
Senior Cybersecurity Defense Specialist
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Mexico, +1 more country.
• Design, implement, manage, enhance, and provide support for global security technology solutions.
• Lead or act as a seasoned technical resource on multidisciplinary IT security initiatives.
• Assess existing security measures and processes across various TD SYNNEX locations.
• Identify and mitigate security vulnerabilities through penetration testing and red teaming activities.
• Respond swiftly to potential security incidents.
• Enhance identity and access management, threat hunting and analysis, vulnerability management, security monitoring, and incident response strategies across both on-premise and cloud platforms.
• Document operational procedures and runbooks, and train support teams accordingly.
• Develop and implement AI-powered detection rules utilizing ML anomaly models, LLM-generated Sigma/SPL/KQL, and behavioral analytics.
• Create intelligent SOAR playbooks incorporating LLM reasoning for dynamic decision-making and adaptive responses.
• Implement and calibrate AI-driven alert triage systems for automated scoring, enrichment, and routing.
• Manage SIEM components, focusing on index optimization, search performance, and data model upkeep.
• Design frameworks for prompt engineering and evaluation harnesses for security-centric LLM applications.
• Construct RAG pipelines leveraging internal security knowledge bases, runbooks, and threat intelligence.
• Execute AI-augmented threat hunting utilizing LLM-generated hypotheses and ML anomaly detection.
• Develop and sustain CI/CD pipelines for detection rules, playbooks, and ML model deployments.
• Conduct AppSec reviews, penetration testing, and red teaming efforts.
• Automate and orchestrate processes to enhance team efficiency.
• Perform data analytics and KPI reporting to measure operational effectiveness and control health.
• Collect, process, preserve, analyze, and present computer-related evidence for investigative purposes.
• Work occasional non-standard hours or overtime as required by business needs.
• Travel as necessary.
• A Bachelor's Degree in an IT-related field is mandatory.
• 8 to 10 years of pertinent work experience is required.
• At least 5 years in security engineering with demonstrated cross-domain expertise (SIEM + SOAR or SIEM + Detection).
• Proficient in SIEM query languages (SPL, KQL) and SOAR playbook creation (Python, low-code platforms).
• Experience in building or integrating AI/ML models for security applications.
• Strong Python skills alongside familiarity with ML frameworks (scikit-learn, PyTorch) and LLM APIs.
• Experience in detection engineering, including Sigma rules, MITRE ATT&CK mapping, and rule tuning methodologies.
• Proficient in Git-based workflows for detection-as-code and infrastructure-as-code.
• Possession of relevant security and technology certifications and/or equivalent proven work experience.
• Ability to communicate effectively and convey necessary information clearly.
• Proficient in conversing and writing in both English and the local language.
• Capable of creating and delivering formal presentations.
• Effective interaction with all levels of management is essential.
• Strong multicultural interpersonal skills are required.
• Strong leadership capabilities with a willingness to lead, innovate, and be assertive.
• Excellent organizational and time management skills.
• Ability to work effectively under stress and pressure, managing high workloads and deadlines.
• Ability to work independently with minimal supervision.
• Quick adaptability to new systems and technologies is necessary.
• Proficient in using relevant computer system applications at an advanced level.
• On-call availability as required.
• Some travel may be necessary.
• Elective benefits customized to the employee's country.
• Formal leadership and professional development programs available.
• Access to on-demand courses.
• Seminars and events promoting financial, physical, and mental well-being.
• Global Life Empowerment Assistance Program.
• Inclusive education and peer-to-peer discussions.
• Opportunities for equitable growth and development.
• Onboarding program with networking opportunities.
• Internal, peer-led inclusive communities and activities.
• Business resource groups to engage with.
• Local volunteering opportunities.
• Participation in environmental and social initiatives.
Alcoa
McKesson
Zillow
Truelogic Software
Get handpicked remote jobs straight to your inbox weekly.