Security Operations Center

hace 2 semanas


Guadalajara, México Avertium A tiempo completo

Avertium is the managed security and consulting provider that companies turn to when they want more than check-the-box cybersecurity. In today’s threat landscape, your not-so-standard processes, workflows, and vulnerabilities require more than just a standard approach to cybersecurity. You need a smarter, stronger, show-no-weakness approach based on more rigor, more relevance, and more responsiveness. That is why more than 1,200 organizations in every sector from manufacturing to financial services, healthcare to technology and business services to hospitality rely on Avertium for cybersecurity services.**SOC Team Lead Key Responsibilities**:- Conduct multi-step breach and investigative analysis to trace the dynamic activities associated with advanced threats.- Perform investigation and escalation for complex or high severity security threats or incidents.- Serve as an escalation resource and mentor for other analysts.- Work with SIEM Engineering to develop and refine correlation rules.- Work on complex tasks assigned by leadership, which may involve coordination of effort among Level 1/2/3 analysts.- Coordinate evidence/data gathering and documentation and review Security Incident reports.- Assist in defining and driving strategic initiatives.- Define tool requirements to improve SOC capabilities.- Experience analyzing packet captures to identify malicious activity.- Fluency in common network protocols including TCP/IP, DNS, TLS, HTTP.- Experience with SIEM technology such as: AlienVault USM Appliance, USM Anywhere, LogRhythm, and/or Wazuh IDS highly preferred.- Malware reverse engineering experience a big plus including tools used.- Monitor, respond to, and analyze SIEM alerts from monitoring tools.- Provide technical guidance / recommendations to clients to enhance their overall security posture within the managed products. Handles daily incidents; monitors, tracks, analyzes and records.- Work with vendors, outside consultants, and other third parties to improve information security within the organization.- Responds to security related tickets escalated from clients, and works collaboratively within the client to assist in resolving security events.- Work with other IT professionals to resolve fast moving vulnerabilities, such as spam, virus, spyware and malware.- Monitor security vulnerability information from vendors and third parties.- Create Weekly and Monthly Status Reports, including daily technical task reports and contract deliverables.- Proactive Threat Hunting using industry tools and existing IDS systems.- Advanced Forensics skills to evaluate current malware and phishing threats.**Qualifications**:- Strong written, verbal and non-verbal communication skills, especially conveying complex information in an understandable manner.- CISSP, CISA or GIAC certification is a plus.- A minimum of 5 years of experience working with Microsoft Active Directory.- Experience in managing an organization's PCI, HIPAA, or SSAE16 certification is preferred.- Analyze and resolve complex technical and business problems.**Job / Experience Requirements**:- Knowledge with NIST, FISMA, DIACAP.- Knowledge of Windows server platforms.- Knowledge of VMware and VM server platforms.- Knowledge of UNIX server platforms.- Working knowledge of analyzing IIS, SQL, firewall, IPS/IDS, Windows.- Web and mail logged events.- Ability to analyze IANA assigned ports (well known, registered, dynamic and private ports).- Ability to troubleshoot common network devices, network, vulnerabilities and network attack patterns.- Ability to troubleshoot Windows Event IDs.- Interact with all levels of management.- Make decisions based on many variables.- Manage multiple tasks/projects simultaneously.**Education and Certification Requirements**:- Minimum of Bachelor's Degree in computer science, telecommunications management, electrical engineering, or a related field or have 4 years of experience.- Advanced network and systems certifications such as CCNP, CCNA and CISSP, are preferred.- Other industry certifications such as ITIL, Microsoft, Juniper and Checkpoint are a plus.



  • Guadalajara, México DEPROC CONSULTORIA EN PROCESOS Y COACHING A tiempo completo

    **Role and Responsibilities**- Lead and manage the Security Operations Center, ensuring efficient and effective 24/7 monitoring of all renewable energy projects.- Develop and implement SOC procedures, protocols, and policies to enhance security operations.- Oversee the detection, analysis, and response to security incidents and threats targeting industrial...


  • Guadalajara, México Epsilon Solutions A tiempo completo

    **Vacante para la empresa Epsilon Solutions en Guadalajara, Jalisco**:**Security Operations Center (SOC) - L1 or L2**:We are looking for a Security Operations Center (SOC) - L1 or L2**Requirements**:Grade: Computer Systems Engineer or equivalent (DEGREE, 100% of credits, Truncated)Gender: IndistinctAge: Not requiredLanguage: Advanced EnglishAVAILABILITY TO...


  • Guadalajara, México DEPROC CONSULTORIA EN PROCESOS Y COACHING A tiempo completo

    **JOB SUMMARY****Role and Responsibilities**- Monitor OT networks for security threats and vulnerabilities, assisting in incident responses.- Manage user provisioning, including creating and maintaining user accounts, modifying permissions, and managing access control lists.- Execute standard operating procedures and adhere to company policies.- Maintain...


  • Guadalajara, México Percona A tiempo completo

    Percona is experiencing significant growth as we continue to mature our IT Security practices and as the company transitions to a software-led organization. The mission of the Security Operation Team Lead is to ensure the overall security of Percona’s information, with a focus on customer information. This is accomplished by managing our Security...


  • Guadalajara, México MHP Mexico A tiempo completo

    ENABLING YOU TO SHAPE A BETTER TOMORROW.- **Code number**:J - **Entry level**:Professionals- **Location**:Mexico- **Organization**:MHP Mexico**Tasks**Tasks**Tasks**We are seeking a highly motivated and skilled **Senior Analyst** in **Security Operations** **and Identity & Access Management (IAM)** to join our international team. This role is ideal for...


  • Guadalajara, México Canonical A tiempo completo

    Join to apply for the Head of Security Operations role at Canonical Join to apply for the Head of Security Operations role at Canonical This global leadership role in cyber security is to manage the Security Operations (SecOps) team responsible for design, implementation and evolution of Canonical security practices, techniques, tools, systems and policies....


  • Guadalajara, México f5 A tiempo completo

    Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.The F5 Security Operations Center is the epicenter of dynamic security events; clients under siege daily, with new attacks and attack vectors...


  • Guadalajara, México f5 A tiempo completo

    Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!**This opportunity is...


  • Guadalajara, México f5 A tiempo completo

    Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!Our Security as a Service...

  • Security Engineer

    hace 1 semana


    Guadalajara, México f5 A tiempo completo

    Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.Join our security engineering team focused on creating internal vulnerability management tools for F5. We use various industry-standard...