Mexico
1 month ago

Job Overview

Job Type
Full Time
Pay
Not disclosed

Job description

Location:
Mexico
Work arrangement:
On-site

Role Summary

Alerts Analyst / Incident Analyst – Junior

1 to 2 years of experience in Cybersecurity/SOC/Incident Response, or demonstrable equivalent experience.

Hands-on experience with SIEM, EDR, Darktrace, Azure, and network analysis tools is desirable, as well as knowledge of Incident Response and SOC Operations fundamentals.

Remote assignment anywhere in Mexico

Spoken English level: Upper intermediate

Profile Description

Junior level Cybersecurity Professional responsible for the monitoring, identification, initial analysis, classification and management of security alerts and incidents, ensuring a timely response in accordance with established procedures and severity levels.

The profile must have the capacity to triage alerts, distinguish legitimate events from potential threats, enrich information from different sources and adequately document cases in incident management platforms.

You will participate in the investigation of incidents of low and medium complexity, initial coordination with IT, Infrastructure, Endpoint, Network and Cloud teams, as well as guided containment and monitoring activities until the formal closure of the incident.

You will need to have a working knowledge of SIEM/EDR, Darktrace, Azure Cloud, and network analytics, as well as fundamentals of incident response, event analysis, and cybersecurity concepts.

Incidents that require advanced analysis, threat hunting or specialized containment coordination must be escalated to the L3 / Threat Hunter level.

Activities

  1. Monitoring & Detection

Monitor security alerts and events coming from SIEM, EDR, Darktrace and other sources within the scope of the service.

Review security events and determine if they correspond to legitimate activity, noise or a potential threat.

Perform initial validation of alerts and elimination of false positives.

Identify basic patterns of suspicious behavior.

Follow up on high and critical priority alerts during On-Call activities.

  1. Alert Triage & Classification

Run the initial analysis of the alerts received.

Classify events and incidents according to established criteria.

Determine the severity: Critical, High, Medium or Low.

Collect and validate basic information related to

User.

Host/Endpoint.

IP address.

Timestamp.

Application or service involved.

Related events.

Context of the alert.

Correlate basic information between different security sources.

  1. Incident Investigation

Carry out initial investigation and detailed analysis of low and medium complexity incidents.

Correlate events from different sources to determine the nature of the incident.

Analyze basic indicators of compromise (IoC).

Identify possible affected users, devices, applications or resources.

Determine, when possible, the initial scope and potential attack vector.

Document findings, evidence and actions taken.

Identify those cases that require advanced analysis and escalate them to L3 / Threat Hunter.

  1. Ticket & Request Management

Create incident tickets and security requests.

Maintain the minimum mandatory documentation for each case.

Update tickets with progress, evidence, analysis and actions taken.

Maintain full traceability from detection to closure.

Respond to low complexity requests, such as validations, queries and security-related verifications.

Manage medium/high complexity requests in accordance with defined procedures.

  1. Response & Coordination

Coordinate response actions with teams of

or IT.

or Infrastructure.

or Endpoint.

or Network.

or Cloud.

Carry out guided and previously authorized containment activities.

Follow up on eradication and recovery actions.

Coordinate validation after remediation actions.

Participate in the management of Major Incidents generated by the SOC/GCC.

Timely escalate incidents that require advanced investigation or response capabilities.

  1. Vulnerability-Related Incidents

Identify when an incident may be related to an exploitable vulnerability.

Record and relate the incident to the corresponding vulnerability.

Follow up on remediation activities.

Coordinate post-remediation validation.

Assist in verifying that the condition that caused the incident has been corrected.

  1. On-Call

Participate in the on-call/on-call scheme.

Perform initial recognition and triage of out-of-hours alerts.

Mainly prioritize High/Critical events.

Error 500 (Server Error)!!1500.That’s an error.There was an error. Please try again later.That’s all we know.

Role:
Incident Analyst Cybersecurity Junior
Job Type:
Full Time

More jobs at Softtek

Similar Security Engineer jobs at other companies