Job Description
Position: SOC Analyst L1
Location: Guadalajara / On-site
Position Type: Full-time
Time Zone: CST
Duration: Permanent
Working Hours/Shift:
- Sunday to Wednesday, 7 AM 5 PM (1 day remote)
- Sunday to Wednesday, 1 PM 12 AM (1 day remote)
Job Responsibilities
Daily Activities:
- Monitor, respond to, and analyze SIEM alerts from monitoring tools.
- Provide technical guidance and recommendations to clients to enhance their overall security posture within the managed products.
- Handle daily incidents; monitor, track, analyze, and record security events.
- Collaborate with vendors, outside consultants, and third parties to improve information security within the organization.
- Respond to security-related tickets escalated from clients, and work collaboratively with clients to resolve security events.
- Work with other IT professionals to resolve fast-moving vulnerabilities such as spam, viruses, spyware, and malware.
- Monitor security vulnerability information from vendors and third parties.
- Create weekly and monthly status reports, including daily technical task reports and contract deliverables.
Skills and Qualifications
- Strong written, verbal, and non-verbal communication skills, especially in conveying complex information understandably.
- Proficiency with SIEM tools is a must.
- 2-4 years of experience working with Microsoft Active Directory.
- Ability to analyze and resolve complex technical and business problems.
- Proficient knowledge in three or more of the following technologies: Application / stateful / UTM firewalls, SIEM, DLP, web content filtering, web application firewalls (WAF), vulnerability scanning and penetration testing, IPS/IDS, Security Operations Center operations, wireless networking, UNIX, AIX & Solaris, Linux, Windows Server Operating Systems, endpoint protection, and malware.
- Knowledge of Windows Server platforms (2003-2012).
- Working knowledge of analyzing IIS, SQL, firewall, IPS/IDS, and Windows logs.
- Ability to analyze IANA assigned ports (well-known, registered, dynamic, and private ports).
- Ability to troubleshoot common network devices, network vulnerabilities, and network attack patterns.
- Ability to troubleshoot Windows Event IDs.
- Interact with all levels of management.
- Make decisions based on many variables.
- Manage multiple tasks/projects simultaneously.
- Minimum of a Bachelor's Degree in Computer Science, Telecommunications Management, Electrical Engineering, or a related field, or 4 years of relevant experience.
Must Have:
- Previous experience with SIEM tools (academic or professional).
- On-site availability.
- High proficiency in English.
- Basic knowledge of networking and cybersecurity.