SOC Cortex XSIAM Analyst

Tata Consultancy Services

Jalisco

Presencial

MXN 420.000 - 660.000

Jornada completa

Hace 9 días
Generador de candidaturas

Destaca para este puesto: genera un currículum y una carta de presentación adaptados en cuestión de un minuto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Direct contract

Descripción de la vacante

Tata Consultancy Services is seeking a SOC Cortex XSIAM Analyst to monitor, investigate, and respond to cybersecurity threats using Cortex XSIAM within the iSOC. The role requires hands-on incident handling, strong English communication, and the ability to work in a 24x7 rotation.

Candidates should be willing to relocate to Querétaro, CDMX, Guadalajara or Monterrey and attend the office multiple days per week. Excellent collaboration across global teams is essential.

Formación

  • 2-4 years of experience in SOC operations, XDR, SIEM, or incident response.
  • Experience with Cortex XSIAM and Cortex XDR strongly preferred.
  • Knowledge of MITRE ATT&CK and NIST 800-61 is a plus.
  • Foundational network knowledge (TCP/IP, DNS, HTTP/S) and Windows/Linux/AD basics.

Responsabilidades

  • Perform continuous monitoring of security alerts and incidents through Cortex XSIAM.
  • Analyze and correlate telemetry from endpoints, networks, and cloud platforms.
  • Triage alerts, determine validity, scope, business impact, and escalation needs.
  • Reduce false positives by tuning and documenting evidence-based recommendations.
  • Escalate incidents to L2/L3 per playbooks and escalation matrices.
  • Execute approved containment or response actions, including automated actions where allowed.
  • Maintain accurate incident records, notes, evidence, timestamps, and handovers in ServiceNow.
  • Provide clear shift handovers and support follow-the-sun continuity.

Conocimientos

Advanced English
SOC operations
XDR experience
Incident response
Analytical thinking

Herramientas

Cortex XSIAM
Cortex XDR
Palo Alto Networks

Descripción del empleo

TCS is looking for a SOC Cortex XSIAM Analyst

(Candidate needs to be located or relocate to Querétaro, CDMX, Guadalajara or Monterrey, it will be requested to attend office at least 3 day per week)

Role Purpose

The SOC Cortex XSIAM Analyst monitors, investigates, and responds to cybersecurity threats using Palo Alto Networks Cortex XSIAM within Customer's global iSOC. The role uses XDR, automation, threat intelligence, and structured incident response practices to identify, contain, and mitigate threats while improving the quality, consistency, and efficiency of security operations.

Experience and Behavioral Competencies
  • Advance English communication
  • 2-4 years of experience in SOC operations, XDR, SIEM, or Incident Response, with experience calibrated to role seniority.
  • Practical Cortex XSIAM, Cortex XDR, or closely related Palo Alto security operations experience is strongly preferred.
  • Strong analytical thinking, disciplined documentation, customer focus, ownership, and attention to detail.
  • Clear written and verbal communication, collaboration across global teams, and composure during high-severity incidents.
  • Ability and willingness to work within an approved 24x7 rotational shift model.
Fundamental and Required Technical Skills
  • Hands-on security monitoring and incident investigation using Cortex XSIAM, Cortex XDR, or comparable enterprise XDR technology.
  • Understanding of SIEM/XDR concepts, alert triage, event correlation, investigation timelines, and evidence handling.
  • Working knowledge of MITRE ATT&CK and a structured Incident Response lifecycle; familiarity with NIST 800-61 is preferred.
  • Foundational knowledge of TCP/IP, DNS, HTTP/S, email security, firewalls, proxies, VPNs, and common network attack patterns.
  • Working knowledge of Windows, Linux, Active Directory, endpoint telemetry, authentication events, and privilege-related threats.
  • Experience creating and maintaining high-quality incident records in ServiceNow or a comparable ITSM platform.
  • Awareness of cloud security monitoring concepts across Azure, AWS, or GCP environments.
Core Operational Responsibilities
  • Perform continuous monitoring of security alerts, incidents, and events through Cortex XSIAM.
  • Analyze and correlate security telemetry from endpoints, networks, cloud platforms, identity services, and integrated security tools.
  • Triage alerts, determine validity, scope, business impact, and severity, and document the investigation rationale.
  • Reduce false positives by identifying tuning opportunities and providing evidence-based recommendations to the engineering team.
  • Escalate incidents to L2/L3, Major Incident Management, or other resolver groups according to playbooks and escalation matrices.
  • Execute approved containment or response actions, including automated actions where authorized by the applicable playbook.
  • Maintain accurate incident records, investigation notes, evidence, timestamps, ownership, and handover details in ServiceNow.
  • Provide clear shift handovers and support follow-the-sun continuity across global delivery locations.
What we offer to you:
  • Direct contract (indeterminate time with initial probation period)
  • Benefits of the law and above

Tata Consultancy Services is an equal opportunity employer, our commitment to diversity & inclusion drives our efforts to provide equal opportunity to all candidates who meet our required knowledge & competency needs, irrespective of any socio-economic background, race, color, national origin, religion, sex, gender identity/expression , age, marital status, disability, sexual orientation or any others. We encourage anyone interested to build a career in TCS to participate in our recruitment & selection process.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cortex XSIAM SOC Analyst — Threat Detection & Incident Response
Cortex XSIAM SOC Analyst — Threat Detection & Incident Response

Tata Consultancy Services • Santiago de Querétaro, Región Centro, Monterrey

Presencial
MXN 420.000 - 660.000
Direct contract
SOC Microsoft Sentinel Analyst
SOC Microsoft Sentinel Analyst

Tata Consultancy Services • Santiago de Querétaro, Región Centro, Monterrey

Híbrido
MXN 420.000 - 640.000
Direct contract (indeterminate time)
Legal benefits
SOC Analyst L2
SOC Analyst L2

adlytics GmbH • Santiago de Querétaro

Híbrido
Horario de Oficina
Nomina 100%
Prestaciones de Ley
+2
SOC Analyst – CrowdStrike / Cybersecurity Specialist
SOC Analyst – CrowdStrike / Cybersecurity Specialist

Arcadion • Polanco (Ranchería Mineral Polanco)

Presencial
MXN 300.000 - 400.000
Competitive compensation
Modern, innovation-driven culture
Opportunities for career growth
SOC Analyst
SOC Analyst

IDR, Inc. • Monterrey

Presencial
MXN 300.000 - 360.000
Competitive pay
Full benefits
SOC Analyst L2
SOC Analyst L2

Capital Empresarial Horizonte • Ciudad de México

Híbrido
Horario de oficina
Esquema 100% nómina
Prestaciones de ley
+1
SOC Analyst: Threat Detection, Incident Response & SIEM
SOC Analyst: Threat Detection, Incident Response & SIEM

Powerofconcord • Ciudad de México

Presencial
MXN 689.000 - 1.120.000
Grocery Vouchers
Internet Bonus
Medical Insurance
+3
Endpoint Engineering
Endpoint Engineering

Tata Consultancy Services • Santiago de Querétaro, Región Centro, Monterrey

Híbrido
MXN 420.000 - 660.000
Major Medical Insurance
Life Insurance
Grocery Vouchers
+3
SOC Analyst - Microsoft Sentinel (Hybrid: 3 days in-office)
SOC Analyst - Microsoft Sentinel (Hybrid: 3 days in-office)

Tata Consultancy Services • Santiago de Querétaro, Región Centro, Monterrey

Híbrido
MXN 420.000 - 640.000
Direct contract (indeterminate time)
Legal benefits
Security Monitoring Engineer
Security Monitoring Engineer

Bosal • Santiago de Querétaro

Presencial
MXN 600.000 - 900.000