Job Closed

This listing is no longer active.

System & Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteMid LevelTeam 5,001-10,000H1B No SponsorCompany SiteLinkedIn

Location

Spain

Posted

60 days ago

Salary

0

Seniority

Mid Level

Job Description

System & Security Analyst

Devoteam

Role Description Estamos en búsqueda de un perfil System & Security Analyst con la siguiente experiencia: - Experiencia en resiliencia operativa y cumplimiento de requisitos regulatorios como DORA y GDPR en entornos financieros o regulados. - Experiencia en gestión de vulnerabilidades y en el uso de análisis estático de seguridad sobre el ciclo de desarrollo, con referencia explícita al uso de GitHub SAST / GitHub Advanced Security. - Experiencia en seguridad en el desarrollo (Secure SDLC) y aplicación de guías OWASP para desarrollo seguro sobre tecnologías .NET Core. - Experiencia en gestión de secretos y manejo seguro de credenciales en pipelines, con uso de herramientas corporativas y referencia a Terraform y servicios de secretos en cloud. - Experiencia en auditoría y mejora continua, manteniendo documentación de procesos y registros de actividad disponibles para auditorías internas o externas. - Experiencia en evaluación inicial de riesgos técnicos y de transición, incluyendo diagnóstico AS-IS, matriz de riesgos de transición y análisis de brechas de conocimiento. - Conocimiento de entornos cloud AWS y de sus implicaciones de seguridad, resiliencia y gobernanza, incluyendo servicios como EC2, S3, RDS y despliegues controlados con Terraform. - Conocimiento de sistemas operativos Windows Server 2019 y Linux aprobados para contenedores, además de software base como IIS 10, .NET Framework / .NET Core. - Conocimiento de herramientas corporativas del cliente como JIRA Service Management, JIRA Software, Confluence, Xray, así como de observabilidad y monitorización con Nagios, Control-M, Grafana y Splunk. - Conocimiento de continuidad de servicio, simulacros de DRP, validación de RTO/RPO y reporting de resiliencia operativa. Qualifications - Capacidad analítica y de evaluación de riesgos, especialmente en fases de transición, auditoría técnica inicial y control de exposición de seguridad. - Orientación a compliance y gobernanza, asegurando alineación con controles operacionales, seguridad corporativa y estándares del cliente. - Visión de resiliencia operativa, combinando seguridad, continuidad, recuperación y estabilidad del servicio Back Office. - Capacidad de documentación y trazabilidad, generando evidencias, reportes técnicos, matrices de riesgos y documentación de arquitectura/procesos. - Comunicación técnica transversal, con interlocución con equipos de desarrollo, operaciones, seguridad, arquitectura y responsables internacionales del Grupo. - Mentalidad DevSecOps, integrando seguridad dentro del ciclo de vida del desarrollo y no como actividad aislada al final del proceso. Requirements - Experiencia en seguridad de activos y control de acceso en entornos críticos, aplicando el principio de Least Privilege y control nominal de accesos a producción. - Experiencia en resiliencia operativa y cumplimiento de requisitos regulatorios como DORA y GDPR en entornos financieros o regulados. - Experiencia en gestión de vulnerabilidades y en el uso de análisis estático de seguridad sobre el ciclo de desarrollo, con referencia explícita al uso de GitHub SAST / GitHub Advanced Security. - Experiencia en seguridad en el desarrollo (Secure SDLC) y aplicación de guías OWASP para desarrollo seguro sobre tecnologías .NET Core. - Experiencia en gestión de secretos y manejo seguro de credenciales en pipelines, con uso de herramientas corporativas y referencia a Terraform y servicios de secretos en cloud. - Experiencia en auditoría y mejora continua, manteniendo documentación de procesos y registros de actividad disponibles para auditorías internas o externas. - Experiencia en evaluación inicial de riesgos técnicos y de transición, incluyendo diagnóstico AS-IS, matriz de riesgos de transición y análisis de brechas de conocimiento. - Conocimiento de entornos cloud AWS y de sus implicaciones de seguridad, resiliencia y gobernanza, incluyendo servicios como EC2, S3, RDS y despliegues controlados con Terraform. - Conocimiento de sistemas operativos Windows Server 2019 y Linux aprobados para contenedores, además de software base como IIS 10, .NET Framework / .NET Core. - Conocimiento de herramientas corporativas del cliente como JIRA Service Management, JIRA Software, Confluence, Xray, así como de observabilidad y monitorización con Nagios, Control-M, Grafana y Splunk. - Conocimiento de continuidad de servicio, simulacros de DRP, validación de RTO/RPO y reporting de resiliencia operativa. Benefits - La modalidad de trabajo es 100% en remoto.

Related Job Pages

More Security Analyst Jobs

CallTek logo

Senior Cyber Threat Intelligence & Forensics Analyst

CallTek

Your White Label Enterprise Support Company.

Security Analyst60 days ago
Full TimeRemoteTeam 5,001-10,000Since 2008H1B No Sponsor

Role Description - Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. - Experience: 5+ years in a dedicated SOC, IR, or Intel role (ideally within a CSIRT or MSSP). - The Toolkit: Mastery of tools like Splunk/ELK, CrowdStrike/SentinelOne/VisionOne, Magnet AXIOM/FTK/EnCase/Autopsy, Sandbox, Volatility, and Wireshark. - Programming: Ability to script in Python or PowerShell to automate repetitive tasks or parse forensic artifacts. - Certifications: We value skills over paper, but GIAC (GCIH, GCFA, GCTI), CFE, CTIA or CHFI are highly preferred. - Familiarity with incident response processes and frameworks. - Strong analytical and problem-solving skills with attention to detail. - Excellent verbal and written communication skills to present complex technical information clearly. Qualifications - Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. - 5+ years in a dedicated SOC, IR, or Intel role (ideally within a CSIRT or MSSP). - Mastery of tools like Splunk/ELK, CrowdStrike/SentinelOne/VisionOne, Magnet AXIOM/FTK/EnCase/Autopsy, Sandbox, Volatility, and Wireshark. - Ability to script in Python or PowerShell. - GIAC (GCIH, GCFA, GCTI), CFE, CTIA or CHFI certifications preferred. - Familiarity with incident response processes and frameworks. - Strong analytical and problem-solving skills. - Excellent verbal and written communication skills. Requirements - 5+ years in a dedicated SOC, IR, or Intel role. - Mastery of specified tools. - Ability to script in Python or PowerShell. - Preferred certifications. - Familiarity with incident response processes. - Strong analytical skills. - Excellent communication skills. Company Description

Philippines
Job Closed
Positivo S+ logo

Information Security Analyst, SIEM

Positivo S+

Somando inovação para multiplicar resultados.

Security Analyst60 days ago
Full TimeRemoteTeam 1,001-5,000Since 2009H1B No Sponsor

• Design, implement, and evolve detection use cases on SIEM platforms. • Increase threat identification capabilities and reduce false positives. • Develop, test, and maintain use cases and correlation rules in SIEM. • Create and refine detections based on the MITRE ATT&CK framework. • Perform continuous tuning to reduce false positives/negatives. • Work on log engineering (onboarding, parsing, normalization, and enrichment). • Define and monitor detection effectiveness metrics (coverage, MTTD, etc.). • Support complex investigations (N2/N3) with in-depth event analysis. • Integrate sources such as EDR, NDR, cloud platforms, IAM, and applications into the SIEM. • Develop playbooks and automations (SOAR where applicable). • Collaborate with incident response and threat intelligence teams. • Document use cases, detection patterns, and implemented improvements.

Brazil
Job Closed
Bonterra logo

Information Security Compliance Analyst

Bonterra

We propel every doer of good to their peak impact.

Security Analyst60 days ago
Full TimeRemoteTeam 1,001-5,000H1B No Sponsor

Role Description The Bonterra Information Security Risk and Compliance department is looking to hire a Compliance Specialist to our team. If you enjoy problem solving, are enthusiastic working in a team format and want to thrive in the ever-changing risk & compliance field while learning new concepts and principles as part of your continuing education, look no further! - Perform as the primary in the executing our annual Service Organization Controls (SOC) reporting initiatives, which includes several Bonterra products. - Works closely with other members of the Information Security Risk team. - Works closely with control owners across the company and internal and external auditors to ensure requests are completed in a timely manner as part of the overall project management process. - Performs technical risk assessments of third party suppliers' security and privacy controls. - Maintains register of relevant suppliers/vendors, controls, and risks for ongoing vendor risk management activities. - Will be responsible for the playbook for reporting of high risk events that involve compliance, risk and information security. - Assists in maintaining our overall security awareness, role based security trainings and phishing simulation programs across the enterprise. - Assists in conducting user activity audits where required. Qualifications - 3+ years experience performing risk and compliance activities. - Project management experience. - A strong understanding of both SOC and ISO as there will be overlap. - Experience managing multiple priorities independently and in a team environment to achieve goals. - Excellent verbal and written communication skills. - Excellent organizational, planning and time management skills. - Excellent research and analytical skills. - Ability to exercise good judgement and tact in dealing with Bonterra senior management. - Proficient with technology and ability to learn our software systems, including GRC, ticketing and project management software and workflows. - Proven track record of proactively identifying needs and implementing solutions. - Information systems security professional certifications preferred (CRISC, CISA, CISSP, CISM, GSEC, GCFA, GCTI, CCSP, or other relevant Information Security certifications). Benefits - Comprehensive benefits package that supports your health, well-being and growth. - Compensation and benefits for this role apply to full-time employees in the United States and may vary based on local standards, laws and norms. - Pay is determined by location, skills, experience, and education, and is one part of Bonterra’s total rewards package, which may also include bonuses, incentives, equity, and a comprehensive benefits program. Equal Opportunity & Accommodations At Bonterra, we are proud to be an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We provide equal employment opportunities without regard to race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, veteran status, or any other characteristic protected by law. If you require a reasonable accommodation during the application process, please submit a request.

United States
$76K - $100K / year
Job Closed

Title: Lead Analyst, Cyber Security Location: Macon United States Job Description: Our technology organization is transforming how we work at Smurfit Westrock. We align with our businesses to deliver innovative solutions that: - Address specific business challenges, integrate processes, and create great experiences - Connect our work to shared goals that propel Smurfit Westrock forward in the Digital Age - Imagine how technology can advance the way we work by using disruptive technology We are looking for forward thinking technologists that can accelerate our focus areas such as building stronger foundational technology capabilities, reducing complexity, employing digital transformation concepts, and leveraging disruptive technology. Location and/or Business/Division Details (if applicable) Lead, IT Identity & Access Management (IAM) Engineer (IGA) - Atlanta, GA (remote may be considered) The opportunity: This opportunity would allow you to apply your strong understanding of designing, configuring, implementing, and supporting Identity Governance & Administration (IGA) solutions and processes. As a Lead IT IAM Engineer (IGA) you will work directly with technology and business partners in a global organization to ensure the IAM services and technology are delivered in accordance with Cyber Security strategy. In this role, the Lead will be part of the Identity and Access Management within Cyber Security and will collaborate with many cross functional teams within and outside of Smurfit Westrock's IT Solutions including Infrastructure & Services, Productivity & Platforms, Core Engineering, Operations, Service Delivery, Human Resources IT teams to grow and mature IAM security program, while protecting Smurfit Westrock's identities and access protocols from the latest threat actors and threat vectors. You will be responsible for technical deployment, rollout, maintenance, and support of key IAM processes and security practices related to Identity Governance and Administration (IGA) and end-to-end identity lifecycle management systems (SailPoint Identity Security Cloud - ISC / IdentityNow or other IGA Solutions), implementing birthright access provisioning/de-provisioning, establishing access certifications/governance workflows, as well as developing and supporting Role Based Access Control (RBAC) frameworks and modern access management solutions, such as single sign-on, multi-factor authentication, proper authorization etc. The successful candidate will have excellent collaboration and communication skills. How you will impact Smurfit Westrock: - Provides technical support across IAM applications to define, implement and enhance current and new IAM software, hardware requirements, delivering and supporting IGA applications, solutions, and processes - Provide support with respect to implementation, and concurrent delivery of two or more Identity platforms (i.e., IGA and PAM) such as SailPoint, Saviynt, BeyondTrust, Okta, Ping Federate, Microsoft Azure AD - Assist with configuring, implementing, maintenance, and documentation of all layers of IAM applications and robust identity and access solutions including tools to support account creation, onboarding, offboarding, user provisioning, deprovisioning, authorization, authentication, single-sign, federated identities, multi-factor authentication, and privileged access management activities - Assist to modernize access control protocols, design from scratch, implement, and maintain role-based access controls (RBAC) and birthright provisioning/de-provisioning mechanisms to execute and maintain a strategy of "least privilege" - Conducts proper root cause analysis and make recommendations to improve IAM processes or prevent future occurrence of end user access issues - Assist in the analysis of user and permission data, and the development and documentation of test cases for applications on boarding, user access and other identified entitlements repositories that have been re-permissioned. What you need to succeed: - Bachelor's degree or a similar level of training in IT and information security - 8-10 years of IT experience focused on Identity Governance Administration (IGA) and other security practices. - 8-10 years working knowledge of two or more IGA solutions (SailPoint, Saviynt, One Identity), etc - 8+ years hands-on knowledge and experience with designing, configuring, implementing, and supporting IAM solutions such as SailPoint, Saviynt, BeyondTrust, Thycotic, CyberArk, Okta or Ping Federate or any IDAM tools - Minimum 8 years hands-on experience with Identity Life-cycle Management processes and Identity Governance related to onboarding and offboarding, good understanding of Active Directory, Single Sign On (SSO) and modern authentication and authorization standards and protocols (i.e., SAML, OpenID Connect, OAuth) - Solid understanding of IGA concepts and frameworks to resolve IAM complex issues in effective/creative ways - Hands-on technical ability to support (SailPoint Identity Security Cloud - ISC / IdentityNow) - Minimum 8 years' experience and know how in any combination of Cloud (AWS IAM), Network, Cyber - Some understanding of Domains, Trusts, AD replication (configuration and troubleshooting), and Group Policy Object (GPO) management and experience in completing Identity migrations post-merger/acquisition. - Experience with JavaScript, Python, Ruby, PowerShell, or other scripting languages - Strong experience with Java, BeanShell, XML, and SQL - Minimum 4 years working with Amazon Web Services (AWS) including EC2 and Lambda - Certifications a plus such as: CISSP, CISM, CRISC, CISA and other similar IAM related certifications. - Must have strong communications skills with the ability to interface with both executives and technical staff - Experience running risk management programs and IT architecture planning and implementation. - Travel up to 30%, although this may be higher when ramping up - Professional proficiency with the MS suite of products (Word, Excel, PPT, Visio, Project) - Self-directed, results-oriented and ability to work under tight deadlines in a fast-paced environment - Strong attention to detail, analytical, decision-making, effective document, and process review skills - Demonstrates strategic thinking in application of security technologies and interoperability What we offer: - Corporate culture based on loyalty, integrity, & respect. - Comprehensive training with numerous learning and development opportunities - An attractive salary reflecting skills, competencies, and potential. - A career with a global packaging company where Sustainability, Safety and Inclusion are business drivers and foundational elements of the daily work.

Georgia