9 дней назад
Security Consultant (SOC IR L3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Consultant (SOC IR L3) (Cybersecurity): Handling complex cybersecurity incidents and leading investigations and remediation across the full incident response lifecycle with an accent on SIEM, EDR, host-based and network-based forensics. Focus on memory investigation, malicious code analysis, intrusion assessment, and improving SOC procedures and security posture.
Location: Bogotá, Colombia
Company
Scientific is an international life sciences company providing analytical testing, laboratory, and clinical diagnostic services across multiple industries.
What you will do
- Perform triage and in-depth investigation of cybersecurity events using SIEM, IDS, EDR, antivirus, internet footprint, proxy, and firewall tools.
- Correlate security events, assess business risk, and analyze successful and unsuccessful intrusion attempts.
- Lead security incidents across the full incident response lifecycle and coordinate remediation with Security and IT teams.
- Conduct host-based, network-based, memory, and malicious code forensic investigations.
- Develop and maintain SOC procedures and processes while improving the organization’s security posture.
- Protect sensitive information and communicate technical findings effectively to IT personnel and management.
Requirements
- At least 5 years of professional experience as a SOC Analyst, threat researcher, threat hunter, or in a comparable incident-handling role.
- Experience leading security incident response and managing cybersecurity cases.
- Strong knowledge of attack vectors and attack types.
- Knowledge of forensic data acquisition and host- and network-based forensic analysis.
- Strong troubleshooting, reasoning, analytical, communication, and multitasking skills.
- Ability to work independently, take ownership, and collaborate effectively with security and IT teams.
Culture & Benefits
- Good working environment.
- Opportunities for professional growth and development.
- Lunch and transportation included.
- Willingness to work overtime and respond to critical L3 incident escalations is expected.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →