Remote SOC Analyst Consultant – MDR & Falcon Expert

EmergencyMD

Ciudad de México

A distancia

MXN 360.000 - 600.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Private medical insurance
Annual performance bonus
Remote work from Mexico
Professional development

Descripción de la vacante

Echelon Risk + Cyber is seeking a seasoned SOC Analyst, Consultant to lead MDR/SOC investigations across client environments in a remote Mexico setting.

You will own Tier 2/3 investigations, tune detections across SIEM/EDR, and develop playbooks to mature the service. Strong telemetry, cloud and identity protection experience is preferred, with English communication required. This role offers exposure to cutting-edge security operations and opportunities to mentor analysts.

Formación

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related discipline, or equivalent professional experience.

Responsabilidades

  • Own Tier 2 and Tier 3 investigations escalated from frontline triage: establish scope and root cause, identify affected hosts, users, and identities, and drive containment, eradication, and recovery.
  • Perform hands-on endpoint investigation and response in EDR/MDR platforms - process and telemetry analysis, remote host triage, artifact collection, host isolation, and analysis of malicious binaries and scripts.
  • Investigate identity and cloud detections across Microsoft 365, Entra ID, Active Directory, AWS, and Azure, including business email compromise, token and session theft, MFA abuse, and privilege escalation.
  • Triage and investigate email security alerts - phishing and BEC analysis, header, URL, and attachment inspection, tenant-wide message trace and remediation, and mail flow and policy recommendations.
  • Review vulnerability scanning and exposure management output, validate findings, and help clients prioritize remediation based on exploitability, exposure, and business context.
  • Write, test, and tune detection content across SIEM and EDR - correlation rules, custom detections, exclusions, and suppression logic - and track the effect on alert quality and false positive rates.
  • Build and maintain automation and SOAR playbooks that take repetitive work out of the triage queue.
  • Run threat hunts using threat intelligence, IoC data, and adversary TTPs mapped to MITRE ATT&CK, and convert hunt findings into durable detections.
  • Document the full incident lifecycle, including root cause analysis and actions taken, and produce clear reports and recommendations for both technical and executive audiences.
  • Serve as the escalation point for confirmed incidents, coordinating with client IT and security teams, Echelon's incident response and offensive security practices, and third parties through to resolution.
  • Support the growth of the Managed SOC/MDR service - standard operating procedures and runbooks, client and platform onboarding, configuration and tuning, quality review of frontline work, and mentoring and training analysts.
  • Participate in after-hours and on-call rotations for SOC alert escalation and response requirements.

Conocimientos

SOC analyst
SIEM
Email security
Vulnerability management
Scripting
Threat intelligence
Identity & AD
Windows/Linux/macOS
Communication
English proficiency

Educación

Bachelor's degree or equivalent

Herramientas

CrowdStrike Falcon
Microsoft Defender for Office 365
Proofpoint
Mimecast
Tenable
Qualys
Rapid7
Splunk
Google Chronicle

Descripción del empleo

Echelon Risk + Cyber is seeking a seasoned SOC Analyst, Consultant to lead MDR/SOC investigations across client environments in a remote Mexico setting.

You will own Tier 2/3 investigations, tune detections across SIEM/EDR, and develop playbooks to mature the service. Strong telemetry, cloud and identity protection experience is preferred, with English communication required. This role offers exposure to cutting-edge security operations and opportunities to mentor analysts.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí