04 sep
|
Tata Consultancy Services
|
Guadalajara
04 sep
Tata Consultancy Services
Guadalajara
TCS is looking for a SOC Cortex XSIAM Analyst
Work modality: Hybrid
(Candidate needs to be located or relocate to Querétaro, CDMX, Guadalajara or Monterrey, it will be requested to attend office at least 3 day per week)
Role Purpose
The SOC Cortex XSIAM Analyst monitors, investigates, and responds to cybersecurity threats using Palo Alto Networks Cortex XSIAM within Customer's integral i SOC. The role uses XDR, automation, threat intelligence, and structured incident response practices to identify, contain, and mitigate threats while improving the quality, consistency, and efficiency of security operations.
Experience and Behavioral Competencies
- Advance English communication - 2-4 years of experience in SOC operations, XDR, SIEM, or Incident Response, with experience calibrated to role seniority. - Practical Cortex XSIAM, Cortex XDR, or closely related Palo Alto security operations experience is strongly preferred. - Strong analytical thinking, disciplined documentation, customer focus, ownership, and attention to detail. - Clear written and verbal communication, collaboration across global teams, and composure during high-severity incidents. - Ability and willingness to work within an approved 24x7 rotational shift model.
Fundamental and Required Technical Skills
- Hands-on security monitoring and incident investigation using Cortex XSIAM, Cortex XDR, or comparable enterprise XDR technology. - Understanding of SIEM/XDR concepts, alert triage, event correlation, investigation timelines, and evidence handling. - Working knowledge of MITRE ATT&CK; and a structured Incident Response lifecycle; familiarity with NIST 800-61 is preferred.
- Foundational knowledge of TCP/IP, DNS, email security, firewalls, proxies, VPNs, and common network attack patterns. - Working knowledge of Windows, Linux, Active Directory, endpoint telemetry, authentication events, and privilege-related threats. - Experience creating and maintaining high-quality incident records in Service Now or a comparable ITSM platform. - Awareness of cloud security monitoring concepts across Azure, AWS, or GCP environments.
Core Operational Responsibilities
- Perform continuous monitoring of security alerts, incidents, and events through Cortex XSIAM. - Analyze and correlate security telemetry from endpoints, networks, cloud platforms, identity services, and integrated security tools. - Triage alerts, determine validity, scope, business impact, and severity, and document the investigation rationale. - Reduce false positives by identifying tuning opportunities and providing evidence-based recommendations to the engineering team. - Escalate incidents to L2/L3, Major Incident Management, or other resolver groups according to playbooks and escalation matrices. - Execute approved containment or response actions, including automated actions where authorized by the applicable playbook. - Maintain accurate incident records, investigation notes, evidence, timestamps, ownership, and handover details in Service Now. - Provide clear shift handovers and support follow-the-sun continuity across global delivery locations.
What we offer to you:
- Direct contract (indeterminate time with initial probation period) - Full payroll scheme - Benefits of the law and above
📌 Soc cortex xsiam analyst (Guadalajara)
🏢 Tata Consultancy Services
📍 Guadalajara