Security Incident Response Incident Coordinator

hace 5 horas


San José, Costa Rica DXC Technology A tiempo completo

The Security Incident Response Control Center (SIRCC) Incident Coordinator position will serve as the in-region coordinator for all DXC cyber security incidents. Each follow-the-sun region will have a coordinator who will function in the incident coordination role in cooperation with the other coordinators in the other regions. Security incidents will be handed off between coordinators as regions go off and come online for their normal working hours to ensure continuity of the incident response process. Coordinator tasks consist of reviewing the work and consulting with the SIRCC analysts to ensure that a given security incident is being handled in an appropriate and expeditious manner according to its severity and risk.

**Job specifics/responsibilities**:

- Ensuring that security incidents are prioritized correctly and handled in a manner reflecting their priority.
- Ensuring tasks necessary to the verification, mitigation, remediation and reporting of security incidents are assigned to SIRCC analysts and progressing in a satisfactory manner.
- Ensuring higher priority incidents are continuing to progress as regions go offline and come on line in the follow-the-sun model in coordination with other regional incident coordinators.
- Ensuring the handoff of incident response activity from the regional shift before and after the region of responsibility.
- Ensuring the appropriate incident escalations and reporting are taking place in accordance with established policy and process guidance.
- On-call duties for escalation of Security Incidents
- Responsible for peer review, final approval, and delivery of significant incident reports (e.g. Root Cause Analyses), management briefings, and incident updates
- Take the lead in management and technical update meetings during significant incidents, delegate tasks to the SIRCC analyst team members, to other security teams, and to other business units.
- Define the meeting timeframes and scheduling for all update briefings.
- Document action items carried out by the Incident Coordination team
- If required, task the SIRCC Incident Analyst team members to complete additional incident related actions outside of meetings
- Liaise with SIRCC Analysts to ensure that SIRCC action items are being actioned correctly, and provide guidance where necessary to facilitate the completion of such tasks
- Peer review and release of management alerts notifications.
- Use intelligence sources to proactively investigate the environment for threats and real or potential security breaches
- During incidents, lead reactive intelligence analysis, and once a basic methodology is established, hand over ongoing tasks to the SIRCC Analysts for continued analysis.
- Peer review results of the SIRCC Analysts analysis of intelligence (e.g. correlation of logs from multiple tools)
- Liaise with other Incident Coordinators to allocate daily and longer term tasks between different coordinators
- Own security tools used by SIRCC and contribute to their strategic development
- Ongoing mentoring of SIRCC staff
- Implementation and management of minor SIRCC projects, and development and documentation of initial draft of project-related processes
- Liaise with SIRCC Manager to completely develop and implement new processes as required
- Work with the SIRCC Manager to develop acceptance criteria, SLA’s, processes, and procedures as required for new tasks and processes being assigned to the SIRCC team by management

**Technical skills**
- Experience with gathering Open Source Intelligence (OSINT)
- Understanding of the requirements for security audit processes/frameworks, such as SOX, SAS70, or ISO27001
- Experience with programming languages such as Python, Perl, Java or C++
- The ability to perform an in-depth analysis of log files from multiple devices and environments and identify indicators of security threats.
- Solid knowledge of common types of Information Security threats.
- In-depth understanding of TCP, IP, and other lower-level network protocols, as well as common higher-level protocols such as HTTP, HTTPS, SMTP, FTP, and others. The ability to conduct an in-depth analysis of network traffic and packet captures.
- Strong familiarity with network security devices, including firewalls, Intrusion Detection/Prevention Systems, proxies, switches, routers, and others. Understanding of modern network operating systems.
- Understanding of, and experience using, Unix-style operating systems, such as Solaris, Linux, or BSD.
- Current or recent experience working with enterprise level anti-malware or advanced endpoint protection packages.
- Experience with Operating System security, administration, and logging in an enterprise environment.
- Previous experience with process and procedure development.
- Experience dealing with cybercrime and working in an environment that requires an investigative response when dealing with computer-based electronic evidence.
- Fluent in written and verbal English



  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    At Experian, we are committed to delivering exceptional service to our clients. As an Incident Response Support Coordinator, you will play a vital role in supporting our Incident Response Team in delivering timely and effective responses to client incidents.The ideal candidate will have excellent communication and organizational skills, with the ability to...


  • San José, Costa Rica DXC Technology A tiempo completo

    **Job specifics/responsibilities**: - Receive input from various event sources, investigate it for unusual and potentially malicious behavior that may indicate security incidents, and escalate any suspicious activity or anomalies to the Tier 2 SIRCC Analyst team; - During security incidents, liaise with the Tier 2 SIRCC Analyst and Tier 3 Incident...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Job DescriptionWe are seeking an experienced Incident Response Coordinator to join our team. As a key member of the Incident Response Team, you will be responsible for supporting client project implementation and Data Breach Response services.Key Responsibilities:Process orders and enrollment reports as directedHandle billing inquiries and finalize...


  • San Francisco, Heredia, Costa Rica Moody'S A tiempo completo

    Job SummaryWe are seeking a highly skilled Cybersecurity Incident Response Specialist to join our Moody's team. In this role, you will be responsible for investigating security incidents and events, using SIEM and other tools, to collect evidence and work with different teams to isolate and/or remediate as necessary.Key ResponsibilitiesAnalyze and correlate...


  • San José, San José, Costa Rica Smartsheet A tiempo completo

    Company Overview">Smartsheet is a leading cloud-based platform for work execution, empowering organizations to plan, capture, track, automate, and report on work at scale. Our company values include safeguarding information, protecting it from unauthorized access, and ensuring regulatory compliance. ">About the Role">We are seeking a skilled Security...


  • San José, San José, Costa Rica Akamai A tiempo completo

    About AkamaiAkamai is a leading provider of cloud-based security solutions that help organizations protect themselves against cyber threats.Job SummaryWe are seeking a highly skilled Network Security Incident Response Specialist to join our team. As a key member of our Security Operations Center, you will be responsible for responding to and mitigating cyber...

  • Data Loss Prevention

    hace 7 meses


    San José, Costa Rica GSB A tiempo completo

    **Key responsibilities**: - Monitor and analyze security alerts and events related to data loss prevention systems. - Investigate and respond to incidents of data loss, leakage, or unauthorized access. - Collaborate with cross-functional teams to assess the impact of security incidents and determine appropriate response actions. - Implement and maintain DLP...

  • Incidentes de Ti

    hace 1 día


    San José, Costa Rica Grupo CMA A tiempo completo

    ACERCA DE LA VACANTE Funciones del Puesto Cumplir el proceso de administración de incidentes (ciclo de vida del incidente) Menores y Mayores. Velar por el cumplimiento de los acuerdos de níveles de servicio para la atención de incidentes. Cumplir con el escalamiento definido del incidente para mitigar el impacto del incidente. Dar seguimiento al...

  • Incidentes de Ti

    hace 1 día


    San José, Costa Rica Grupo CMA A tiempo completo

    **Acerca de la vacante**: **Funciones del Puesto**: Cumplir el proceso de administración de incidentes (ciclo de vida del incidente) Menores y Mayores. Velar por el cumplimiento de los acuerdos de níveles de servicio para la atención de incidentes. Cumplir con el escalamiento definido del incidente para mitigar el impacto del incidente. Dar seguimiento al...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    About ExperianWe are the world's leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses, and society. We've been recognized as one of the 100 Best Companies to work for by FORTUNE and one of the 100 'World's Most Innovative Companies' by Forbes Magazine.As a forward-thinking...


  • San José, San José, Costa Rica Splunk A tiempo completo

    About the RoleWe are seeking a seasoned Incident Management Lead to join our team at Splunk. As a leader in incident management, you will be responsible for owning the response to high-profile customer impacting incidents.Key ResponsibilitiesTake command of incidents by setting up or taking over a technical bridge call with internal and external...


  • San José, San José, Costa Rica Splunk A tiempo completo

    Incident Prevention and Root Cause AnalysisSplunk is a leader in creating a safer and more resilient digital world. We achieve this through our unified security and observability platform, which enables enterprises to keep their digital systems secure and reliable.The role of the Problem Manager at Splunk is crucial in leading and remediating high severity...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    About the RoleThis is a critical position within Experian's Global Security Office (EGSO) - Global Cyber Incident Response Team (GCIRT), responsible for responding, containing, escalating, investigating, and coordinating mitigation of security events relative to anomalies detected and escalated by the Cyber Fusion Centre (CFC).ResponsibilitiesRespond to...

  • Sr Incident Commander

    hace 6 meses


    San José, Costa Rica Splunk A tiempo completo

    Splunk is here to build a safer and more resilient digital world. The world's leading enterprises use our unified security and observability platform to keep their digital systems secure and reliable. While customers love our technology, it's our people that make Splunk stand out as an amazing career destination and why we've won so many awards as a best...


  • San José, San José, Costa Rica Intel A tiempo completo

    At Intel, our Product Assurance and Security team is dedicated to building trust with our customers through unparalleled security, privacy, and assurance of our products. This team drives security governance, identifies emerging threats, secures existing products through mitigations, and defines future security innovations for our products.The Intel Product...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Job DescriptionExperian, a leading global information services company, is seeking a highly motivated Cybersecurity Threat Response Specialist to join our Global Security team at our Costa Rica facility.As a member of Experian's Global Security Office (EGSO) / Global Cyber Incident Response Team (GCIRT), this individual will respond, contain, escalate,...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    About the RoleWe are seeking an experienced Cyber Security Threat Response Team Lead to join our Global Cyber Incident Response Team (GCIRT) at Experian. As a member of this team, you will play a critical role in responding to and containing cyber security threats that impact Experian's information assets.


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    About UsAt Experian, we are the world's leading global information services company. We empower consumers and our clients to manage their data with confidence, making smarter decisions, and preventing identity fraud and crime.Job OverviewWe are seeking a highly skilled Cyber Security Threat Response Team Director to join our Global Security Office (EGSO)....


  • San José, Costa Rica Akamai A tiempo completo

    **Are you excited about detecting and mitigating the latest cyber attacks?** **Would you enjoy supporting the world's leading brands in a fast-paced environment?** **Join our world class Security Operations Command Center** Our industry-leading Security Operations Command Center (SOCC) protects our customers 24/7 against the growing threat of cyber-attacks...


  • San José, San José, Costa Rica Intel A tiempo completo

    Job OverviewWe are seeking a highly skilled Cybersecurity Threat Response Specialist to join our Intel Product Security Incident Response Team (PSIRT). As a member of this team, you will play a critical role in evaluating security vulnerabilities and advising product teams to ensure the highest level of product security.