Security Analyst

Logo of Encora

Encora

πŸ“Remote - Mexico

Job highlights

Summary

Join Encora as a Senior Security Operations Analyst and play a critical role in our cybersecurity framework. You will specialize in security event analysis, detection, and response, handling complex security incidents. This role requires a strong background in security operations and a comprehensive understanding of cybersecurity fundamentals. You will manage security operation technologies, lead incident response efforts, and conduct threat hunting. The ideal candidate will have experience with SIEM and EDR tools, scripting languages, and cloud security. This is a full-time, work-from-home position.

Requirements

  • Broad and deep knowledge of security concepts, principles, and best practices
  • 5-7 years information security and/or technology experience, 3+ years in a similar cyber security analyst role
  • Exceptional decision-making skills, demonstrating a track record of effectively evaluating the costs and benefits of various courses of action to find the optimal solution
  • Comfortable communicating with a broad audience, including executives, clients, and cross-functional teams
  • Skilled in the analysis of threat event data and recognition of tactics, techniques, and procedures (TTPs) employed by threat actors
  • Experience with operating and managing SIEM (e.g., Google Chronicle, Splunk) and Endpoint, Detection and Response (EDR) tools
  • Familiar with scripting languages for automation (e.g., Python, Bash, PowerShell)
  • An understanding of applying MITRE ATT&CK or similar frameworks in enterprise environments
  • Experience with cloud security and monitoring (e.g., AWS, Azure, Google Cloud)
  • Strong background in incident response and handling complex security incidents
  • Experience in cyber threat intelligence gathering and analysis and threat hunting methodologies and tools

Responsibilities

  • Review and analyze security alerts generated by the SIEM system, prioritizing and triaging alerts based on severity and potential impact
  • Manage and optimize security operation technologies and functions such as SIEM, TIP, and incident response case management to enhance the organization's security visibility
  • Evaluate security data sources and use cases for consideration in the improvement and expansion of the team’s detection capabilities
  • Lead incident response efforts, including investigation, containment, eradication, and recovery from security incidents and breaches. Participating in the team’s on-call rotation for critical incident escalations
  • Conduct root cause analysis and post-incident reviews
  • Develop and evangelize incident response playbooks and procedures for CSIRT
  • Steer the Cyber Threat Intelligence (CTI) program to continually monitor emerging security threats, trends, and technologies. Provide recommendations for improving security controls and processes to mitigate risks efficiently
  • Gather and analyze cyber threat intelligence from various sources, correlate it with security events and incidents, and provide actionable insights to the security team and stakeholders
  • Conduct proactive threat hunting activities to identify potential threats, develop and implement methodologies and tools, and document findings with recommended mitigation strategies
  • Monitor and analyze user behavior to detect potential insider threats, investigate suspicious activities and recommend appropriate actions, and develop and implement insider threat detection and response strategies
  • Provide guidance, support, and mentorship to junior team members who demonstrate a willingness to learn and take on new challenges
  • Aid in the gathering of evidence for compliance audits

Preferred Qualifications

CISSP, GIAC or comparable certifications

Benefits

Work from home

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.

Similar Remote Jobs

Please let Encora know you found this job on JobsCollider. Thanks! πŸ™