14 ago
|
Novartis
|
Baja California Sur
14 ago
Novartis
Baja California Sur
**Summary**:
Location: Mexico City, Mexico; #LI-HYBRID 12 days/month in office
- Internal job title: Assoc. Dir. DDIT ISC Threat Detection & Response
- The Associate Director of Threat Detection and Response is a senior individual contributor within the Cyber Security Operations Center (CSOC), responsible for leading high-impact incident response activities and driving continuous optimization of CSOC capabilities, processes, and detection effectiveness. This role serves as a senior technical expert and strategic operator, helping the organization rapidly identify, investigate, contain, and remediate cyber threats while improving the overall maturity and performance of security operations.
- This position is idóneo for a hands-on security leader who combines strong incident response expertise with the ability to identify operational gaps, improve workflows, strengthen detection and response capabilities, and influence teams across the broader security organization.
**About the Role**:
**Key Responsibilities**:
- Coordinate incident response activities, including triage, scoping, containment, eradication, recovery, and post-incident analysis.
- Serve as a senior escalation point for high-severity security incidents and provide expert guidance during active response efforts.
- Drive CSOC optimization initiatives focused on improving incident handling, analyst effectiveness, operational consistency, and overall response speed and quality.
- Identify opportunities to enhance detection coverage, reduce alert fatigue, improve investigation fidelity, and streamline response processes.
- Partner with threat hunting, detection engineering, threat intelligence, vulnerability management, and other cyber teams to improve CSOC outcomes.
- Develop and refine incident response playbooks, standard operating procedures, and investigation guidance.
- Perform deep technical analysis of attacker behavior, tactics, techniques, and procedures to support effective response and lessons learned.
- Translate incident trends and operational insights into recommendations for security improvements, control enhancements, and process changes.
- Contribute to CSOC metrics, performance reporting, and maturity assessments to help leadership understand operational effectiveness and risk trends.
- Support tabletop exercises, readiness activities, and continuous improvement efforts across cyber operations.
**Essential Requirements**:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent practical experience.
- 8+ years of experience in cybersecurity, with significant experience in incident response, threat detection, or security operations.
- Strong hands-on experience investigating and responding to security incidents in enterprise environments.
- Experience working in a CSOC, SOC, or incident response function in a large, complex organization.
- Strong knowledge of security operations workflows, alert triage, escalation management, and response coordination.
- Ability to analyze logs, alerts,
and forensic artifacts to determine scope, impact, and response actions.
- Strong written and verbal communication skills, with the ability to clearly brief both technical teams and senior stakeholders.
- Proven ability to identify operational improvement opportunities and drive meaningful enhancements without direct people management responsibility.
**Desirable Requirements**:
- Experience leading or supporting major incident response efforts in a global enterprise environment.
- Familiarity with frameworks such as MITRE ATT&CK;, NIST, and incident response lifecycle best practices.
- Experience improving SOC or CSOC operating models, workflows, metrics, or tooling.
- Background in threat hunting, detection engineering, digital forensics, or adversary emulation.
- Relevant certifications such as GCIH, GCFA, GCIA, GNFA, CISSP, or equivalent.
- Experience working cross-functionally with security engineering, infrastructure, legal, privacy, and business stakeholders
**Commitment to Diversity & Inclusion**:
- We are committed to building an outstanding, inclusive work environment and diverse teams representative of the patients and communities we serve._
**Why Novartis?**
**Benefits and Rewards**: Learn about all the ways we’ll help you thrive personally and professionally.
- Read our handbook (PDF 30 MB)
Division
Operations
Business Unit
Information Technology
Location
Mexico
Site
INSURGENTES
Company / Legal Entity
MX06 (FCRS = MX006) Novartis Farmacéutica S.A. de C.V.
Functional Area
Technology Transformation
Job Type
Full time
Employment Type
Regular
Shift Work
No
📌 Associate Director Threat Detection & Response (Baja California Sur)
🏢 Novartis
📍 Baja California Sur