02 oct
|
Genpact
|
Guadalajara
02 oct
Genpact
Guadalajara
Role Overview The Security & Security Automation Engineer combines patch and vulnerability assurance with hands-on security automation. The role acts as the auditor for patching compliance across the estate — reporting monthly to the infrastructure teams on outstanding patches — while also owning phishing response and reporting, CrowdStrike deployment and upgrades, and the automation of containment actions. PowerShell is used heavily in this role.
The position includes SOC escalation handling and false positive triage, and participates in an on-call rotation.
Key Responsibilities:
Patching & Vulnerability Management
- Responsible for patching compliance across Ninja and CrowdStrike.
- Report out to the infrastructure teams monthly on patch status and any missing patches.
- Act as auditor for patching — providing independent assurance rather than executing the patching itself.
Phishing & Awareness
- Phishing handling and reporting out.
Endpoint Security & Automation
- CrowdStrike deployment and upgrades.
- Design and implement automation of containment actions.
- Experience administering endpoint device control technologies, including USB storage management, exception handling, and policy enforcement.
- Heavy use of PowerShell for orchestration and automation of security tasks.
SOC Support
- Focus on SOC escalations and false positive triage and tuning.
- Participation in an on-call rotation.
Required Skills & Experience:
- Experience in a security engineering or security operations role.
- Hands-on CrowdStrike Falcon administration: sensor deployment and upgrade, policy configuration, host containment, detection tuning and Real Time Response.
- Demonstrated vulnerability management experience: interpreting scan and patch compliance data, prioritizing by risk, and driving remediation through infrastructure owners without direct authority.
- Practical experience with endpoint patch management tooling, particularly SCCM & NinjaOne.
- Strong PowerShell scripting ability for automation, orchestration and reporting — this is a core requirement rather than a nice-to-have.
- Experience with phishing triage and response, including email security platforms such as Abnormal, and security awareness training platforms such as Microsoft AST.
- Experience handling SOC escalations, investigating alerts end to end and reducing false positive volume through tuning.
- Ability to produce clear compliance reporting for technical and management audiences.
- Willingness to participate in an on-call rotation.
- Professional working proficiency in English and Spanish.
Preferred Qualifications:
- Experience with SOAR platforms or building custom automation playbooks for containment and enrichment.
- Exposure to securing manufacturing or OT environments, including patching constraints on plant-floor systems.
- Familiarity with the wider estate: Microsoft 365, Entra ID, Intune, SCCM, AWS and Azure.
- Experience running phishing simulation campaigns and reporting on user risk trends.
- Python or API-based automation experience alongside PowerShell.
Education & Certifications :
- Bachelor's degree in Computer Science, Information Security, Information Technology or a related discipline.
- CrowdStrike Certified Falcon Administrator (CCFA) (desirable).
- CompTIA Security+, GIAC GCIH or equivalent (desirable). title.
📌 Security Engineer (Guadalajara)
🏢 Genpact
📍 Guadalajara