SOC Cybersecurity Analyst Incident Response Expert
Date de publication : 13/02/2025
Requisition ID : 42265
SOC Cybersecurity Analyst Incident Response Expert
SOC Cybersecurity Analyst / Incident Response Expert
Join ENGIE Mexico and be a protagonist in the energy transition!
At ENGIE, we have a clear mission: to accelerate the transition towards a more sustainable and carbon-neutral future. With a presence in 31 countries and a team of over 97,000 employees, we work every day to combat global warming and reduce greenhouse gas emissions by driving innovative and sustainable solutions.
In Mexico, we have 27 years of experience. Our four Business Units allow us to supply more than 3.5 million people, generating over 20,000 direct and indirect jobs. Here, your voice counts. We believe in the power of ideas, collaboration, and the strength of mutual trust. If you are looking for a place where you can grow, make an impact, and see your ideas transform the world, this is your moment!
Ready to be part of the change?
Role Objective:
As part of its Cyber Defense strategy, the Engie group has set up a global Cyber Security Operations Center (Global SOC) to meet the needs of all Engie group entities. The Global SOC is a worldwide center of excellence that is part of the continuity and development of the Engie group's Cyber Security initiatives, with the aim of preventing, detecting and dealing with security incidents in the fields of traditional IS (Office and Data Center), industrial IS and new digital uses.
The Global SOC's mission is to detect and manage cybersecurity incidents. To achieve this, the GSOC relies on the following technical environment: -Splunk for log collection and detection of cybersecurity alerts, xsoar for alert and security incident management, CrowdStrike for endpoint protection, native security tool consoles (Proofpoint TAP, Zscaler, ...).
To strengthen the GSOC team, we are looking to recruit a :SOC Cybersecurity Analyst/Incident Response Expert
Activities:
- Detect and manage security incidents from the SIEM, by e-mail or telephone.
- Handle security incidents in coordination with the Group entities' security teams.
- Assess the risks and cyber threats that could impact Engie and implement the dedicated means of detection.
- Threat Intelligence: analysis and monitoring of threats
- Implement and improve detection rules
- Document incident response playbooks
- Threat Hunting: Search for intrusions on Engie's IS, including Office 365, Cloud AWS and Microsoft Azure environments.
- Perform Forensics analysis
- Communicate with all group security operating teams
Requirements:
Educational Background:
- Security or IT Engineer or master degree in security or IT
- English 100%
- 3 to 5 years of experience
Technical skills:
- SIEM Knowledges
- Knowledge of EDR tools
- Knowledge of Cloud AWS, Microsoft Azure and Office 365 environments
- Cyber defense certifications (SANS, HS2, etc.)
- Skills in forensics and/or pentests
Key Skills:
- Ability to communicate easily, curiosity, autonomy, teamwork
- Fluency in English (oral and written) with good writing skills
- Develop detection rules
- Development of python scripts to automate repetitive actions
- Implementation of dashboards and security indicators
Our Commitment to Diversity and Inclusion: At ENGIE, we promote an environment where you feel free to give your best. We value diversity and it is one of our priorities. We are committed to offering equal opportunities, focusing on your skills and career path. Here, everyone is welcome, regardless of race, disability, religion, gender, sexual orientation, ethnicity, creed, age, or marital status.
Join ENGIE and together, as Transition Makers, let's transform the world into a more sustainable place!