Senior Incident Response Analyst

4 Months ago β€’ 3-6 Years β€’ Cyber Security

Job Summary

Job Description

Join Blue Yonder as a Senior Incident Response Analyst in Monterrey. You'll be responsible for threat detection, monitoring, and incident response. Must have experience with SIEM, SOAR, WAF, AV, Firewalls, and malware analysis.
Must have:
  • SIEM experience
  • Malware analysis
  • Incident response
  • Security tools
Good to have:
  • Digital forensics
  • Threat intelligence
  • Email security
  • Network traffic
Perks:
  • Christmas bonus
  • Savings fund

Job Details

Title: Senior Incident Response Analyst (SOC)
Location: Monterrey, N.L.

Blue Yonder is seeking a β€œHands-on” Senior Incident Response Analyst (SOC) who would be responsible for threat detection, monitoring and Incident response. Looking for suitable candidates to join SOC (Security Operations Team) Tier-2 & 3, 24x7 team as Sr. Incident Response Security Analyst. The candidate will be responsible for Daily SOC Operations and security incident response. The candidate is required to work 5 days a week, which could be weekends as well. This candidate will closely be partnering with internal security teams across the world.

Responsibilities

  • Detect and respond to cyber security threats to ensure your organization operates securely.

  • Partner with the existing internal SOC team across the world and keep the CISO informed about security operations.

  • Act as a liaison between the SOC team, other internal stakeholders, and external parties such as vendors, clients or regulatory bodies.

  • Develop incident management plans and procedures, surveying the networks for signs of a breach.

  • Coordinating and executing tabletop exercises to practice, develop plans, policies and procedures.

  • Perform proactive threat hunts to identify threats and assess the state of security controls.

  • Work with in-house red teams in order to detect offensive operations, and capture and action findings.

  • Proactively look for suspicious anomalous activity based on data alerts or data outputs from various toolsets.

  • Drive Security Incidents end-end as Incident Responders (Asses, Triage, Communication, Remediation, Documentation)

  • Develop new SIEM use-cases to detect un-usual activities.

  • Develop Incident Response Playbooks for emerging Threats/attack types.

  • Work on malware analysis, Phishing email analysis, and all other alerts reported.

  • Document the lessons learned and improve the process.

  • Responsible for completing the documentation of the investigation; determine the validity and priority of the activity and escalate to senior SOC analysts or leads.

  • Carry out Level 3 triage of incoming issues (initial assessing the priority of the event, initial determination of incident to determine risk and damage or appropriate routing of security or privacy data request)

  • Provide communication and escalation throughout the incident per the SOC guidelines.

  • Identify and manage a wide range of threat intelligence sources to provide a holistic view of the threat landscape and filter out noise to focus and execute upon actionable intelligence.

  • Leading the development of actionable use cases to detect, triage, investigate and remediate based on latest threat actor trends, support teams with the technical implementation of parsing log sources creating, validating and testing alerting queries to reduce false positives.

  • Ensure that all security events and incidents (internal / external) are logged into ServiceNow and regularly updated and closed within the set SLAs

Qualifications

  • At lest 3-6 years of proven experience in Security incident response and SOC Operations

  • Practical experience with threat detection, monitoring and incident response and implementation

  • Ability to query and write detection rules, in Security tools, (i.e., SIEM (Qradar / Splunk), SOAR, WAF, AV, Firewalls, Internet-facing services).

  • Strong technical understanding of network/OS fundamentals and common Internet protocols, specifically DNS, HTTP, HTTPS

  • Experience conducting technical analysis of security events including Malware analysis, Phishing, and digital forensics.

  • Strong written and oral communication skills.

  • Experience in investigating security issues and / or complex operational issues on Windows and Linux

  • Knowledge of email security threats and security controls, including analyzing email headers, Web attack, network traffic analysis using tools such as Wireshark.

  • Experience reviewing system and application logs (e.g., web or mail server logs)

  • Familiarity with core concepts of security incident response, e.g., the typical phases of response, vulnerabilities vs threats vs actors, Indicators of Compromise (IoCs), etc.

  • Certifications such as GCIH, GCIA, GSEC, CEH, Security+, SSCP.

  • Results focused and attention to detail.

  • Available to work outside of their shift when needed.

At Blue Yonder, we care about the wellbeing of our employees and those most important to them. This is reflected in our robust benefits package and options that includes

  • Competitive Salary

  • Christmas Bonus (30 days)

  • Savings Fund

  • 15 Vacation Days on first two year and 60% Vacation bonus

  • Major and Minor Medical Service insurance for you and your family

  • Life Insurance

  • Totalpass

  • Annual bonus

  • And more to be shared!

#LI-JA1

Our Values


If you want to know the heart of a company, take a look at their values. Ours unite us. They are what drive our success – and the success of our customers. Does your heart beat like ours? Find out here: Core Values

Diversity, Inclusion, Value & Equality (DIVE) is our strategy for fostering an inclusive environment we can be proud of. Check out Blue Yonder's inaugural Diversity Report which outlines our commitment to change, and our video celebrating the differences in all of us in the words of some of our associates from around the world.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Similar Jobs

DAZN - Shift Lead – Anti Piracy

DAZN

Hyderabad, Telangana, India (On-Site)
β€’ 3 Months ago
Cyara - Support Engineer

Cyara

Hyderabad, Telangana, India (Hybrid)
β€’ 4 Months ago
Cyara - NOC Engineer

Cyara

Hyderabad, Telangana, India (Hybrid)
β€’ 4 Months ago
The Walt Disney Company - Sr Engineer - Network

The Walt Disney Company

Burbank, California, United States (On-Site)
β€’ 3 Months ago
PlayStation Global - Sr Application Security Engineer

PlayStation Global

United States (Remote)
β€’ 4 Months ago
PwC - ETIC, Cybersecurity Cloud Security - Manager

PwC

Cairo, Cairo Governorate, Egypt (On-Site)
β€’ 4 Months ago
varonis-internal - Cloud Security Architect

varonis-internal

London, England, United Kingdom (On-Site)
β€’ 3 Months ago
Illumina - Sr IT Engineer

Illumina

Bengaluru, Karnataka, India (On-Site)
β€’ 4 Months ago
PwC - Risk Services, Digital Audit - Associate / Senior Associate

PwC

Singapore (On-Site)
β€’ 4 Months ago
PwC - IN_Manager_ IT Risk _S&G _Advisory_Pune

PwC

Pune, Maharashtra, India (On-Site)
β€’ 4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Playrix - Senior QA Engineer (VSO Engine)

Playrix

Georgia (Remote)
β€’ 3 Months ago
Axinous - Escalation Engineer

Axinous

Sahibzada Ajit Singh Nagar, Punjab, India (Hybrid)
β€’ 3 Months ago
Intel Corporation - Network Security Engineer (DevSecOps)

Intel Corporation

Phoenix, Arizona, United States (Hybrid)
β€’ 3 Months ago
Saviynt - Technical Lead, Support Operations- Networking

Saviynt

Bengaluru, Karnataka, India (Hybrid)
β€’ 3 Months ago
Playrix - Senior QA Engineer (VSO Engine)

Playrix

Almaty, Almaty Region, Kazakhstan (Remote)
β€’ 3 Months ago
Axinous - Product Support Engineer II

Axinous

Sydney, New South Wales, Australia (Hybrid)
β€’ 3 Months ago
Wolters Kluwer - Principal Network Engineer | Cloud

Wolters Kluwer

New York, New York, United States (Hybrid)
β€’ 4 Months ago
Axinous - Senior/Staff Windows Developer

Axinous

San Jose, California, United States (On-Site)
β€’ 3 Months ago
Axinous - Customer Success Developer

Axinous

London, England, United Kingdom (Remote)
β€’ 3 Months ago
Axinous - Technical Account Manager - Central Region

Axinous

Illinois, United States (Remote)
β€’ 3 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Monterrey, Nuevo Leon, Mexico

Nissan - SAP Data Management Supervisor

Nissan

Mexico City, Mexico City, Mexico (On-Site)
β€’ 4 Months ago
HP - Digital and Transformation Finance Controller

HP

Tlaquepaque, Jalisco, Mexico (On-Site)
β€’ 4 Months ago
Blue Yonder - Mid-level Graphic Designer

Blue Yonder

Monterrey, Nuevo Leon, Mexico (Remote)
β€’ 3 Months ago
Blue Yonder - Support Engineer II (Supply Chain Planning)

Blue Yonder

Monterrey, Nuevo Leon, Mexico (On-Site)
β€’ 4 Months ago
PwC - Manager Fiscal

PwC

Mexico City, Mexico City, Mexico (On-Site)
β€’ 4 Months ago
HP - Principal Data Scientist

HP

Tlaquepaque, Jalisco, Mexico (On-Site)
β€’ 4 Months ago
Liquid Development - Senior 3D Environment Artist/World Builder

Liquid Development

Mexico City, Mexico City, Mexico (Hybrid)
β€’ 7 Months ago
HP - Workplace Solutions Category Manager

HP

Tlaquepaque, Jalisco, Mexico (On-Site)
β€’ 4 Months ago
paypal - Facilities Lead

paypal

Mexico City, Mexico City, Mexico (On-Site)
β€’ 4 Months ago
gigamon - Principal Professional Services Engineer - Mexico

gigamon

Mexico City, Mexico City, Mexico (On-Site)
β€’ 3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

HP - Cybersecurity Metrics Analyst

HP

Bengaluru, Karnataka, India (On-Site)
β€’ 4 Months ago
PwC - IN_Senior Associate_Internal Audit_Managed Services_Advisory_Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
β€’ 4 Months ago
Axinous - Principal Zero-Day Vulnerability Researcher

Axinous

San Jose, California, United States (Remote)
β€’ 3 Months ago
PwC - Senior Scrum Master

PwC

Rosario, Santa Fe Province, Argentina (On-Site)
β€’ 4 Months ago
Meta - Product Security Engineer

Meta

Bellevue, Washington, United States (On-Site)
β€’ 3 Months ago
Keywords Studios (Player Support) - Global Information Security Operations Lead - APAC

Keywords Studios (Player Support)

Philippines (Remote)
β€’ 8 Months ago
ElevenLabs - IT Security Engineer

ElevenLabs

Berlin, Berlin, Germany (Remote)
β€’ 3 Months ago
PwC - IN-Senior Associate_ITGC _Strategy and Governance_ Advisory_Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
β€’ 4 Months ago
PwC - CD&E -SOC L1 Support- Associate 2 - Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
β€’ 4 Months ago
Google - Customer Engineer, Security, Small and Medium Business

Google

Dublin, County Dublin, Ireland (On-Site)
β€’ 3 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Bengaluru, Karnataka, India (On-Site)

Hyderabad, Telangana, India (On-Site)

Dallas, Texas, United States (On-Site)

Tokyo, Japan (On-Site)

Warsaw, Masovian Voivodeship, Poland (Hybrid)

Hyderabad, Telangana, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Monterrey, Nuevo Leon, Mexico (Remote)

Bengaluru, Karnataka, India (On-Site)

View All Jobs

Get notified when new jobs are added by Blue Yonder

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug