SOC Tier 3 Analyst & Engineer

dxctechnology

Santiago

Sur place

CLP 12 000 000 - 24 000 000

Plein temps

Il y a 10 jours
Générateur de candidature

Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.

Passez les filtres ATS

Résumé du poste

DXC Technology is seeking a skilled Cyber Security Analyst to join a global SOC team in Santiago. You will analyze complex security events, correlate data across SIEM tools, and drive incident response from detection to remediation.

The role emphasizes collaboration with IT operations, threat intelligence, and security engineering, with a focus on modern security platforms and OT environments.

Qualifications

  • 3–5 years of operational experience as a cyber security analyst/engineer handling incidents, detection, and response.
  • Experience with SIEM, IDS/IPS, firewalls, NAC, DLP and endpoint protection.
  • Strong communication, organizational and customer service skills.
  • Hands-on with scripting (Python/PowerShell/Bash).
  • Familiarity with OT environments (Nozomi Networks, SCADA/ICS) is a plus.

Responsabilités

  • Analyze cyber security incidents and provide corrective analysis for escalated events.
  • Correlate logs from diverse devices to identify threats and recommend remediation.
  • Ingest IOCs and enhance SOC runbooks and SOPs.
  • Coordinate with enterprise staff to resolve incidents and improve alerting.
  • Develop technical advisories and contribute to incident response processes.

Connaissances

English/Spanish fluency
Incident handling
Threat hunting
SIEM analysis
Python
PowerShell
Bash
Network protocols
Troubleshooting
Effective communication

Formation

CompTIA Security+
CISSP (preferred)
GCIA/GPEN/CERT or equivalent

Outils

CrowdStrike
Splunk ES
SNORT
Yara
Nozomi Networks
Palo Alto Cortex XSIAM
Microsoft Defender/MDATP
Active Directory

Description du poste

Job Description:

At DXC, we harness the power of technology to deliver mission-critical IT services that our clients need to modernize operations and drive innovation across their entire IT estate. We provide services through the Enterprise Technology Stack for business process outsourcing, analytics and engineering, applications, security, cloud, IT Outsourcing, and Modern Workplace.

About the role

Responsibilities:

  • Utilize advanced technical background and experience to scrutinize and provide corrective analysis to escalated cyber security events from Tier 1 & 2 analysts distinguishing these events from benign activities and escalating confirmed incidents to the Incident Response Lead.
  • Provide in-depth cyber security analysis, and trending/correlation of large datasets such as logs, event data, and alerts from diverse network devices and applications within the enterprise to identify and troubleshoot specific cyber security incidents and make informed technical recommendations that enable remediation efficiently.
  • Proactively search through log, network, and system data to find and identify undetected threats.
  • Identify and ingest indicators of compromise (IOC’s) (e.g., malicious IPs/URLs, etc.) into network security tools/applications to protect the clients network.
  • Quality-proof technical advisories and assessments prior to release from SOC.
  • Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents.
  • Report common and repeat problems, observed via trend analysis, to SOC management and propose process and technical improvements to improve the effectiveness and efficiency of alert notification and incident handling.
  • Formulate technical best-practice SOPs and Runbooks for SOC Analysts.
  • Respond to inbound requests via phone and other electronic means for technical assistance and resolve problems independently. Coordinate escalations with Service Delivery Lead and collaborate with internal technology teams to ensure timely resolution of issues.
  • Identifies, reports, and resolves security violations.
  • The role oversees a modern security ecosystem leveraging AI Agentic SIEM, OT environment with Nozomi, and Threat Intelligence platforms to deliver real-time visibility, rapid threat detection, and resilient cyber operations.

Skills and Qualifications:

  • Proficiency in English and Spanish, enabling effective communication with global stakeholders, vendors, and executive leadership teams.
  • At least 3-5 years of demonstrated operational experience as a cyber security analyst/engineer handling cyber security incidents and response in critical environments, and/or equivalent knowledge in areas such as: technical incident handling and analysis, intrusion detection, log analysis, penetration testing, vulnerability management.
  • In-depth understanding of: current cyber security threats, attacks and countermeasures for adversarial activities such as network probing and scanning, distributed denial of service (DDoS), phishing, ransomware, botnets, command and control (C2) activity, etc.
  • In-depth hands-on experience analyzing and responding to security events and incidents with most of the following technologies and/or techniques: security information and event management, (SIEM) technologies, intrusion detection/prevention systems (IDS/IPS), network and host-based firewalls, network access control (NAC), data leak protection (DLP), database activity monitoring (DAM), web and email content filtering, vulnerability scanning tools, endpoint protection, secure coding, etc.
  • Strong communication, interpersonal, organizational, oral, and customer service skills.
  • Strong knowledge of TCP/IP protocols, services, and networking.
  • Knowledge of forensic analysis techniques for common operating systems.
  • Adept at proactive search, solicitation, and detailed analysis of threat intelligence (e.g., exploits, IOCs, hacking tools, vulnerabilities, threat actor TTPs) derived from open-source resources and external entities, to identify cyber security threats and derive countermeasures, not previously ingested into network security tools/applications (external & internal threat hunting)
  • Excellent ability to multi-task, prioritize, and manage time and tasks effectively.
  • Ability to work effectively in stressful situations.
  • Strong attention to detail.
  • Strong understanding of command line scripting and implementation (i.e., Python, PowerShell, Bash Shell)
  • Ability to write new content/searches/scripts (e.g., CrowdStrike Falcon Next-Gen + AI & ONUM, Palo Alto Cortex XSIAM + AI, Microsoft Azure Sentinel, Splunk Enterprise Security, IBM QRadar, ManageEngine Log360, etc.)
  • Strong knowledge of Operational Technology (OT) environments, including SCADA systems, Industrial Control Systems (ICS), industrial network security, asset visibility, threat detection, and OT security solutions such as Nozomi Networks.
  • Experience with tools such as Active Directory, Cisco IOS, MS Server, AMP, CrowdStrike, Splunk ES, SNORT, Yara, IronPort, and Firepower.
  • Strong understanding of networking (TCP Flags, TCP Handshake, IP addressing, Firewalls, Proxy, IDS, IPS)
  • Ability to perform NetFlow / packet capture (PCAP) analysis
  • Information Technology security related certifications but not limited to: CompTIA A+, Network+, Security+, Linux, Cisco CCNA, MS (SC-*/AZ-*), AWS, CEH, CrowdStrike, Palo Alto Cortex XSIAM, CISSP, etc.

Preferred Skills:

  • Certification desired - SANS GCIA, GCED, GPEN, GCIH or similar industry
  • Experience working with or in any of the following:
  • Computer Incident Response Team CIRT/CSIRT.
  • Computer Emergency Response Team CERT.
  • Computer Security Incident Response Center CSIRC.
  • Degree in Computer Science, Information Security or similar discipline.

Joining DXC connects you with brilliant people who embrace change and seize opportunities to advance their careers and amplify client success. At DXC, we support each other and work as a team, globally and locally. Our achievements demonstrate how we deliver excellence to our clients and colleagues. You will join a team committed to creating a culture of learning, diversity, and inclusion, dedicated to strong ethics and corporate citizenship.

At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

SOC Tier 3 Analyst
SOC Tier 3 Analyst

DXC Technology • Santiago

Sur place
CLP 25 000 000 - 40 000 000
Senior SOC Tier 3 Analyst & Incident Response Engineer
Senior SOC Tier 3 Analyst & Incident Response Engineer

dxctechnology • Santiago

Sur place
CLP 12 000 000 - 24 000 000
Senior SOC Analyst - Tier 3 Threat Detection & Response
Senior SOC Analyst - Tier 3 Threat Detection & Response

DXC Technology • Santiago

Sur place
CLP 25 000 000 - 40 000 000
CloudOps Analyst – Cloud Engineering
CloudOps Analyst – Cloud Engineering

dxctechnology • Santiago

Sur place
CLP 22 320 000 - 40 176 000
CloudOps Analyst – Cloud Engineering
CloudOps Analyst – Cloud Engineering

CLES Enterprise Services Chile Comercial Limitada • Santiago

Sur place
CLP 68 160 000 - 116 845 000
CloudOps Analyst – Cloud Engineering
CloudOps Analyst – Cloud Engineering

DXC Technology • Santiago

Sur place
CLP 24 000 000 - 42 000 000
Network Engineer
Network Engineer

dxctechnology • Santiago

Sur place
CLP 25 000 000 - 40 000 000
Senior ServiceNow Technical Consultant / Tech Lead
Senior ServiceNow Technical Consultant / Tech Lead

DXC Technology • Santiago

Sur place
CLP 28 000 000 - 46 000 000
Network Engineer – Wireless (Cisco Meraki / Cisco ISE)
Network Engineer – Wireless (Cisco Meraki / Cisco ISE)

DXC Technology • Santiago

Sur place
CLP 401 760 000 - 535 680 000
Senior ServiceNow Technical Consultant / Tech Lead
Senior ServiceNow Technical Consultant / Tech Lead

DXC Technology Inc. • Santiago

Hybride
CLP 60 000 000 - 95 000 000