Talent.com
Esta oferta de trabajo no está disponible en tu país.
SOC Lead Analyst - Senior (Servidores Proxy) - Híbrido

SOC Lead Analyst - Senior (Servidores Proxy) - Híbrido

HSBC MéxicoToluca, Toluca, Mexico
Hace más de 30 días
Descripción del trabajo

If you’re looking for a career where you can make a real impression, join Global Service Center (GSC) HSBC and discover how valued you’ll be. HSBC is one of the largest banking and financial services organisations in the world, with operations in 64 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realise their ambitions.

We are currently seeking an experienced professional to join our team in the role of SOC Lead Analyst

Role Purpose :

Operating within the Cybersecurity Global Defence function and under the management of the Global Head of Cybersecurity Operations, the Global Cybersecurity Operations (GCO) team provides a coordinated suite of “Network Defence” related services and are responsible for the detection and response to information and cybersecurity threats across the global HSBC assets and estate.

The GCO team is split into four distinct sub-functions :

  • Monitoring & Threat Detection (MTD) – Monitoring, detection, alerting and triage of initial cyber-threat events.
  • Incident Management & Response (IMR) – Management and deep-dive investigation and response to cyber-incidents.
  • Information Protection & Response (IPR) – Management and response to information and data security incidents.
  • Strategic Innovation & Operations (SIO) – Continuous improvement of cyber-threat detection capabilities and process automation.
  • Critical to the success of GCO are its close partnerships with other Cybersecurity Global Defence teams including Cybersecurity Engineering, Service Reliability Engineering, Cyber Intelligence & Threat Analysis teams and the wider HSBC businesses and functions.
  • The overall GCO mission is placed under the purview of the Cybersecurity Chief Technology Officer / Head of Cybersecurity Global Defence.

Main Activities : Lead Analyst (GCO)

Global Cybersecurity Operations (GCO) provides a coordinated suite of “Network Defence” services responsible for detecting and responding to information and cybersecurity threats to HSBC assets across the globe and is under the management of the Head of Global Cybersecurity Operations. This includes dedicated functions for the monitoring and detection of threats within the global estate as well as Cybersecurity Incident Management and Response activities.These two principal functions are supported by additional internal Global Defence (GD) capabilities in : Cyber Intelligence and Threat Analysis, Technical Director Office, Cybersecurity Engineering and Service Reliability Engineering.Critical to the success of GCO is its close partnership with sister Cybersecurity teams, IT Infrastructure Delivery and Global Business and Function clients. The overall GCO and GD mission is placed under the purview of the Cybersecurity Chief Technology Officer (CTO) and the Group Chief Information Security Officer (CISO).

The Cybersecurity Monitoring and Threat Detection Team are charged with efficiently and effectively monitoring the HSBC global technology and information estate 24x7.The team’s mission is to detect the presence of any adversary within the estate, quickly analyse the severity and scope of the issue and work with the Cybersecurity Incident Management and Response Team to contain, mitigate and remediate the incursion.In addition, the team is responsible for constantly improving its detection capability through attack analysis and ensuring that the appropriate security event information is being fed into the team and that the alerting rules are tuned for maximum effectiveness.This mission is critical to the protection of HSBC customers, the HSBC brand, shareholder value, as well as HSBC information and financial assets.

Lead Analysts are responsible for leading the analysis of and supporting the response to cyber security events within HSBC, using the latest threat monitoring and detection technologies to detect, analyse and respond.

The Lead Analyst must :

  • Work as a senior member of the Monitoring and Threat Detection team within an “Analysis POD” tasked with triage of threat detection events from across the entire global HSBC technology estate.
  • Skills

  • Excellent investigative skills, insatiable curiosity, and an innate drive to win.
  • Instinctive and creative, with an ability to think like the enemy.
  • Strong problem-solving and trouble-shooting skills.
  • Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one.
  • An understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business.
  • An understanding of organisational mission, values and goals and consistent application of this knowledge.
  • Self-motivated and possessing of a high sense of urgency and personal integrity.
  • Highest ethical standards and values.
  • Experience defining and refining operational procedures, workflows, and processes to support the team in consistent, quality execution of monitoring and detection.
  • Good understanding of HSBC cyber security principles, global financial services business models, regional compliance regulations and laws.
  • Good understanding and knowledge of common industry cyber security frameworks, standards, and methodologies, including MITRE ATT&CK, OWASP, ISO2700x series, PCI DSS, GLBA, EU data security and privacy acts, FFIEC guidelines, CIS and NIST standards.
  • Good communication and interpersonal skills with the ability to produce clear and concise reports for targeted audiences across internal and external stakeholders.
  • Ability to speak, read and write in English, in addition to your local language.
  • Technical Skills

  • Technical expertise in analysing threat event data, evaluating malicious activity, documenting unusual files and data, and identifying tactics, techniques and procedures used by attackers.
  • Expert level knowledge and demonstrated experience in analysis and dissection of advanced attacker tactics, techniques, and procedures to inform adjustments to the control plane.
  • Expert level of knowledge and demonstrated experience of common Security Information and Event Management (SIEM) platforms for the collection and real-time analysis of security information.
  • Expert level knowledge of Enterprise Detect and Response (EDR) tooling for the identification, prevention, and detection of cyber-threats and for use in triage, investigation and threat hunting.
  • Detailed knowledge and demonstrated experience of common cybersecurity technologies such as IDS / IPS / HIPS, Advanced Anti-malware prevention and analysis, Firewalls, Proxies, MSS, etc.
  • Excellent knowledge and demonstrated experience of common operating systems and end user platforms to include Windows, Linux, Citrix, ESX, OSX, etc.
  • Excellent knowledge of common network protocols such as TCP, UDP, DNS, DHCP, IPSEC, HTTP, etc. and network protocol analysis suits.
  • Good knowledge and demonstrated experience in incident response tools, techniques and process for effective threat containment, mitigation, and remediation.
  • Functional knowledge of scripting, programming and / or development of bespoke tooling or solutions to solve unique problems.
  • Functional knowledge of Security Orchestration Automation and Response (SOAR) platforms including development and implementation of automation routines.
  • Functional knowledge and technical experience of cloud computing platforms such as AWS, Azure and Google.
  • Basic knowledge and demonstrated experience in common cybersecurity incident response and forensic investigation tools such as : EnCase, FTK, Sleuthkit, Kali Linux, IDA Pro, etc.
  • Industry Experience and Qualifications

  • Candidates will be evaluated primarily upon their ability to demonstrate the competencies required to be successful in the role, as described above. For reference, the typical work experience and educational background of candidates in this role are as follows :
  • 5+ years of experience in cyber security senior analyst role or similar.
  • Experience within an enterprise scale organisation; including hands-on experience of complex data centre environments, preferably in the finance or similarly regulated sector.
  • Industry recognised cyber security related certifications including CEH, OSCP, EnCE, SANS GSEC, GCIH, GCIA, and / or CISSP.
  • Formal education and advanced degree in Information Security, Cyber-security, Computer Science or similar and / or commensurate demonstrated work experience in the same.
  • Effective Communication
  • Analytic Thinker
  • Results Oriented
  • Negotiation
  • Due to the urgent hiring need, candidates with immediate right to work locally and no relocation need will be prioritised.

    At HSBC we offer our colleagues a greater number of leave days so that they can fully enjoy their wedding, take care of the new member of the family, or grieve the loss of a family member. Our paid leave package is at the forefront in Mexico, now you have one more reason to be HSBC and proudly live a culture of well-being, balance, and care.

    HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role.

    Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.

    #J-18808-Ljbffr

    Crear una alerta de empleo para esta búsqueda

    Soc Analyst • Toluca, Toluca, Mexico

    Ofertas relacionadas
    • Oferta promocionada
    Especialista en certificación de aplicaciones Sr

    Especialista en certificación de aplicaciones Sr

    Grupo SalinasTlalpan, Ciudad De México, México
    Contribuir a robustecer la seguridad de las aplicaciones, servidores y bases de datos por medio de seguimiento y recomendaciones puntuales sobre la mitigación de vulnerabilidades en ecosistemas.Det...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Soporte a Ventas

    Soporte a Ventas

    Grupo SalinasCuernavaca, Morelos, México
    La función principal es administrar el producto de Inversión a plazo, así mismo asegurar la rentabilidad del mismo cumpliendo con las normas regulatorias aplicables. Ejecutar las solicitudes de Inve...Mostrar másÚltima actualización: hace 19 días
    • Oferta promocionada
    Consultor Análisis de Riesgos

    Consultor Análisis de Riesgos

    Grupo SalinasTlalpan, Ciudad De México, México
    Gestionar los Riesgos y Amenazas del negocio, asegurando la implementación de Medidas Preventivas y Correctivas.Apoya y ejecuta tareas en sistema de seguridad SAP. GRC (Governance-Risk-Compliance).G...Mostrar másÚltima actualización: hace 19 días
    • Oferta promocionada
    Category Senior Analyst

    Category Senior Analyst

    DiDiEstado de México, Mexico
    Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.It offers a wide range of app-based services across markets including Asia-Pacific, Latin America and ...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    ANALISTA SR. T24

    ANALISTA SR. T24

    Banco Ve por MásAzcapotzalco, Mexico City, Mexico
    México certificada por Great Place To Work, conformada por cuatro unidades de negocio : .Banco, Casa de Bolsa, Arrendadora y Seguros. .Enriquecer la vida de las personas.Licenciatura en Sistemas, Elec...Mostrar másÚltima actualización: hace 5 días
    • Oferta promocionada
    Consultor Especialista Ciberseguridad

    Consultor Especialista Ciberseguridad

    Banco AztecaTlalpan, Ciudad De México, México
    Responsable de Identificar, evaluar y monitorear riesgos de ciberseguridad de Cajeros, comunicando mediante infografías los resultados del análisis de Ciberriesgos. Identificación de factores de rie...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Credit Risk Jr. Analyst Financial Institution (Ciudad de México, Miguel Hidalgo)

    Credit Risk Jr. Analyst Financial Institution (Ciudad de México, Miguel Hidalgo)

    BBVA Technology en AméricaMiguel Hidalgo, Mexico City, Mexico
    En BBVA, dentro de la unidad de Riesgos de Corporate & Investment Banking (GRM CIB), estamos buscando un / a Credit Risk Jr. Analyst para unirse a nuestro equipo de Global Transactional Banking & Glob...Mostrar másÚltima actualización: hace 13 días
    • Oferta promocionada
    Sourcing Specialist

    Sourcing Specialist

    AxaltaTlalnepantla, México, Mexico
    Axalta is a world class chemical company in the coatings space.This role offers the opportunity to learn and grow with a strong global procurement team in an organization where the procurement work...Mostrar másÚltima actualización: hace 17 días
    • Oferta promocionada
    Analista

    Analista

    ElektraTlalpan, Ciudad De México, México
    Analisis y resolución de casos Salesforce, Conciliación Medios de Pago, Parcializaciones y Kpi´s.Lic Contabilidad, Admón o afin. Prestaciones de ley : Vacaciones iniciando con 12 días al año, Prima v...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Líder de Análisis Estratégico e Implementación

    Líder de Análisis Estratégico e Implementación

    Empresa ConfidencialCuauhtémoc, Mexico City, Mexico
    Como Líder de Análisis Estratégico e Implementación serás responsable de realizar análisis estratégicos y de mercado, generar insights a partir de datos y construir casos de negocio que respalden l...Mostrar másÚltima actualización: hace 1 día
    • Oferta promocionada
    Analista 1er nivel

    Analista 1er nivel

    Grupo UPAXTlalpan, Ciudad De México, México
    Detecta de manera oportuna las fallas que presentan los equipos instalados en cada uno de los canales a través del monitoreo continuo así como gestiona los tickets de todos los incidentes presentad...Mostrar másÚltima actualización: hace 22 días
    • Oferta promocionada
    KA Sr. Analyst

    KA Sr. Analyst

    DiDiEstado de México, Mexico
    Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.It offers a wide range of app-based services across markets including Asia-Pacific, Latin America and ...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Analista de Encuestas de Servicio (NPS)

    Analista de Encuestas de Servicio (NPS)

    LG MéxicoTlalnepantla, México, Mexico
    ANALISTA DE ENCUESTAS DE SERVICIO.Responsable de monitorear, analizar y dar seguimiento a los resultados de la encuesta NPS de la tienda en línea, con el fin de identificar oportunidades de mejora ...Mostrar másÚltima actualización: hace 17 días
    • Oferta promocionada
    Gestor Prosperidad Incluyente

    Gestor Prosperidad Incluyente

    Banco AztecaCoatepec Harinas, Mexico, Mexico
    Como gestor de cobranza domiciliaria, eres responsable de validar los datos de los clientes que solicitan un crédito, así como realizar planes de pago a clientes en sus primeras semanas de atraso, ...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    SOC Analyst (all genders welcome)

    SOC Analyst (all genders welcome)

    COSMO CONSULTEstado de México, Mexico
    Teletrabajo
    SOC Analyst (all genders welcome).Proactive monitoring : You are responsible for the continuous, 24 / 7 monitoring of all security-related events in our global IT systems. Threat detection and analysis...Mostrar másÚltima actualización: hace 13 días
    • Oferta promocionada
    Sr. Lead de Sanciones

    Sr. Lead de Sanciones

    Openbank MéxicoÁlvaro Obregón, Mexico City, Mexico
    Te apasiona la gestión de Cumplimiento y la protección del sistema financiero? Únete a.Garantizar procesos sólidos de sanciones, listas negras y PEPs, impulsando la seguridad y el cumplimiento norm...Mostrar másÚltima actualización: hace 14 días
    • Oferta promocionada
    Senior Manager Inventory Control LATAM

    Senior Manager Inventory Control LATAM

    GXO Logistics, Inc.Cuautitlán Izcalli, México, Mexico
    At GXO, we are looking our next.Senior Manager, Inventory Control LATAM.At GXO, we design the fastest, smartest, and most efficient supply chains. We are designing supply chains that transform logis...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Soc analyst...

    Soc analyst...

    JobbydooCuauhtémoc, MX
    We are seeking a talented individual to join our Cyber Security Incident Response team at Marsh McLennan.This role will be based in Mexico City, Torre Mayor office. This is a hybrid role that has a ...Mostrar másÚltima actualización: hace 1 día