Cybersecurity Analyst - Threat Hunter

Kohler Co.

Ciudad Juárez

Presencial

MXN 400.000 - 800.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Kohler Co. is seeking a SOC Analyst / Threat Hunter to strengthen detection, investigation, and response capabilities across the enterprise.

This hybrid role is based in the Juarez area, Mexico, and involves working with SIEM, EDR, and cloud security signals. You will perform proactive threat hunting, develop hypotheses aligned with MITRE ATT&CK, and refine detections to reduce false positives while increasing coverage.

Formación

  • /Bachelor’s degree in Information Security, Computer Science, or equivalent experience/
  • /Security certifications (GIAC/SANS, GCIA, GNFA, OSCP, or similar) beneficial but not required/
  • /2+ years in a SOC or threat-focused security role with threat hunting exposure/

Responsabilidades

  • Monitor, triage, and investigate security alerts across endpoints, identity, network, cloud, and SaaS environments.
  • Lead and support incident investigations with clear timelines and containment actions.
  • Develop structured queries and analysis mapped to MITRE ATT&CK for hunts.
  • Tune detections to reduce false positives and improve telemetry.
  • Contribute to SOC playbooks and automation to speed responses.

Conocimientos

SIEM analysis
EDR tooling
Threat hunting
Cloud/SaaS security
Analytical mindset
AI-assisted security tooling
Scripting (KQL, SPL, Python)

Educación

Bachelor’s degree in Information Security/CS

Herramientas

SIEM platforms
EDR tools (Palo Alto, Rapid, Microsoft)
Cloud security signals
Threat intel tooling

Descripción del empleo

Opportunity

Kohler Co. is seeking a SOC Analyst / Threat Hunter to strengthen detection, investigation, and response capability across the enterprise.

Location: Hybrid, Juarez Nuevo León

Work Mode: Hybrid, Juarez, Nuevo León

Key Responsibilities

This role operates within standard business hours with an on-call rotation.

Detection & Incident Response

Monitor, triage, and investigate security alerts across endpoint, identity, network, cloud, and SaaS environments—moving quickly from initial signal to understanding scope and impact.

Lead and support incident investigations by developing clear timelines, identifying affected assets, and driving toward containment.

Execute and oversee containment and response actions (including via automated and agentic workflows) in line with established playbooks, using sound judgment when situations fall outside defined procedures.

Produce clear, concise documentation of investigations and incidents to support post-incident review and continuous improvement.

Threat Hunting

Perform proactive, hypothesis-driven threat hunting based on attacker techniques, observed behavior, and current threat intelligence.

Develop and test hunt hypotheses mapped to MITRE ATT&CK (or equivalent frameworks), translating them into structured queries and analysis.

Identify weak signals and suspicious patterns that fall below existing detection thresholds.

Feed hunt findings back into detection engineering—improving rule quality and closing visibility gaps over time.

Detection & Signal Improvement

Assist with tuning and improving SIEM and EDR detections.

Reduce false positives while strengthening high-confidence alerts.

Work with architecture and engineering teams to improve telemetry and visibility.

Attacker & TTP Awareness

Actively follow the evolving threat landscape, including emerging attacker tooling, techniques, and campaigns, and bring relevant intelligence into day-to-day detection and hunting activity.

Map detections and hunts to real-world attack behavior.

Proactively identify and prioritize detection gaps based on current threat actor behavior.

Operational Maturity

Contribute to the development and refinement of SOC procedures and playbooks.

Contribute to automation and orchestration efforts to improve response speed and consistency.

Provide operational feedback to improve security architecture and tooling decisions.

Experience & Skills

2+ years of experience in a SOC or threat-focused security role, with demonstrable exposure to proactive threat hunting and a clear drive to develop further in that discipline.

Hands-on experience with:

  • SIEM platforms and log analysis.
  • Endpoint detection and response (EDR) tools(Palo, Rapid, Microsoft).
  • Identity-based attacks and lateral movement techniques.
  • Cloud and SaaS security signals.
  • Strong analytical and investigative mindset.
  • Able to work effectively in fast-moving and evolving environments.
  • Hands-on experience working with AI-assisted security tooling, with a drive to build and mature agentic workflows that automate detection, investigation, and response activity at scale.
  • Query and scripting languages relevant to security analysis (KQL, SPL, or Python).
Education & Certifications (Preferred)

Bachelor’s degree in Information Security, Computer Science, or equivalent experience.

Security certifications (GIAC/SANS, GCIA, GNFA, OSCP, or similar) are beneficial but not required.

Why Choose Kohler?

We empower each associate to #BecomeMoreAtKohler with a competitive total rewards package to support your health and wellbeing, access to career growth and development opportunities, a diverse and inclusive workplace, and a strong culture of innovation. With more than 30,000 bold leaders across the globe, we’re driving meaningful change in our mission to help people live gracious, healthy, and sustainable lives.

About Us

It is Kohler’s policy to recruit, hire, and promote qualified applicants without regard to race, creed, religion, age, sex, sexual orientation, gender identity or expression, marital status, national origin, disability or status as a protected veteran. If, as an individual with a disability, you need reasonable accommodation during the recruitment process, please contact kohlerjobs@kohler.com . Kohler Co. is an equal opportunity/affirmative action employer.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Hybrid Threat Hunter & SOC Analyst
Hybrid Threat Hunter & SOC Analyst

Kohler Co. • Ciudad Juárez

Híbrido
MXN 400.000 - 800.000
Manager, Cybersecurity Threat Intelligence - Advanced English
Manager, Cybersecurity Threat Intelligence - Advanced English

KTSA - KPMG Technology Services Americas • México

Híbrido
MXN 1.455.000 - 1.820.000
Extended maternity, paternity, and adoption leaves
Learning opportunities, training, and certification programs
Comprehensive medical plan and life insurance
Threat Detection & Response Senior Specialist
Threat Detection & Response Senior Specialist

Healthcare Businesswomen’s Association • Ciudad de México

Híbrido
MXN 480.000 - 720.000
SOC Analyst Consultant (CrowdStrike Experience) - Remote (Mexico) Posted on Aug 06 / 2026
SOC Analyst Consultant (CrowdStrike Experience) - Remote (Mexico) Posted on Aug 06 / 2026

EmergencyMD • México

Híbrido
MXN 600.000 - 900.000
Private medical insurance
Life insurance
Christmas bonus and technology stipend
+3
Sr Cyber Security Architect/Engineer
Sr Cyber Security Architect/Engineer

Resideo • Chihuahua

Híbrido
MXN 600.000 - 900.000
SOC Analyst Consultant (CrowdStrike Experience) - Remote (Mexico)
SOC Analyst Consultant (CrowdStrike Experience) - Remote (Mexico)

Echelon Risk + Cyber • México

Híbrido
PHP 1.487.000 - 1.912.000
Access to private medical insurance
Life insurance via MetLife
30-day Christmas bonus and a monthly技术
+3
SOC Analyst – CrowdStrike / Cybersecurity Specialist
SOC Analyst – CrowdStrike / Cybersecurity Specialist

Arcadion • Polanco (Ranchería Mineral Polanco)

Presencial
MXN 300.000 - 400.000
Competitive compensation
Modern, innovation-driven culture
Opportunities for career growth
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Dematic • Guadalupe

Presencial
MXN 700.000 - 1.000.000
Career Development
Competitive Compensation and Benefits
Pay Transparency
+1
Senior Cyber Security Incident Responder
Senior Cyber Security Incident Responder

ZEISS Group • Ciudad de México

Presencial
MXN 1.254.255 - 1.612.614
Digital Product Delivery Manager
Digital Product Delivery Manager

Kohler Co. • Benito Juárez

Presencial
MXN 2.083.000 - 2.778.000
Health & wellbeing benefits
Career growth opportunities
Inclusive workplace
+1