Information Security Analyst

External Posting

Bogotá ciudad

Híbrido

COP 105.862.000 - 172.026.000

Jornada completa

Hace 4 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico — crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Remote/hybrid flexibility
Professional growth
Work-life balance

Descripción de la vacante

Rainforest Alliance is seeking an experienced Information Security Analyst to join our Global Technology team. You will protect our digital assets, respond to security incidents, and drive continuous improvement of our security posture across Azure, Entra ID, M365, and related services.

The role includes vulnerability management, security documentation, risk assessments, and collaborating with IT teams to embed security into design and operations.

Formación

  • Minimum of 3 years of hands-on experience in an information security role.
  • Experience with Azure security services and best practices.
  • Experience with Entra ID (Azure Active Directory) and Microsoft 365 security administration.
  • Experience with endpoint hardening methodologies and implementation.
  • Hands-on administration of CrowdStrike Falcon platform.
  • Experience with security incident response and threat hunting.
  • Experience with networking concepts.
  • Familiarity with security frameworks (e.g., Cyber Essentials, NIST, ISO 27001).

Responsabilidades

  • Participate in security incident response activities, including investigation, containment, eradication, recovery, and post-incident analysis.
  • Monitor security alerts from SIEM, EDR, and cloud logs, responding to incidents promptly.
  • Develop and maintain security documentation, procedures, runbooks, and incident response plans.
  • Conduct vulnerability assessments and support remediation efforts.
  • Contribute to security awareness training for employees and ensure security is integrated into infrastructure and applications.
  • Lead risk assessments and participate in security design reviews.
  • Administer and configure Azure security services and monitor environments for threats and misconfigurations.
  • Lead Entra ID security management including MFA and CA policies.

Conocimientos

Azure security practices
Entra ID (Azure AD)
Microsoft 365 security administration
Endpoint hardening
Threat hunting
Incident response
Networking concepts
Cybersecurity frameworks

Herramientas

CrowdStrike Falcon
Azure Defender/ Defender for Cloud

Descripción del empleo

POSITION SUMMARY

POSITION: Information Security Analyst


LOCATION: We will only consider candidates legally authorized to work in Colombia or Guatemala.


WORKPLACE TYPE: Flexible hybrid working environment


CLOSING DATE: 09 October 2026


JOB LEVEL: 14


We are looking for an experienced Information Security Analyst to join our security team. You will help protect our digital assets, detecting and responding to security incidents, and ensuring the continuous improvement of our security posture. You will identify security risks, develop, and implement security frameworks, and ensure the integrity of our IT systems and data. You will be responsible for all goals related to cyber security. Rainforest Alliance will expect you to coordinate implementation of all information security related processes together with others. You will also handle and coordinate task/activities by firms/individuals contracted to provide information security services, working to ensure peers, senior and junior colleagues deliver necessary environment improvements effectively and expediently. You will have a strong technical background, with confirmed hands‑on experience securing Microsoft cloud environments, including Azure, Entra ID, Microsoft 365, Purview, and Defender Suite. Additionally, they will have experience implementing endpoint hardening strategies and using advanced security tools. The Information Security Analyst will report to the Global Technology Director.


WHAT YOU WILL DO:

Security Operations & Incident Response:

Participate in security incident response activities, including investigation, containment, eradication, recovery, and post-incident analysis.


Monitor security alerts from different sources (SIEM, EDR, cloud logs) and respond to security incidents promptly.


Develop and maintain security documentation, including procedures, runbooks, and incident response plans.


Conduct vulnerability assessments and support penetration testing remediation efforts.


Security Awareness & Training:

Contribute to the development and delivery of security awareness training for employees, being a domain authority for security best practices.


Work with all IT teams to ensure security is integrated into all aspects of our infrastructure and applications at the design and requirements stage.


Find opportunities for automation and improvement of Rainforest Alliance security posture, including exception handling of threat alerts, patches, system and software vulnerabilities.


Reporting:

Create weekly and monthly reporting packs, demonstrating rolling position on vulnerabilities, threats, progress against plan on important security initiatives.


Conduct risk assessments and participate in security design reviews.


Administer and configure Azure security services (e.g., Azure Security Centre/Defender for Cloud, Defender for Endpoint, Azure Network Security Groups, Azure Key Vault, Azure Firewall).


Monitor Azure environments for security threats, vulnerabilities, and misconfigurations.


Make sure security best practices within Azure IaaS and PaaS deployments, audit Azure resources for compliance.


Lead and secure Entra ID (Azure Active Directory) including Conditional Access Policies, Multi‑Factor Authentication (MFA), Identity Governance, and Privileged Identity Management (PIM).


Monitor Entra ID for suspicious activity and unauthorised access attempts.


Microsoft 365 Administration & Security:

Secure Microsoft 365 services (Exchange Online, SharePoint Online, OneDrive, Teams), looking after user access, data governance, and threat protection within the Microsoft 365 ecosystem.


Configure and improve Microsoft 365 security features (e.g., Defender for Office365, Data Loss Prevention (DLP), Microsoft Purview + compliance policies).


Develop, implement, and maintain security baselines and hardening standards for endpoints (Windows, macOS, Linux).


Configure and handle Microsoft Entra Domain Services based Group Policies (GPOs) and equivalent Mobile Device Management (MDM) solutions for security settings.


Ensure secure configuration and patch management across all endpoints.


XDR:

Administer, configure, and optimise our XDR service, currently Crowdstrike Falcon but planned for migration to Microsoft Defender XDR.


Monitor alerts and dashboards for endpoint security incidents and threats, perform threat hunting and incident response activities using CrowdStrike data.


Develop and refine custom detections and response playbooks within CrowdStrike.


Vulnerability Scanning:


  • Identify and prioritise remediation of CVE-aligned vulnerabilities

  • Provide reporting to IT leadership on progress against remediation targets

  • Notify IT teams of new high/critical vulnerabilities and coordinate remediation planning

  • Design reporting dashboards for senior IT leadership


WHAT YOU BRING:

Minimum of 3 years of hands‑on experience in an information security role.


Experience with Azure security services and best practices.


Experience with Entra ID (Azure Active Directory) and Microsoft 365 security administration.


Experience with endpoint hardening methodologies and implementation.


Hands‑on administration and operational experience with CrowdStrike Falcon platform.


Experience with security incident response and threat hunting.


Experience with networking concepts.


Familiarity with security frameworks (e.g., Cyber Essentials, NIST, ISO 27001).


BENEFITS OF WORKING AT THE RAINFOREST ALLIANCE:

Be a part of a global organization with an impactful mission and a collaborative, respectful, and accountable culture.


Enjoy opportunities for professional growth and career development.


Benefit from remote working flexibility and flexible hybrid working environment.


Prioritize your wellbeing. We have numerous ways to promote work-life balance.


If you have any questions about the job vacancy, please contact the HR department: recruitment@ra.org The Rainforest Alliance encourages diversity and inclusion across the global organization. With this commitment to diversity, we are proud to be an equal opportunity employer and do not discriminate on the basis of gender, race, color, ethnicity, religion, sexual orientation, gender identity, ages, disability and any other protected group.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Hybrid Information Security Analyst: Azure & Threat Response
Hybrid Information Security Analyst: Azure & Threat Response

External Posting • Bogotá ciudad

Híbrido
COP 105.862.000 - 172.026.000
Remote/hybrid flexibility
Professional growth
Work-life balance
Ingeniero/a de senior de GRC
Ingeniero/a de senior de GRC

GMV • Bogotá

Presencial
COP 133.920.000 - 178.560.000
Hybrid working model
8 weeks remote work per year
Flexible working hours
+3
Operations Specialist
Operations Specialist

The Nature Conservancy • Antioquia

Presencial
COP 13.680.000 - 18.508.000
Health care benefits
401(k) with 8% employer match
Parental leave
+4
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Orbia • Colombia

Presencial
COP 90.000.000 - 150.000.000
Security Consultant - TDR - SOAR Engineer
Security Consultant - TDR - SOAR Engineer

IBM • Bogotá ciudad

Presencial
COP 108.000.000 - 180.000.000
Consultant (m/f/d) - Cost-Benefit Analysis for Mangrove-Based Adaptation Projects
Consultant (m/f/d) - Cost-Benefit Analysis for Mangrove-Based Adaptation Projects

FORLIANCE GmbH • San Andrés

A distancia
COP 133.920.000 - 223.200.000
Travel & fieldwork costs covered
[Job-32034] Senior GRC Security Specialist, Colombia
[Job-32034] Senior GRC Security Specialist, Colombia

Lever, Inc. • Colombia

A distancia
COP 120.000.000 - 180.000.000
Premium Healthcare
Meal voucher
Maternity and Parental leaves
+5
Specialist II, Application Security (TCF)
Specialist II, Application Security (TCF)

cnx • Bogotá ciudad

A distancia
COP 54.000.000 - 76.000.000
Remote work
Technical Advisor – Environmental (Facilitator) in Colombia | Deadline September 27, 2026
Technical Advisor – Environmental (Facilitator) in Colombia | Deadline September 27, 2026

NBSAP Accelerator Partnership • Bogotá ciudad

Presencial
COP 217.526.000 - 341.827.000
CyberSecurity Manager
CyberSecurity Manager

Lean Tech • Norte

Presencial
COP 280.260.000 - 467.101.000