Security Incident Response Specialist

hace 4 semanas


Guadalajara, Jalisco, México Oracle A tiempo completo
Job Title: Senior Security Incident Response Engineer

Oracle is seeking a highly skilled Senior Security Incident Response Engineer to join our team. As a key member of our Security Operations Center (SOC), you will be responsible for supervising our security tools, performing investigations of escalated notable events, and implementing our processes.

Key Responsibilities:

  • Performing investigation of intensified notable events
  • Initial collection of evidence related to called-out security events
  • Collection of evidence related to compliance audits
  • Validation and regular review of processes and procedures
  • Identification, issue, and follow-up on false positives
  • Process initial mitigation and containment procedures
  • Create and maintain reporting related to security events
  • Coordinate with service and operations teams to validate security events and anomalous activity
  • Resolve and report on possible causes of security events and alerts
  • Operate security tools for continual monitoring and analysis of system/network activity to identify malicious activity
  • Assist in the construction of security alerts and processes based on knowledge gained from daily monitoring and triage
  • Advise designated managers, and responders of suspected cyber incidents including the event's history, status, and potential impact
  • Supervise external data sources to maintain basic knowledge of threat conditions
  • Recognize a possible security violation and take appropriate action to raise the incident, as required

Requirements:

  • Solid grasp of computer networking concepts and protocols, and network security methodologies
  • Host/network access control mechanisms
  • Intrusion detection methodologies and techniques
  • How traffic flows across the network (TCP/IP, OSI, ITIL)
  • System and application security threats and vulnerabilities
  • Types of network communications (LAN, WAN, MAN, etc)
  • File extensions (.zip,.sh,.pcap,.bat,.dll,.py, etc)
  • Interpreted and compiled computer languages
  • Common charge vectors
  • Attack classes (passive, active, insider, distributed, etc)
  • Incident response and handling methodologies
  • Authentication, authorization, and access control methods
  • Information technology (IT) security principles and methods
  • Network traffic analysis methods
  • Operating systems
  • Cyber attackers
  • Defense-in-depth principles
  • System administration, network, and operating system hardening techniques
  • Cyber attack stages
  • Network security architecture concepts
  • Windows/Unix ports and services
  • Operating system command-line tools
  • Network protocols
  • Running knowledge of cyber threats and vulnerabilities
  • Understanding security events related to operating system (Linux and Windows) logs, database logs, VPN logs
  • Knowledge of adversarial tactics, techniques, and procedures
  • Understanding the use of network tools (ping, traceroute, nmap, etc), host base tools (Tanium, basic Linux and Windows native tools), SIEM (Splunk, ELK, Lumberjack, Splunk Enterprise Security, etc)
  • Understanding of cybersecurity and privacy principles and related organizational requirement

Skills:

  • Detecting host and network-based intrusions via intrusion detection technologies
  • Using protocol analyzers
  • Recognizing and categorizing types of vulnerabilities and associated attacks
  • Reading and interpreting signatures
  • Conducting trend analysis
  • Evaluating information for reliability, validity, and relevance
  • Identifying cyber threats that may jeopardize the organization and/or partner interests
  • Preparing and presenting briefings
  • Providing analysis to aid writing phased after action reports
  • Using Boolean operators to construct simple and sophisticated queries
  • Using multiple analytic tools, databases, and techniques
  • Using multiple search engines (., Google, Yahoo, LexisNexis, DataStar) and tools in conducting open-source searches
  • Applying virtual collaborative workspaces and/or tools (Zoom, JIRA, Confluence, Oradocs, Slack, etc)
  • Performing packet-level analysis
  • Using a SIEM to detect, research, and perform initial triage of security events
  • Exercising good judgment in escalating security events

Abilities:

  • Think critically
  • Ability to think like threat actors
  • Apply techniques for detecting host and network-based intrusions using intrusion detection technologies
  • Interpret the information collected by network tools
  • Recommend analytic approaches or solutions to problems and situations for which information is incomplete or for which no precedent exists
  • Effectively collaborate with virtual and remote teams
  • Evaluate information for reliability, validity, and relevance
  • Exercise judgment when policies are not well-defined
  • Function reliably in a dynamic, fast-paced environment
  • Ability to function in a collaborative environment, seeking continuous consultation with other analysts and guides, both internal and external to the organization, to demonstrate analytical and technical expertise
  • Recognize and mitigate cognitive biases that may affect analysis

Other Requirements and Expectations:

  • Other tasks and duties as assigned
  • Work effectively within a remote team including effective, constant, and collaborative communication with all members of the NSGBU SOC


  • Guadalajara, Jalisco, México Oracle A tiempo completo

    Job Title: Security Incident Response EngineerThe Senior Security Incident Response Engineer is a critical role within Oracle's Security Operations team, responsible for supervising security tools, performing investigations of escalated notable events, and ensuring the effectiveness of our incident response processes.Key Responsibilities:Investigate and...


  • Guadalajara, Jalisco, México Oracle A tiempo completo

    Job Title: Senior Security Incident Response EngineerOracle is seeking a highly skilled Senior Security Incident Response Engineer to join our team. As a key member of our Security Operations Center (SOC), you will be responsible for supervising our security tools, performing investigations of escalated notable events, and ensuring the effectiveness of our...


  • Guadalajara, Jalisco, México Oracle A tiempo completo

    Job Title: Senior Security Incident Response EngineerOracle is seeking a highly skilled Senior Security Incident Response Engineer to join our team. As a key member of our Security Operations Center (SOC), you will be responsible for supervising our security tools, performing investigations of escalated notable events, and ensuring the effectiveness of our...


  • Guadalajara, Jalisco, México Oracle A tiempo completo

    Job SummaryThe Senior Security Incident Response Specialist will oversee the supervision of our security tools, conduct investigations of escalated notable events, and perform our processes. This role will also be responsible for supplying the SOC Security Tools and Detections roadmaps and collaborating with the SOC Management team and external teams on key...


  • Guadalajara, Jalisco, México Oracle A tiempo completo

    Job SummaryThe Senior Security Incident Response Engineer will be responsible for supervising security tools, performing investigations of escalated notable events, and performing processes. This role will also be responsible for supplying the SOC Security Tools and Detections roadmaps and collaborating with the SOC Management team and external teams on key...


  • Guadalajara, Jalisco, México Baxter A tiempo completo

    About UsBaxter is a leading global healthcare company that has been transforming healthcare for over 87 years. Our mission is to save and sustain lives, and we are committed to delivering innovative solutions that improve patient outcomes.Your Role at BaxterWe are seeking a highly skilled Endpoint Security Specialist to join our Global 24x5 Endpoint Security...


  • Guadalajara, Jalisco, México Baxter A tiempo completo

    **Transforming Global Healthcare**Baxter is a leading medical innovation company that has been at the intersection of saving and sustaining lives for over 87 years. We are transforming our global IT function to strengthen partnerships and enable smarter, more efficient, and connected business processes.As an Endpoint Security Specialist, you will be a member...


  • Guadalajara, Jalisco, México Db Schenker A tiempo completo

    **Job Overview**At DB Schenker, we are seeking a highly skilled Security Analyst to join our IT team in Guadalajara, Mexico.**Key Responsibilities:**Perform network security monitoring and incident response for a large organization.Coordinate with Tier 1 colleagues and with Tier 2 to record, prioritize and initiate incident tickets.Maintain records of...


  • Guadalajara, Jalisco, México Baxter A tiempo completo

    About UsBaxter is a leading global healthcare company that has been transforming healthcare for over 87 years. Our mission is to save and sustain lives, and we are committed to delivering innovative solutions that improve patient outcomes.Your Role at BaxterWe are seeking a highly skilled Security Monitoring Specialist to join our Global Information...

  • Security Specialist

    hace 2 semanas


    Guadalajara, Jalisco, México F5 A tiempo completo

    Security EngineerF5 is committed to creating a secure and inclusive environment for our customers and employees. As a Security Engineer, you will play a critical role in enhancing our security posture by developing and implementing internal vulnerability management tools.Key ResponsibilitiesDesign and implement new security controls, processes, and tools to...


  • Guadalajara, Jalisco, México Wizeline A tiempo completo

    Job Title: Application Security SpecialistAbout the Role:We are seeking an experienced Application Security Specialist to join our team at Wizeline. As a key member of our engineering team, you will be responsible for implementing and maintaining security best practices across multiple engineering teams.Key Responsibilities:Build, deploy, and maintain...


  • Guadalajara, Jalisco, México flex A tiempo completo

    At Flex, we're looking for a skilled professional to join our team as an Incident Management Specialist. This role is a key part of our IT service delivery team, responsible for ensuring that our business operations run smoothly and efficiently.The ideal candidate will have a strong background in IT service management, with experience in incident management,...


  • Guadalajara, Jalisco, México Stateside A tiempo completo

    This role offers a unique opportunity to join a remote team and take on a challenging role as a Sr. Security Architect. The ideal candidate will have extensive experience in designing and implementing security architectures for cloud-based systems, as well as a deep understanding of security frameworks and industry standards.Key Responsibilities:Security...

  • Security Specialist

    hace 1 semana


    Guadalajara, Jalisco, México Cognizant Technology Solutions A tiempo completo

    **We're seeking a talented Security Specialist to join our team at Cognizant Technology Solutions**As a Security Specialist, you will play a key role in supporting our clients' security needs, working closely with our Information Security teams and business units to ensure the highest level of security and compliance.**Key Responsibilities:**Day-to-day...


  • Guadalajara, Jalisco, México Radian Generation A tiempo completo

    About Radian GenerationRadian Generation is a global provider of critical technology-forward services designed to support the comprehensive lifecycle of renewable facilities, including solar, wind, and energy storage. Our services are tailored to meet the unique needs of developers, owners, and operators in the renewable energy sector.Job SummaryThe SOC Lead...


  • Guadalajara, Jalisco, México Radian Generation A tiempo completo

    About Radian GenerationRadian Generation is a leading provider of technology-forward services designed to support the comprehensive lifecycle of renewable facilities, including solar, wind, and energy storage.We serve a wide range of clients, from developers to operators, with critical insights into each aspect of their assets to make informed...


  • Guadalajara, Jalisco, México Stateside A tiempo completo

    Job Title: Senior Security ArchitectJob Summary: Stateside is seeking a highly skilled Senior Security Architect to design and manage the strategic design of systems, policies, and technologies that protect our organization's IT and business assets from cyber threats. The ideal candidate will have a deep understanding of security principles, concepts, and...


  • Guadalajara, Jalisco, México Ntt Data, Inc. A tiempo completo

    Job Title: Security Specialist - CloudflareNtt Data, Inc. is seeking a skilled Security Specialist to join our team in Mexico. As a Security Specialist, you will be responsible for identifying, troubleshooting, and resolving web access and remote access issues for users, as well as building new solutions based on client requirements.Key...

  • Senior Security Architect

    hace 2 semanas


    Guadalajara, Jalisco, México Stateside A tiempo completo

    Job Opportunity We are seeking a highly skilled Senior Security Architect to join our team at Stateside. Job Summary This is a remote position that requires a strong background in security architecture and design. The successful candidate will be responsible for designing and implementing robust security architectures, developing and maintaining a...


  • Guadalajara, Jalisco, México Radian Generation A tiempo completo

    About Radian GenerationRadian Generation is a global leader in providing cutting-edge technology services to support the entire lifecycle of renewable facilities, including solar, wind, and energy storage.We serve a diverse range of clients, from developers to operators, with a comprehensive suite of commercial, technical, and compliance services that...