Security Incident Response Incident Coordinator

hace 22 horas


San José, Costa Rica Dxc Technology A tiempo completo

The Security Incident Response Control Center (SIRCC) Incident Coordinator position will serve as the in-region coordinator for all DXC cyber security incidents.
Each follow-the-sun region will have a coordinator who will function in the incident coordination role in cooperation with the other coordinators in the other regions.
Security incidents will be handed off between coordinators as regions go off and come online for their normal working hours to ensure continuity of the incident response process.
Coordinator tasks consist of reviewing the work and consulting with the SIRCC analysts to ensure that a given security incident is being handled in an appropriate and expeditious manner according to its severity and risk.
**Job specifics/responsibilities**:

- Ensuring that security incidents are prioritized correctly and handled in a manner reflecting their priority.
- Ensuring tasks necessary to the verification, mitigation, remediation and reporting of security incidents are assigned to SIRCC analysts and progressing in a satisfactory manner.
- Ensuring higher priority incidents are continuing to progress as regions go offline and come on line in the follow-the-sun model in coordination with other regional incident coordinators.
- Ensuring the handoff of incident response activity from the regional shift before and after the region of responsibility.
- Ensuring the appropriate incident escalations and reporting are taking place in accordance with established policy and process guidance.
- On-call duties for escalation of Security Incidents
- Responsible for peer review, final approval, and delivery of significant incident reports (e.g.
Root Cause Analyses), management briefings, and incident updates
- Take the lead in management and technical update meetings during significant incidents, delegate tasks to the SIRCC analyst team members, to other security teams, and to other business units.
- Define the meeting timeframes and scheduling for all update briefings.
- Document action items carried out by the Incident Coordination team
- If required, task the SIRCC Incident Analyst team members to complete additional incident related actions outside of meetings
- Liaise with SIRCC Analysts to ensure that SIRCC action items are being actioned correctly, and provide guidance where necessary to facilitate the completion of such tasks
- Peer review and release of management alerts notifications.
- Use intelligence sources to proactively investigate the environment for threats and real or potential security breaches
- During incidents, lead reactive intelligence analysis, and once a basic methodology is established, hand over ongoing tasks to the SIRCC Analysts for continued analysis.
- Peer review results of the SIRCC Analysts analysis of intelligence (e.g.
correlation of logs from multiple tools)
- Liaise with other Incident Coordinators to allocate daily and longer term tasks between different coordinators
- Own security tools used by SIRCC and contribute to their strategic development
- Ongoing mentoring of SIRCC staff
- Implementation and management of minor SIRCC projects, and development and documentation of initial draft of project-related processes
- Liaise with SIRCC Manager to completely develop and implement new processes as required
- Work with the SIRCC Manager to develop acceptance criteria, SLA's, processes, and procedures as required for new tasks and processes being assigned to the SIRCC team by management

**Technical skills**
- Experience with gathering Open Source Intelligence (OSINT)
- Understanding of the requirements for security audit processes/frameworks, such as SOX, SAS70, or ISO27001
- Experience with programming languages such as Python, Perl, Java or C++
- The ability to perform an in-depth analysis of log files from multiple devices and environments and identify indicators of security threats.
- Solid knowledge of common types of Information Security threats.
- In-depth understanding of TCP, IP, and other lower-level network protocols, as well as common higher-level protocols such as HTTP, HTTPS, SMTP, FTP, and others.
The ability to conduct an in-depth analysis of network traffic and packet captures.
- Strong familiarity with network security devices, including firewalls, Intrusion Detection/Prevention Systems, proxies, switches, routers, and others.
Understanding of modern network operating systems.
- Understanding of, and experience using, Unix-style operating systems, such as Solaris, Linux, or BSD.
- Current or recent experience working with enterprise level anti-malware or advanced endpoint protection packages.
- Experience with Operating System security, administration, and logging in an enterprise environment.
- Previous experience with process and procedure development.
- Experience dealing with cybercrime and working in an environment that requires an investigative response when dealing with computer-based electronic evidence.
- Fluent in written and verbal English



  • San José, Costa Rica Dxc Technology A tiempo completo

    **Job specifics/responsibilities**:- Receive input from various event sources, investigate it for unusual and potentially malicious behavior that may indicate security incidents, and escalate any suspicious activity or anomalies to the Tier 2 SIRCC Analyst team;- During security incidents, liaise with the Tier 2 SIRCC Analyst and Tier 3 Incident Coordinator...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Company Overview:Experian, a global information services company, empowers consumers and clients to manage data with confidence. We provide financial control, access to financial services, help businesses make informed decisions, lenders lend responsibly, and organizations prevent identity fraud.**Job Summary:**We seek an experienced Cyber Security Incident...


  • San Francisco, Heredia, Costa Rica Grupo Preselección A tiempo completo

    About UsGrupo Preselección is a dynamic organization that thrives in a fast-paced, on-call environment. We value innovation and collaboration.Salary and BenefitsOur competitive compensation package includes a monthly salary of ¢600,000.00.About the JobWe are seeking a highly skilled Cybersecurity Incident Response Specialist to join our team. As a key...


  • San José, Costa Rica Splunk A tiempo completo

    Join us as we pursue our vision to make machine data accessible, usable and valuable to everyone. We are a company filled with people who are passionate about our product and seek to deliver the best experience for our customers. At Splunk, we’re committed to our work, customers, having fun, and most importantly to each other’s success. Learn more about...

  • Data Loss Prevention

    hace 22 horas


    San José, Costa Rica Global Services Business A tiempo completo

    You will work closely with various teams to identify, assess, and mitigate risks associated with data breaches or unauthorized access.Your role will involve implementing DLP solutions, analyzing security events, and developing strategies to enhance data protection measures.**Key responsibilities**:Monitor and analyze security alerts and events related to...

  • Data Loss Prevention

    hace 22 horas


    San José, Costa Rica Gsb A tiempo completo

    **Key responsibilities**:- Monitor and analyze security alerts and events related to data loss prevention systems.- Investigate and respond to incidents of data loss, leakage, or unauthorized access.- Collaborate with cross-functional teams to assess the impact of security incidents and determine appropriate response actions.- Implement and maintain DLP...


  • San Francisco, Heredia, Costa Rica Ibm A tiempo completo

    About the RoleWe are seeking a highly skilled Cyber Security Response Lead to join our team. In this role, you will be responsible for coordinating with security teams to investigate and respond to cyber-related threats.You will oversee the root cause analysis process, ensure preventative actions are taken, and enforce security policies. Your expertise in...


  • San José, Costa Rica Cloud Software Group A tiempo completo

    Key Responsibilities - Incident Management - Lead cross-functional response to high priority, high visibility, complex critical incidents. - Calmly assess situations and command flawless execution of the incident response process to high-profile, high-impact escalations, to drive customer loyalty - Ensure the flow of information by pulling in appropriate...


  • San José, Costa Rica Cloud Software Group A tiempo completo

    Key Responsibilities Incident Management - Lead cross-functional response to high priority, high visibility, complex critical incidents. - Calmly assess situations and command flawless execution of the incident response process to high-profile, high-impact escalations, to drive customer loyalty - Ensure the flow of information by pulling in appropriate...

  • Sr Incident Commander

    hace 4 horas


    San José, Costa Rica Splunk A tiempo completo

    Splunk is here to build a safer and more resilient digital world.The world's leading enterprises use our unified security and observability platform to keep their digital systems secure and reliable.While customers love our technology, it's our people that make Splunk stand out as an amazing career destination and why we've won so many awards as a best place...


  • San Francisco, Heredia, Costa Rica Cloud Software Group A tiempo completo

    Job SummaryWe are seeking a seasoned Support Incident Manager to lead our cross-functional response to high-priority incidents.About the RoleThis is a dynamic position that requires excellent communication skills, strong problem-solving abilities, and experience in incident management. You will be responsible for assessing situations, commanding flawless...


  • San Francisco, Heredia, Costa Rica Grupo Preselección A tiempo completo

    Company OverviewGrupo Preselección is a leading organization that specializes in cybersecurity and information security. We are committed to providing top-notch services and expertise to our clients. Job DescriptionWe are seeking a highly skilled Cybersecurity Incident Analyst to join our team. As a key member of our incident response team, you will be...


  • San Francisco, Costa Rica Cloud Software Group A tiempo completo

    Key Responsibilities Incident Management - Lead cross-functional response to high priority, high visibility, complex critical incidents. - Calmly assess situations and command flawless execution of the incident response process to high-profile, high-impact escalations, to drive customer loyalty - Ensure the flow of information by pulling in appropriate...


  • San José, Costa Rica Akamai A tiempo completo

    **Are you excited about detecting and mitigating the latest cyber attacks?****Would you enjoy supporting the world's leading brands in a fast-paced environment?****Join our world class Security Operations Command Center**Our industry-leading Security Operations Command Center (SOCC) protects our customers 24/7 against the growing threat of cyber-attacks and...


  • San José, Costa Rica Emerson A tiempo completo

    As a Product Security Project Coordinator, you will be a member of our Global Cybersecurity team and play an important role in continuing to strengthen the cybersecurity posture of Emerson Commercial and Residential Solutions’ products. - You will work with software engineering teams and product owners to identify, capture, escalate, and remediate security...

  • Senior Security Engineer

    hace 22 horas


    San José, Costa Rica Microsoft A tiempo completo

    **Responsibilities**:**Qualifications**:**Required/Minimum Qualifications**:5+ years of experience in software development lifecycle, large-scale computing, modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), and operations...

  • Security Analyst

    hace 22 horas


    San José, Costa Rica Smartsheet A tiempo completo

    Cyber Security is an integral part of Smartsheet's corporate culture.At Smartsheet, we believe that it is the responsibility of each and every employee to safeguard information, protect it from unauthorized access, and ensure regulatory compliance.Cyber Security has a significant effect on privacy, consumer trust, external reputation, and it is a priority on...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    At Experian, we are the world's leading global information services company. We empower consumers and our clients to manage their data with confidence.We help individuals take financial control and access financial services, businesses make smarter decisions and thrive, lenders lend more responsibly, and organizations prevent identity fraud and crime.**Job...


  • San José, Costa Rica Vs-Staffing A tiempo completo

    **Network Security Engineer****Job Description**:**Title**:Network Security Engineer**Location**:Remote, based in Costa Rica**Job Overview**:Faced with an ever-increasing cyber-security threat, organizations need to maintain a vigilant approach to protect their systems and data, and Security Engineers play a key role in this process.You will be responsible...


  • San José, Costa Rica Western Union A tiempo completo

    IT Manager, Major Incident Management – Santa Ana, Costa RicaAre you ready to join a team in a global company where you will execute strategic functions to implement high-end, business-wide, critical strategy and manage one of the critical IT Service Management processes as a part of the Global Technology Organization?Are you interested in joining a...