SOC (Security Operation Center) - Purple Team -tier
hace 2 semanas
**Why Kyndryl**Kyndryl is a market leader that thinks and acts like a start-up. We design, build, manage, and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl?We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers, and our communities. We invest heavily in you - not only through learning, training, and career development, but also through the flexible working practices and stellar benefits that help you grow and progress long-term. And we give back - from planting 90,000 trees in our first 3 months as part of our One Tree Planted initiative to the Corporate Social Responsibility and Environment, Social and Governance practices embedded within everything we do, we are committed to powering human progress in an ethical, sustainable way.**Your Role and Responsibilities**- Serve as Tier 3 level for complex technical and procedural escalations- Provide technical lead support to tier 2 and 1 soc analysts- Responsible for development and execution of incident response plans for escalated response processes- Proactively identify indicators of compromise and generate and execute- Incident Response Plan upon detection- Provide Incident remediation and prevention documentation- Identification and resolution of complex issues in customer environments.- Develop resolution and implementation plans- Work in collaboration with other security and company departments (operations, legal, sales) to help identify / resolve chronic issues and assist with the creation and implementation of corrective / preventative action plans- Research, analyze and identify potential vulnerabilities and security deficiencies. Initiate escalation procedure to counteract potential threats/vulnerabilities- Conduct security training, new hire training and network impact reviews. Coordinate repair and maintenance of security system with security integrators- Liaise directly with third party vendors / suppliers- Develop, document, and maintain Incident Response process, procedures, workflows, and playbook.- Tune and maintain security tools (EDR, IDS, SIEM, etc) to reduce false positives and improve SOC detection capabilities- Document Investigation and Incident Response actions taken in Case Management Systems and prepare formal Incident Reports- Create metrics and determine Key Performance Indicators to measure maturity of SOC operations.- Develop security content such as scripts, signatures, and alerts**Required Technical and Professional Expertise**- Experience at least three (3) years working with SIEM(QRADAR, SPLUNK, SENTINEL, etc), FW, IPS/IDS- Threat Intelligence solutions, knowledge of Elastic Stack (Elasticsearch, Kibana)- Strong analytical skills to define risk, identify potential threats, document and develop action/mitigation plan- Deep knowledge/experience with Operating Systems (e.g. Windows Server, CentOS Linux).- Knowledge/experience of networking and firewalls- Knowledge of Enterprise Anti-Virus, IDS, Full Packet Capture and Host/Network Threat Analysis- Knowledge of Threat Monitoring Procedures- Deep knowledge conducting and leading incident response situations- Experience implementing monitoring tools and capabilities- Solid hands-on experience with one or several of the following security tools:- CrowdStrike O365 Security, AWS security and/or Hub Azure defender- Security center Splunk Advance OSINT knowledge- Experience with a wide range of security tools and knowledge of relevant cyber frameworks and methodologies- Work in collaboration with other security and company departments to help identify / resolve chronic issues and assist with the creation and implementation of corrective / preventative action plans- Research, analyze and identify potential vulnerabilities and security deficiencies. Initiate escalation procedure to counteract potential threats/vulnerabilities- Conduct security training, new hire training and network impact reviews- Coordinate repair and maintenance of security system with security integrators- Liaise directly with third party vendors / suppliers- Develop, document, and maintain Incident Response process, procedures, workflows, and playbook- Tune and maintain security tools (EDR, IDS, SIEM, etc) to reduce false positives and improve SOC detection capabilities- Document Investigation and Incident Response actions taken in Case Management Systems and prepare formal Incident Reports- Create metrics and determine Key Performance Indicators to measure maturity of SOC operations- Develop security content such as scripts, signatures, and alerts**Preferred Technical and Professional Experience**- Three (3) years experience working within a security operations center- Three (3) years experience working across multiple security disciplines (DFIR, log analysis, packet analysis, etc.) 1-2 years of le
-
Senior Lead, Security Specialist: SOC
hace 1 semana
Ciudad de México Kyndryl Mexico S. de R.L. de C.V. A tiempo completo**Why Kyndryl** Kyndryl is a market leader that thinks and acts like a start-up. We design, build, manage, and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our...
-
SOC Tier 2
hace 1 semana
Ciudad de México Kyndryl Mexico S. de R.L. de C.V. A tiempo completo**Why Kyndryl** Kyndryl is a market leader that thinks and acts like a start-up. We design, build, manage, and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our...
-
Professional, Information Security
hace 2 semanas
Ciudad de México Ingram Micro A tiempo completoIt's fun to work in a company where people truly BELIEVE in what they're doing!**Job Description**:As a global leader in technology, working in partnership with thousands of experts, you’ll be part of the respected Ingram Micro international team delivering cutting-edge solutions worldwide.Be part of our tomorrow as a Professional, Information Security...
-
Associate Professional, Information Security
hace 2 semanas
Ciudad de México Ingram Micro A tiempo completoIt's fun to work in a company where people truly BELIEVE in what they're doing!**Job Description**:Join the business behind the world’s technology brands. You’ll be providing leading-edge IT solutions whilst enjoying the benefits of an ethical, multinational corporation— building us a brighter tomorrow.Be part of our tomorrow as an Information...
-
Senior Support Engineer
hace 4 semanas
Ciudad de México Purple A tiempo completoAre you a highly skilled and customer-focused Support Engineer with a passion for cutting-edge WiFi technology? Do you thrive in a dynamic environment where you can make a significant impact? We're seeking a Senior Support Engineer to join our team, with a primary focus on enabling the success of one of our key partners, Telmex, and their customers.**About...
-
Manager, Security Operations Center
hace 6 días
Ciudad de México, CDMX Warner Bros. Discovery A tiempo completo**_Welcome to Warner Bros. Discoverythe stuff dreams are made of._** **Who We Are ** When we say, “the stuff dreams are made of,” we’re not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD’s vast portfolio of iconic content and beloved brands, are the _storytellers_ bringing our...
-
Jefe de Ciberseguridad
hace 6 días
México Mabe A tiempo completo**DESCRIPCION GENERAL DEL PUESTO**: **PRINCIPALES RESPONSABILIDADES**: 1. Gestión de proveedores 2. Gestión de security operation center (SOC) 3. Gestión de threat intelligence 4. Auditorías a sistemas internos **PRINCIPALES ACTIVIDADES A DESEMPEÑAR**: 1. Gestión de proveedores 2. Gestión de security operation center (SOC) 3. Gestión de threat...
-
SOC Analyst
hace 3 semanas
México Talent Center A tiempo completoTechnical degree or Computing Modules- 1 to 3 years of experience in a SOC- Proficiency in using Security Information and Event Management (SIEM) solutions- Familiarity with other security tools, including firewalls, intrusion detection systems (IDS), and vulnerability scanners- Security Essentials- Computer Forensic Investigation-Windows in depth- Security...
-
SOC Analyst
hace 3 semanas
Ciudad de México Temenos A tiempo completoTHE ROLE As our Security Incident Responder you will be part of a fast-paced Global SOC team and cover broad aspects of Temenos Cyber security monitoring and incident response operations. Working closely with SOC Manager and Cyber Security Engineers, the role is to help coordinate and report on cyber incidents affecting Temenos on-premises and Cloud...
-
Director Soc
hace 1 semana
Ciudad de México Factor Uno A tiempo completo**Requisitos**: - Edad: 30 a 45 años. - Ingeniero o licenciatura en Informática o sistemas (finalizada). - Esquema de trabajo hibrido. Cdmx - Inglés comunicacional avanzado. **Experiência**: - Amplio conocimiento en ciberseguridad - Operación de SOC a nível gerencial de prefencia directivo - Metodologías de seguimiento y respuesta a incidentes. -...