We’re currently looking for a Senior Cyber Security Analyst (Remote) to join our InfoSec Offensive Vulnerability Management, Threat Intelligence, Application Code Scanning, Penetration Testing team in Mexico City or Aguascalientes. This role involves supporting all areas of threat intelligence to help inform and defend the business, protect brand reputation, and manage vulnerability and risk exposure across enterprise-wide technical systems. Responsibilities include asset identification, reporting, remediation, and continuous assessment.
Job Duties:
- Manage vulnerabilities across applications, endpoints, databases, networking devices, and mobile, cloud, and third-party assets.
- Conduct continuous discovery and vulnerability assessments of enterprise-wide assets.
- Document, prioritize, and report asset and vulnerability status, along with remediation recommendations and validation.
- Communicate vulnerability results effectively to technical and non-technical stakeholders, considering risk tolerance and business impact.
- Procure and maintain tools and scripts used in asset discovery and vulnerability assessment.
- Utilize vulnerability databases to understand weaknesses, likelihood, and remediation options, including vendor fixes and workarounds.
- Perform tactical assessments involving social engineering, application security (web and mobile), physical security, lateral movement, threat analysis, and network architecture.
- Develop and maintain tools and scripts for penetration testing and red team activities.
- Support purple team exercises to enhance team collaboration and security posture.
- Collaborate with the security operations center (SOC) to leverage intelligence, identify threats, and verify security measures.
- Work with infrastructure teams to support remediation efforts and verify security improvements.
- Continuously research new TTPs and assess risks to implement or validate controls.
- Maintain an active database of third-party assets, vulnerabilities, remediation, and overall security posture.
Skills and Experience:
- 5+ years in information security, offensive tactics, monitoring, and incident response.
- Proficient in scripting languages such as Python, PowerShell, Bash, and Ruby.
- Experience with testing frameworks and tools like Burp Suite, Cobalt Strike, Kali Linux, Nessus, and PowerShell Empire.
- Experience conducting penetration tests or red team engagements.
- Strong knowledge of operating systems (*nix, Windows, Mac) and networking protocols.
- Experience with vulnerability management solutions like Qualys, Nessus, Kenna Security, Tanium, and open source tools.
- Experience with system hardening and security best practices.
- Understanding of Windows and *nix OS, endpoint applications, networking, and cloud platforms (AWS, Azure, GCP) is preferred.
- Ability to perform organization-wide vulnerability scanning and remediation.
- Ability to maintain persistence within systems while avoiding detection.
- Familiarity with security technologies such as IPS/IDS, SIEM, firewalls, EPP, EDR, and UEBA.
- Knowledge of OWASP, MITRE ATT&CK framework, and SDLC.
Education:
Bachelor's degree in a related discipline or equivalent work experience.