- Location
- Mexico Polanco
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Security
- Experience
- 5+ years
- Source
- Workday
Description
Security Analyst
The Opportunity
As a Security Analyst, you will collaborate with a team of experienced security professionals to safeguard our corporate and production environments, leveraging advanced security tools and techniques to play a critical role in detecting, preventing, investigating, and responding to security threats and incidents.
As a first line of defense, you are expected to bring deep expertise across security operations, cloud security, DevSecOps, threat detection, and incident response, with strong hands-on experience in securing modern cloud-native environments. In addition, you will partner with cross-functional teams to provide security guidance, support, and training to strengthen our organization’s overall security posture.
This position requires participation in a shift rotation to support 24/7 security monitoring and incident response operations.
Responsibilities
Monitor, investigate, and triage security events to support and enhance threat modeling efforts
Proactively monitor cloud, network, endpoint to identify suspicious activity and emerging threats
Perform cloud security posture assessments, configuration reviews, policy enforcement, and continuous compliance monitoring across AWS, Azure, and GCP environments
Develop and maintain security alerts, log correlation rules, and dashboards using SIEM solution
Develop and implement security automation, detection engineering, and response workflows to improve operational efficiency and reduce manual effort
Configure, administer, and optimize security platforms including SIEM, CSPM, CNAPP, EDR/XDR, DLP, vulnerability management, and cloud security monitoring solutions
Conduct ongoing threat hunts and publish regular threat intelligence reports
Manage the InfoSec ticket queue, conduct investigations, and document resolutions
Review and evaluate vulnerability scan results and remediation efforts
Document, analyze, and escalate security incidents as needed
Collaborate with other business units to assess system configurations and ensure secure integration
Partner with internal stakeholders to define, develop, and implement security standards and best practices
Conduct quarterly security gap analyses and risk assessments
Conduct third-party security assessments for new and renewing vendors
Qualifications
5+ years of hands-on experience with major cloud service providers (e.g., AWS, Azure, GCP)
5+ years of hands-on experience with endpoint security and detection technologies such as Cortex XDR, CrowdStrike, Microsoft Defender, or equivalent platforms.
5+ years of experience working with SIEM solutions, including log correlation, alert development, and dashboard creation
5+ years of experience in security alert monitoring and incident investigation
3+ years of hands-on experience implementing DevSecOps practices, including security integration within CI/CD pipelines, Infrastructure-as-Code (IaC), container security, and automated security testing
Strong understanding of cloud-native security tools and configurations, including identity and access management, logging/monitoring, and workload protection
Experience developing automation using scripting languages such as Python, PowerShell, Bash, or similar to improve security operations and incident response workflows
Practical experience with threat hunting techniques and methodologies
Familiarity with the MITRE ATT&CK framework and its application to detection engineering and incident analysis
Strong ability to interpret and analyze security logs, network traffic, and system behaviors to detect attack patterns and anomalies
In-depth knowledge of network, endpoint, and cloud security technologies and principles
Demonstrated experience collaborating across global teams and working in cross-functional environments
Strong organizational and time management skills with the ability to work independently
Up-to-date knowledge of recent vulnerabilities, attack vectors, and remediation strategies
Excellent written and verbal communication skills to support collaboration with technical and non-technical stakeholders
Experience administering and fine-tuning security infrastructure is a strong plus
Security professional certifications such as CISSP, CCSP, Security+, GSEC, GCIH, GCIA, AWS Security Specialty, Azure Security Engineer Associate, or equivalent certifications are preferred