- Location
- Santurce - Lucchetti, United States of America
- Type
- Full-time
- Experience
- 8+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- Workday
Description
Job Summary:
Supports the protection of critical IT and OT environments by triaging alerts, investigating threats, and enhancing defensive capabilities that uphold confidentiality, integrity, and availability standards. Ensures continuous operational readiness through coordinated incident response and proactive threat hunting, driving measurable improvements in the organization’s overall security posture.Job Description:
Triage security alerts to determine root cause and prioritize incident handling, ensuring timely and accurate escalation aligned with SOC response standards.
Investigates suspicious activity across SIEM, email, and network telemetry to validate threats and produce evidence-based findings that support rapid containment.
Collaborates with cross-functional cybersecurity teams to coordinate incident response actions and achieve complete resolution and documented lessons learned in accordance with established protocols.
Conducts proactive threat hunting and intelligence analysis to identify emerging risks and deliver actionable reports that strengthen LUMA’s preventive security posture.
Supports vulnerability assessment and defense architecture reviews to recommend improvements that ensure alignment with critical infrastructure protection standards.
Maintains and enhances operational playbooks, detection rules, and SOPs to ensure consistent, compliant, and up-to-date defensive capabilities across the organization.
Participates in on-call and rotating coverage to ensure continuous SOC operational readiness and consistent 24/7 incident response support.
Follows established company policies, procedures, and standards to ensure full compliance with applicable laws and industry regulations.
Participates in storm restoration tasks and assigned drills to contribute to the safe and reliable recovery of services.
Performs additional tasks aligned with role expectations and qualifications to support team goals and operational flexibility.
Additional Job Description:
Education
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Assurance, or related field.
Experience
5 years of relevant cybersecurity experience, preferably in a SOC, cyber defense operations, or incident analysis role.
Hands-on experience with SIEM platforms (Sumo Logic or equivalent), EDR (CrowdStrike or equivalent), and security monitoring tools.
Additional experience may substitute for required education when it aligns with the competencies and knowledge necessary for the role:
Associate’s degree in Cybersecurity, Computer Science, Information Technology, Information Assurance may substitute when accompanied by a minimum of 8 years of experience performing similar functions and at least 3 years of experience performing a previous position as Specialist role.
High School or equivalent (GED) when accompanied by a minimum of 10 years of experience performing similar functions described and at least 5 years of experience performing a previous Specialist role.
Competencies (Skills)
Networking & Traffic Analysis: Demonstrates strong understanding of TCP/IP, common protocols, firewall and VPN technologies, IDS/IPS systems, and the ability to analyze logs, review network traffic, and correlate security events.
Operating Systems, Scripting & Forensics: Applies working knowledge of Windows and Linux OS environments, basic scripting in Python, PowerShell, or Bash, and foundational malware and digital forensics concepts.
Cybersecurity Frameworks: Understands and applies cybersecurity frameworks such as NIST CSF, MITRE ATT&CK, and ISO 27001, along with defense‑in‑depth principles.
Event Analysis & Security Monitoring: Possesses the ability to analyze logs, correlate events, and identify suspicious activity using technical knowledge and monitoring techniques.
Analytical & Communication Skills: Demonstrates strong analytical and problem‑solving abilities, clear written and verbal communication in Spanish and English, attention to detail, teamwork, and high ethical standards under pressure.
Licenses/Certifications
At least one professional certification (or demonstrable equivalent):
CompTIA Security+ (or higher).
CySA+, or equivalent.
CISSP, CEH, GCIA, GCIH, or GSEC is strongly valued.
Travel Requirements
Not required
Physical Demands
Stationary Position: Constantly
Pushing/ Pulling/ Reaching: Seldom
Kneel: Seldom
Grab: Seldom
Bend: Seldom
Lift/Carry over: 0 - 15 lbs.
Working Conditions
Wet or humid: Never
Working near or on moving mechanical parts: Never
Working near or on heavy machinery: Never
Working in high places: Never
Exposed to fumes or airborne particles: Never
Frequency of working in outdoor weather conditions: Never
Work with electricity: Never
Loud noise conditions: Seldom
LUMA Energy is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, military status, disability, or any other characteristic protected by federal or local laws.