Cyber Threat Intelligence Analyst

hace 4 días


Colonia Polanco, México Siemens A tiempo completo

**Looking for a chance to create a positive impact on our society?**

Siemens Cybersecurity Defense is a global organization within Siemens consisting of regionally aligned teams across Germany, Portugal, Spain, United States, Mexico, and China. The mission of the organization is to proactively identify anomalies, respond and remediate Cybersecurity issues related to IT infrastructure, Operational Technology (OT), and products of Siemens.

**As Senior Cyber Threat Intelligence Expert (f/m/d) you will**:

- Provide intelligence to support decision making process concerning emergent and current threats targeting Siemens by developing processes and procedures to gather, identify, analyze, and distribute tailored intelligence products.
- Collaborate with Incident Response team, translating raw sensor data, reports, and other intelligence feeds into actionable intelligence to drive proactive measures and appropriately prioritize response activities.
- IT security incidents in a geographically distributed environment, orchestrating the interaction among all relevant technical and non-technical stakeholders during all phases of the incident.
- Help improving Siemens CERT internal playbooks and toolset by contributing with improvement ideas about processes, functionalities, and new features.
- Collect, organize, analyze, and refine information about known and emerging cyber security threats, including novel tactics, techniques, and procedures (TTPs) used by attackers to potentially target Siemens’ business or customers.
- Support the awareness activities by monitoring for and reporting relevant news in the cyber security space in the form of news articles on the Siemens CERT News Portal, for which you will also provide a Siemens-tailored risk assessment.
- Research on the latest trends in malware and advanced attacks.
- Leverage internal and external resources to enrich relevant information to deliver contextualized intel to acting teams in a timely manner.
- Contribute to every step of the IoC lifecycle within the Siemens CERT Threat Intelligence Platform (e.g. organizing input sources and feeds, manually crafting new indicators, tuning the strategies in place to label and organize relevant intel, etc.)
- Monitor Siemens’ public exposure to detect signs of sensitive disclosure, exposed credentials, and targeted hacker groups activities
- Provide tailored intelligence briefings to Cybersecurity colleagues and to other Security and IT areas.

**To make a difference, you must have**:

- Significant technical system expertise (e.g. gathered from being an IT Administrator) with relevant exposure and expertise in IT Security, in several of the following technologies: Linux and Windows operating systems, web-technologies (encryption, HTTP, REST), networking, cloud environments
- Expert knowledge of fundamental Threat Intelligence concepts (terminology, tools, processes, etc.). Experience with formal aspects of Threat Intelligence (e.g. ACH, analytical biases, etc.) is a plus.
- Experience with common threat intelligence models, tools, sources, and feeds.
- Strong analytical skills with the ability to collect, organize, analyze, and disseminate significant amounts of information with attention to detail and accuracy.
- Significant experience conducting intelligence analysis, including social network analysis, targeting, technical analysis, attribution etc.
- Knowledge of cyber threats and vulnerabilities: how to properly identify, triage, and remediate threats based on threat intelligence as well as on analysis of security events, log data and network traffic.
- Understanding of technical and human aspects of cyber threats and security.
- Deep and current knowledge of most common OSINT tools and techniques, including social network monitoring and dark web networks (TOR, I2P, etc.).
- Experience tracking threat actors or comparable types of cyber investigations.
- Basic knowledge of relevant laws, regulations, policies, and ethics related to cybersecurity and privacy topics. Advanced knowledge of regional (e.g. GDPR) or sector-specific (e.g. HIPAA) laws and regulations is a plus.
- Models to describe and document cyber-attacks (e.g., reconnaissance, scanning, enumeration, persistency, lateral movement, exfiltration) such as Cyber Kill Chain, Diamond model or MITRE ATT&CK.
- Familiarity with Incident Handling-related topics.
- Application Security Risks (e.g., OWASP Top 10 list).
- Experience with Malware analysis, sandboxes, and reverse engineering tools.
- Experience with scripting languages (e.g., Python, Bash or PowerShell) and using REST API, as well as data processing, regular expressions, and console-based text processing tools (e.g., sed, awk, jq).
- Bachelor degree in STEM studies (required). A Master degree (or higher academic title) in computer science or cyber security topics is highly desirable but might be traded-off for relevant experience.
- At least 5 years of relevant work experience in at least one of



  • Colonia Polanco, México Siemens A tiempo completo

    Siemens Cybersecurity Defense is a global organization within Siemens consisting of regionally aligned teams across Germany, Portugal, Spain, United States, Mexico, and China. The mission of the organization is to proactively identify anomalies, respond and remediate Cybersecurity issues related to IT infrastructure, Operational Technology (OT), and products...


  • Colonia Bosques de las Lomas, México Unilever A tiempo completo

    **Location**: Bosques, Mexico City **Terms & Conditions**: Full time position. Currently live in Mexico City. Have an advanced level of English. **ABOUT UNILEVER** Unilever is the place where you can bring your purpose to life with the work that you do - creating a better business and a better world. You will work on brands that are loved and improve the...


  • Polanco IV Sección, México RMx DEV S de R L de C V A tiempo completo

    **Purpose**The Cyber Security Analyst is a technically proficient business oriented information security leader with broad experience in all the core areas of information security. As a security analyst, you will be responsible for working closely with development teams, infrastructure teams, architects, business analysts and business partners to identify,...


  • Colonia Polanco, México Siemens A tiempo completo

    Siemens Cybersecurity Defense is a global organization within Siemens consisting of regionally aligned teams across Germany, Portugal, Spain, United States, Mexico, and China. The mission of the organization is to proactively identify anomalies, respond and remediate Cybersecurity issues related to IT infrastructure, Operational Technology (OT), and products...

  • Cyber Security Analyst

    hace 2 semanas


    Colonia Polanco, México Mercer A tiempo completo

    We are seeking a talented individual to join our Cyber Security Incident Response team at Marsh McLennan. This role will be based in Mexico City, Torre Mayor office. This is a hybrid role that has a requirement of working at least three days a week in the office. As a Cyber Security Analyst, you will play a crucial role in monitoring and responding to...


  • Colonia Polanco, México Siemens, S.A. de C.V. A tiempo completo

    **Job Description**:What are my responsibilities?- Operate a cloud environment. This includes automation, monitoring, improvement.- Maintain a next-generation log collection and Big Data Analytics framework- Build / integrate automation tools to deploy and monitor cyber defense use cases.- Operate and implement new functionalities through REST APIs- Operate...

  • Cyber Incident Responder

    hace 3 semanas


    Colonia Polanco, México Siemens, S.A. de C.V. A tiempo completo

    Siemens CERT is a dedicated team of Security Engineers with the mission to secure the Siemens infrastructure. CERT also monitors the current Cyber Threat Landscape for Siemens and assesses its potential impact to the enterprise. Based on that know-how and the latest technological trends, it consults with the Information Technology departments in...

  • Cyber Incident Responder

    hace 2 semanas


    Colonia Polanco, México Siemens A tiempo completo

    Siemens CERT is a dedicated team of Security Engineers with the mission to secure the Siemens infrastructure. CERT also monitors the current Cyber Threat Landscape for Siemens and assesses its potential impact to the enterprise. Based on that know-how and the latest technological trends, it consults with the Information Technology departments in Siemens to...


  • Colonia Polanco, México Marsh McLennan A tiempo completo

    We are seeking a talented individual to join our Cyber Security Incident Response team at Marsh McLennan. This role will be based in Mexico City, Torre Mayor office. This is a hybrid role that has a requirement of working at least three days a week in the office.As a Cyber Security Analyst, you will play a crucial role in monitoring and responding to...

  • DevOps Engineer

    hace 6 días


    Colonia Polanco, México Siemens A tiempo completo

    Siemens Cybersecurity Defense is a global organization within Siemens consisting of regionally aligned teams across Germany, Portugal, Spain, United States, Mexico, and China. The mission of the organization is to proactively identify anomalies, respond and remediate Cybersecurity issues related to IT infrastructure, Operational Technology (OT), and products...