Senior Threat Detection & Response Analyst — CSOC

Novartis

Ciudad de México

Híbrido

MXN 700.000 - 1.000.000

Jornada completa

Hace 2 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Transforma esta oferta en una entrevista: un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Descripción de la vacante

Novartis in Mexico City is seeking a Threat Detection & Response Senior Specialist to join the CSOC, focusing on real-time monitoring, incident response, and strategic threat mitigation. You will collaborate with technical and business stakeholders to analyze threats, coordinate investigations, and implement robust security playbooks.

The role requires 3+ years in cybersecurity, hands-on incident response experience, and strong SIEM/EDR skills.

Formación

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience.
  • 3+ years of experience in cybersecurity, with significant experience in incident response, threat detection, or security operations.
  • Strong hands-on experience investigating and responding to security incidents in enterprise environments.
  • Deep understanding of attacker techniques across endpoint, identity, network, cloud, and email attack surfaces.
  • Experience working in a CSOC, SOC, or incident response function in a large, complex organization.
  • Strong knowledge of security operations workflows, alert triage, escalation management, and response coordination.
  • Experience with SIEM, EDR/XDR, email security, identity monitoring, case management, and other security operations technologies.
  • Ability to analyze logs, alerts, and forensic artifacts to determine scope, impact, and response actions.
  • Strong written and verbal communication skills, with the ability to clearly brief both technical teams and senior stakeholders.
  • Proven ability to identify operational improvement opportunities and drive meaningful enhancements without direct people management responsibility.

Responsabilidades

  • Security Monitoring and Triage: monitor in real time security controls and consoles from across the Novartis IT ecosystem.
  • Forensics and Incident Response: support incident response activities including scoping, communication, reporting, and long term remediation planning, conduct initial investigations into security incidents involving a variety of threats.
  • Communicate with technical and non-technical end users who report suspicious activity, prepare technical reports for business stakeholders and IT leadership.
  • Gather live evidence from endpoint devices and log sources from a variety of systems and applications.
  • Big Data analysis and reporting: Utilizing SIEM/Big data to identify abnormal activity and extract meaningful insights; Research, develop, and enhance content within SIEM and other tools.
  • Technologies and Automation: Interface with engineering teams to design, test, and implement playbooks, orchestration workflows and automations; Research and test new technologies and platforms; develop recommendations and improvement plans.
  • Day to day: Perform host based analysis, artifact analysis, network packet analysis, and malware analysis in support of security investigations and incident response; Coordinate investigation, containment, and other response activities with business stakeholders and groups; Develop and maintain effective documentation; including response playbooks, processes, and other supporting operational material.
  • Perform quality assurance review of analyst investigations and work product; develop feedback and development reports; Develop incident analysis and findings reports for management, including gap identification and recommendations for improvement; Recommend or develop new detection logic and tune existing sensors / security controls.
  • Provide mentoring of junior staff and serve as point of escalation for higher severity incidents.
  • Work with security solutions owners to assess existing security solutions array ability to detect / mitigate the abovementioned TTPs

Conocimientos

Incident response
Threat detection
Security operations
SIEM
EDR/XDR
Communication

Educación

Bachelor's degree in Cybersecurity/related field

Herramientas

SIEM tools
EDR/XDR platforms
Forensic tools

Descripción del empleo

Novartis in Mexico City is seeking a Threat Detection & Response Senior Specialist to join the CSOC, focusing on real-time monitoring, incident response, and strategic threat mitigation. You will collaborate with technical and business stakeholders to analyze threats, coordinate investigations, and implement robust security playbooks.

The role requires 3+ years in cybersecurity, hands-on incident response experience, and strong SIEM/EDR skills.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Threat Detection & Response Specialist
Senior Threat Detection & Response Specialist

Novartis México • Ciudad de México

Híbrido
MXN 900.000 - 1.100.000
Senior Cyber Threat Detection & Response Specialist
Senior Cyber Threat Detection & Response Specialist

Novartis • Guamúchil

Híbrido
MXN 900.000 - 1.200.000
Threat Detection & Response Senior Specialist
Threat Detection & Response Senior Specialist

Novartis • Guamúchil

Híbrido
MXN 900.000 - 1.200.000
Threat Detection & Response Senior Specialist
Threat Detection & Response Senior Specialist

Novartis • Ciudad de México

Híbrido
MXN 700.000 - 1.000.000
SOC Analyst: Threat Detection, Incident Response & SIEM
SOC Analyst: Threat Detection, Incident Response & SIEM

Powerofconcord • Ciudad de México

Presencial
MXN 689.000 - 1.120.000
Grocery Vouchers
Internet Bonus
Medical Insurance
+3
Senior SOC Analyst: Threat Detection & Response
Senior SOC Analyst: Threat Detection & Response

Arcadion • Polanco (Ranchería Mineral Polanco)

Presencial
MXN 300.000 - 400.000
Competitive compensation
Modern, innovation-driven culture
Opportunities for career growth
SOC Analyst (Intermediate) - Incident Response & Detection
SOC Analyst (Intermediate) - Incident Response & Detection

Deutsche Telekom AG • Ciudad de México

Presencial
MXN 500.000 - 700.000
SOC Analyst: 24/7 Global Security Monitoring & Response
SOC Analyst: 24/7 Global Security Monitoring & Response

IDR, Inc. • Monterrey

Presencial
MXN 300.000 - 360.000
Competitive pay
Full benefits
SOC Analyst
SOC Analyst

IDR, Inc. • Monterrey

Presencial
MXN 300.000 - 360.000
Competitive pay
Full benefits
Cortex XSIAM SOC Analyst — Threat Detection & Incident Response
Cortex XSIAM SOC Analyst — Threat Detection & Incident Response

Tata Consultancy Services • Santiago de Querétaro, Región Centro, Monterrey

Presencial
MXN 420.000 - 660.000
Direct contract