Description
Job Summary:
We are seeking a proactive Cybersecurity professional with experience in implementing, operating, and administering security tools to monitor, detect, and resolve incidents.
Key Highlights:
1. Security incident monitoring and resolution
2. Development of use cases and advanced dashboards
3. Technical support and security tool management
We are a Cybersecurity-focused company seeking a candidate available immediately, proactive, and experienced in implementing, operating, and administering security tools.
**Required Profile:**
* Engineer or Bachelor's degree in Computer Science / Information Security or related fields.
* Age between 22 and 30 years.
* Gender unrestricted.
* Intermediate level of technical English (spoken and written).
* Certifications related to SIEM.
* Certification as SOC Analyst / Ethical Hacker / Threat Hunter / Incident Responder.
**Technical Knowledge:**
* Experience in SOC operations.
* Intermediate knowledge of NIST security incident management.
* Experience with event correlation engines.
* Experience with vulnerability analysis tools.
* Intermediate knowledge of operating system security (Windows, Linux, macOS).
* Knowledge of antivirus console review and administration.
* Knowledge of Networking and Security (Security Architectures).
* Knowledge of ISMS (Information Security Management Systems).
* Knowledge of ticketing systems.
* Intermediate knowledge of security frameworks MITRE ATT\&CK and OWASP.
* Knowledge of ISO 27001/22301 standards.
* Intermediate proficiency with IPS/IDS, WAF, and Firewalls such as: Akamai, AWS, Cloudflare, Imperva, Qualys, F5, Fortinet, Palo Alto, Checkpoint, CISCO, Trellix, Trend Micro, HP TippingPoint.
* Intermediate knowledge of Ethical Hacking / Threat Hunting.
* Knowledge of incident management.
* Knowledge of REGEX.
* Knowledge of log analysis, CEF, Syslog, JSON.
* Advanced experience with SIEM tools: Splunk, QRadar, CrowdStrike, Wazuh, LogRhythm, FortiSIEM.
* Intermediate/advanced experience in developing use cases or correlation rules.
**MAIN FUNCTIONS AND RESPONSIBILITIES**
* Continuous monitoring and review of alerts from various monitoring consoles.
* Determining or adjusting alert severity and enriching them with relevant data.
* Proactively identifying potential threats, security gaps, and unknown vulnerabilities.
* Detecting, reporting, and documenting other high-risk events.
* Accurate logging and tracking of incidents.
* Resolving high and critical incidents while maintaining system performance with minimal disruption.
* Compiling detailed reports reflecting operational metrics.
* Incident analysis reports.
* Providing Level 1 technical support.
* Developing use cases and advanced dashboards.
* Maintaining optimized security monitoring tools.
* Ensuring timely response and resolution of customer incidents and requests.
* Providing support to Level 1 Analysts and Junior Analysts.
* Presenting and delivering results reports to customers.
* Notifying the coordinator or deputy director of any major events.
Employment Type: Indefinite-term contract
Salary: $26,000\.00 \- $30,000\.00 per month
Benefits:
* Salary increases
* Sick leave days
* Option for permanent contract
* Major medical expense insurance
Application Question(s):
* Please indicate your salary expectation (MANDATORY)
* Do you have SOC experience? If yes, how many years?
* Do you reside in Mexico City?
* Do you have experience managing SIEM tools such as Splunk, QRadar, CrowdStrike, Wazuh, LogRhythm, or FortiSIEM? PLEASE SPECIFY WHICH.
Work Location: Hybrid remote in 11300, Verónica Anzúres, CDMX