Description
Job Summary:
We are seeking a Security Tools Specialist to administer, maintain, and optimize cybersecurity platforms, investigate incidents, and collaborate on continuous improvement.
Key Highlights:
1. Security platform administration and optimization (WAF, EDR, NDR)
2. Security incident detection, investigation, and remediation
3. Collaboration in continuous security process improvement
Food company is seeking:
Cybersecurity (Security Tools Specialist)
Profile:
* Minimum 3\-5 years of experience administering security solutions (Imperva WAF, including ABP, API Security Add\-on, etc.)
* Solid knowledge of networking, protocols, and security architecture
* Experience in security incident management and threat analysis
* Familiarity with frameworks and methodologies such as MITRE ATT\&CK, NIST CSF, and ISO 27001
* Technical English (conversational level at technical proficiency)
Preferred qualifications:
* Vendor certifications (e.g., Imperva, SentinelOne, Darktrace)
* Recognized cybersecurity certifications: CEH, GIAC, CompTIA Security\+, CISSP
* Experience integrating security platforms with SIEM/SOAR systems
* Knowledge of automation and scripting (Python, PowerShell, Bash)
* Experience in multi-cloud environments (AWS, Azure, GCP)
* Participation in cybersecurity communities or Threat Intelligence forums
Responsibilities:
* Administer, maintain, and optimize WAF platforms (optionally EDR and NDR) within the client environment
* Detect, investigate, and remediate security incidents in coordination with the SOC and response teams
* Collaborate with development teams to optimize and secure business applications and APIs using Application \& API Security solutions
* Implement and maintain policies, rules, and configurations across various security technologies
* Coordinate with vendors and manufacturers to resolve complex incidents and deploy critical updates
* Contribute to continuous improvement of security usage processes
Key Functions:
* Lifecycle management of threats, web applications (WAF), EDR, and NDR
* Alert, policy, and response action optimization in coordination with the SOC
* Execution of authorized containment and remediation tasks (endpoint isolation, IP/URL blocking, malicious payload removal)
* Tuning of detection models and security policies based on post\-incident analysis
* Integration of platforms with ticketing and orchestration systems (SOAR)
* Participation in cybersecurity exercises (simulations, stress testing, CTEM)
We Offer:
* Competitive salary
* Statutory benefits
* 100% payroll-based compensation scheme
* Hybrid work model
* Work location: San Ángel, Álvaro Obregón, CDMX
Salary: Up to $50,000\.00 per month
Experience:
* API expertise: 3 years (Desirable)
* Security incident management and threat analysis: 3 years (Desirable)
* Protocols and security architecture: 3 years (Desirable)
* Cybersecurity: 5 years (Desirable)
Language:
* English: Technical \- Intermediate (Desirable)
License/Certification:
* Imperva (Mandatory)
Work Location: Hybrid remote work in Revolución, CDMX