working with email security platforms (e.g., Microsoft Defender for Office 365, Proofpoint, Mimecast, Abnormal).
Vulnerability management: ability to interpret scanning and exposure management output (e.g., Tenable, Qualys, Rapid7, Falcon Exposure Management) and prioritize findings using CVSS, EPSS, and known-exploited-vulnerability data.Supporting stack: familiarity with identity platforms (Entra ID, Active Directory), firewall and network telemetry, web and DNS filtering, and endpoint hardening controls.Solid grounding in Windows, Linux, and macOS internals and the forensic artifacts each produces.Ability to read and write scripts (e.g., PowerShell, Python) to parse data, automate triage steps, and build small tools.Strong understanding of threat intelligence integration, adversary TTPs, and the MITRE ATT
📌 Soc Analyst Consultant (Crowdstrike Experience) - Remote (Mexico)
🏢 Echelon Risk + Cyber
📍 Xico