
Information Security Engineer
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in Mexico.
• Oversee cybersecurity investigations across various environments, including cloud, endpoint, identity, SaaS, email, and network.
• Detect, investigate, contain, and resolve security incidents effectively.
• Analyze data from SIEM, EDR, cloud, identity, and network security tools.
• Collaborate with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams during incidents.
• Manage incidents, articulate risks, and enhance the organization’s security posture.
• Enhance security operations through automation, AI-driven workflows, detection tuning, and playbook creation.
• Coordinate external takedowns and threat remediation efforts with third-party providers.
• Examine suspicious activities in AWS, Kubernetes, GitHub, SaaS platforms, and identity systems.
• Conduct purple team exercises and engage in threat hunting activities.
• Create, calibrate, and maintain security detections and SIEM use cases.
• Document investigations, incident timelines, playbooks, and insights gained.
• A Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or 2-5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, or Detection Engineering.
• Proven experience in leading and coordinating cybersecurity investigations from initial detection through to containment and remediation.
• Familiarity with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting.
• Experience in investigating incidents across cloud, endpoint, identity, SaaS, and network environments.
• Proficient in analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems.
• Strong knowledge of Windows, Linux, Active Directory, Entra ID (Azure AD), AWS IAM, and contemporary identity attacks.
• Working understanding of TCP/IP, DNS, HTTP/S, SMTP, VPNs, and standard enterprise architectures.
• Experience in performing root cause analysis and correlating activities across various security technologies.
• Ability to produce executive summaries and effectively communicate technical findings to both technical and non-technical stakeholders.
• Experience collaborating across Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams.
• Excellent documentation skills for investigations, incident timelines, playbooks, and lessons learned.
• Commitment to continuous learning, security automation, and process enhancement.
• Experience utilizing AI-assisted security tools and workflow automation.
• Ability to identify repetitive operational tasks suitable for automation and implement AI-enabled workflows.
• Experience in conducting purple team exercises.
• Familiarity with Wiz CNAPP.
• Experience in threat hunting utilizing the MITRE ATT&CK framework.
• Experience in developing, tuning, or maintaining security detections and SIEM use cases.
• Knowledge of SOAR platforms and security automation.
• Experience in conducting fraud investigations or partnering with Fraud Operations.
• Experience in investigating account takeover, payment fraud, synthetic identity fraud, or cyber-enabled fraud.
• Security certifications such as GCIH, GCTI, AWS Security Specialty, Security+, or equivalent.
• A diverse, equitable, and inclusive workplace culture.
• Access to employee resource groups.
• Commitment to equal opportunity employment.
• No pre-employment fees for background checks, training, or equipment.
Redox
Darktrace
Alteryx
Banner Health
Get handpicked remote jobs straight to your inbox weekly.