2 months ago
Zapopan, MexicoSenior
Responsibilities
- Define and own SOC detection coverage strategy, standards, naming conventions, quality criteria, coverage targets, MTTD, and false-positive KPIs.
- Map threats and adversary behaviors to MITRE ATT&CK, prioritize detection development, maintain coverage heatmaps, and identify coverage gaps.
- Build, deploy, and own the full lifecycle of detections-as-code, automated triage, and production agentic detection and response workflows.
- Embed with SOC, incident-response, platform, engineering, and managed-services teams to deliver in partner-controlled environments and coach technical teams.
- Design and govern non-human identity, scoped delegation, audit logging, kill-switch, guardrail, safety-control, and human-oversight mechanisms for security AI agents.
- Apply MITRE ATLAS to threat-model AI-agent deployments and address adversarial ML and agent-specific attack vectors.
- Architect collector and forwarder systems, log pipelines, SIEM strategy, security data infrastructure, and portable detection content.
- Run or support purple-team and adversary-emulation exercises to validate detection efficacy and close coverage gaps.
- Apply NIST AI RMF, OWASP Top 10 for LLM Applications, and OWASP Top 10 for Agentic AI governance controls.
- Build supervised automations that expand analyst capacity while maintaining governance, visibility, and operational oversight.
- Provide IC7 technical leadership, drive decisions, synthesize inputs, and mentor engineers and analysts.
Requirements
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Software Engineering, or a related field.
- 4–6+ years of relevant hands-on experience.
- Advanced English proficiency is mandatory.
- Software-development proficiency, with Python preferred, plus API integration, infrastructure-as-code, and CI/CD experience.
- Security operations fluency covering detection engineering, SIEM/SOAR platforms, and incident-response workflows.
- Experience owning the detection lifecycle end to end and applying MITRE ATT&CK to TTP mapping, kill-chain coverage, and detection alignment.
- Experience applying MITRE ATLAS to adversarial ML threat modeling for AI systems and agents.
- Hands-on production experience building with agent frameworks, RAG pipelines, or agentic orchestration.
- Knowledge of NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic AI Applications, guardrails, human oversight, and secure orchestration.
- Ability to embed with operational teams, ship in partner-controlled environments, and coach across technical levels.
- Preferred experience with Defender XDR, Microsoft Sentinel, Microsoft Sentinel Data Lake, Security Copilot, Logic Apps, KQL, and Azure.
- Preferred Splunk experience including SPL, log forwarding, content and detection management, and index administration.
- Preferred experience with Model Context Protocol, Security Copilot plugins, or comparable security-native agent orchestration and connector frameworks.
- Preferred experience with Entra Workload Identities, Okta, service principals, managed identities, or comparable workload-identity systems.
- Preferred experience with SIEM migration, detection-content portability, and collector/forwarder architecture at scale.
- Prior forward-deployed engineering, solutions-engineering, or detection-engineering experience is preferred.
