Sobre esta vaga de Senior Cybersecurity Engineer na A2MAC1
Manage security capabilities and lead complex L3 incident response and preventive engineering, ensuring the outsourced SOC’s detections and escalations translate into structural improvements across identity, endpoint, email, DLP, cloud, DevOps, Product and AI security.
The Senior role designs and drives resilient security solutions and reduces exposure surface by turning repeated incidents, vulnerabilities, and audit findings into prioritized roadmaps, automation, and guardrails—balancing security, usability, and compliance.
Tasks & Responsabilities
· End-to-end ownership of one or more security capabilities/platforms: design, implement, operate, and evolve them with threats and business needs.
· Serve as L3 technical authority for complex/high-impact incidents: lead investigations, perform deep RCA, and define long-term preventive engineering actions.
· Drive exposure surface reduction by improving vulnerability management processes, prioritization, and engineering remediation patterns.
· Ensure operational excellence for anti-phishing and DLP (advanced tuning, policy design, exception governance, evidence-by-default).
· Embed security into DevOps and product environments: threat modeling facilitation, application security tooling/guardrails, and automation to shift left.
· Design and maintain AI security implementation patterns (data protection, identity controls, safe usage guardrails) aligned with compliance needs.
· Strengthen the SOC partner operating model: refine escalation criteria, enrich context, improve runbooks, and reduce noise via engineering.
· Mentor/coach (as IC leadership) on secure engineering practices, troubleshooting methodology, and standards adoption across teams.
Requirements
Professional Experience & Studies
- Experience: 5–8 years of significant successful experience in IT infrastructure, application security and cybersecurity operations or engineering.
- Studies: Engineering degree or Master’s in IT/Security is a plus; Bachelor’s remains acceptable with strong track record (consistent with your baseline).
- Language: Professional English; strong written skills for standards and audit evidence narratives.
Certifications
Must have
- Azure Security & Governance, Sentinel/Defender, Purview, Entra IAM, Azure Security Architecture.
Nice to have
- Ethical hacking experience.
Skills & Abilities
Must have
- Strong communication, negotiation, leadership behaviors (“can do”, “team player”), problem-solving and analytical skills.
- Expert-level hands-on expertise: Azure/M365/Entra, Defender, Intune, Purview DLP/MIP, Sentinel SIEM/SOAR automation, Azure DevOps CI/CD.
- Strong networking and system foundations (Windows/Linux/AD, firewall/VPN/DNS/DHCP/Wi‑Fi) and ability to drive complex remediation.
- Strong security fundamentals: vulnerability management, OWASP, pentesting concepts, AI security; ability to turn incidents/findings into structural improvements.
- Strong scripting/automation capability (PowerShell/Python) and ability to operate with agile/Kanban.
- Knowledge of standards and governance: ITIL/ITSM, ISO27001/NIST, regulatory context (GDPR/TISAX).
Nice to have
- Automotive/industrial experience; additional professional languages (French/German/Chinese).
Benefits
Biweekly Payment
IMSS
Chritsmas Bonus
Vacations by the law
Vacations bonus by the law
Food Vouchers
Gas Vouchers
Medical Insurance only for employee
Life Insurance only for employee