← Back to jobs
Cuchilla de Padierna, Ciudad de México, CDMX, Mexico
No related jobs found
Position Overview
The Senior Information Security Engineer III is responsible for supporting and enhancing Cyber Detection capabilities, with a strong focus on centralized logging and monitoring. This role will lead efforts to migrate and optimize SIEM capabilities, transitioning from legacy platforms (e.g., Splunk, CRIBL, Syslog-NG) to CrowdStrike Falcon Next-Gen SIEM.
The position requires hands-on expertise in log onboarding, SIEM operations, data validation, and security monitoring within a highly regulated financial environment.
Key Responsibilities
SIEM Operations & Migration
Support U.S. SIEM operations and lead migration of log sources to CrowdStrike Falcon Next-Gen SIEM
Validate completeness and accuracy of log data based on volume, event types, and enriched fields
Enable and support data bifurcation between legacy SIEM platforms and CrowdStrike Falcon
Coordinate implementation of requirements for seamless data transition
Infrastructure & Data Flow Enablement
Coordinate firewall rules, network routing, proxy configurations, and DNS resolution to support SIEM migration
Validate bandwidth and proxy capacity requirements for log ingestion and data transfer
Monitor log ingestion pipelines and proactively identify and resolve outages
Log Source Onboarding & Validation
Configure and onboard log sources across cloud, SaaS, and on-prem environments
Implement required agents/clients (e.g., CrowdStrike, ONUM) on source systems
Analyze log data to ensure proper parsing, field extraction, and compliance with CIM standards
Validate successful migration of logs for regulatory and business-critical systems (e.g., SOX/GLBA applications, DB logs, authentication systems)
Monitoring & Optimization
Maintain and enhance dashboards, reports, and log coverage metrics
Develop and refine monitoring use cases to improve threat detection capabilities
Research and analyze log sources, particularly from security and networking devices
Documentation & Collaboration
Document and continuously improve log onboarding processes and standards
Provide system owners with logging requirements and configuration guidance
Collaborate with global cybersecurity and operations teams to implement scalable logging solutions
Contribute to centralized logging architecture, including ingestion layers, load balancing, and proxy configurations
Required Qualifications
5+ years of experience in SIEM operations, log onboarding, and centralized security logging (Splunk Enterprise Security preferred)
Hands-on experience with:
CrowdStrike Falcon Next-Gen SIEM
ONUM
CRIBL
Splunk (including SPL)
Python scripting
2+ years of experience working with:
Red Hat Linux
Windows environments
Experience with threat intelligence sharing platforms (e.g., FS-ISAC)
Bachelor’s degree in Cybersecurity, Computer Science, or related field (or equivalent experience)
Bilingual proficiency in English and Spanish
Core Competencies
Strong expertise in SIEM platforms and security monitoring processes
Experience with enterprise security and IT infrastructure tools:
Firewalls, Proxy, DNS, VPN
Active Directory, Windows, Linux
Familiarity with tools such as Jira, ServiceNow CMDB, and Confluence
Knowledge of log forwarding technologies (e.g., Syslog-NG, CRIBL, Splunk)
Understanding of cybersecurity frameworks and standards:
NIST Cybersecurity Framework
FFIEC Cybersecurity Assessment Tool (CAT)
Preferred Qualifications
Splunk User or Power User certification
SANS or equivalent cybersecurity certifications (e.g., GREM, GCIA, GCFA, GCIH)
Experience working in global, cross-functional teams across multiple time zones
Soft Skills
Strong analytical and problem-solving abilities
Excellent communication and documentation skills
Ability to present technical findings and security risks to diverse audiences
High attention to detail and organizational skills
Strong work ethic with a passion for cybersecurity
Any Graduate
No related jobs found
← Back to jobs