Agentic Detection
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Al continuar, aceptas nuestros Términos & Política de Privacidad.
Overview
In this role you will advance security operations beyond traditional incident response by integrating AI-driven investigations, automation, and agentic security workflows. You'll lead complex investigations while shaping detection engineering and response capabilities to reduce alerts and improve efficiency. Partner with security architects to deploy AI-assisted techniques and SOAR-driven playbooks. This position offers the chance to impact how a growing SOC scales with automation and intelligent workflows.
Compensaciones / Beneficios Fully remote work (optional)
Flexible schedule
Flexible compensation (transport, childcare)
Health insurance with dental co-payment
Training budget and Microsoft certifications
English lessons
Responsabilidades Lead complex incident investigations and advanced security escalations
Analyze activity across endpoint, identity, network, cloud, and SIEM to determine scope and response actions
Design, build, and improve detection rules, correlation logic, and investigation queries
Develop security automations, integrations, and SOAR playbooks to streamline workflows
Collaborate with security architects and engineers to implement AI-assisted and agentic security capabilities
Identify opportunities to apply AI for investigation support, enrichment, evidence summarization, and response recommendations
Act as technical reference for L1 and L2 analysts to improve escalations, procedures, and maturity
Drive continuous improvement to reduce alert fatigue, increase detection quality, and improve response efficiency
Requisitos principales 6+ years of SOC experience with solid L3 investigations or advanced escalations
Strong background in Incident Response, Threat Hunting, Detection Engineering, and Security Operations
Experience investigating threats across endpoint, identity, network, and cloud
Hands-on experience with SIEM and EDR/XDR technologies
Strong query skills using KQL, SPL, or equivalent
Experience with Microsoft Sentinel, Microsoft Defender XDR, or similar platforms
Scripting and automation experience with Python, PowerShell, APIs, or SOAR
Interest in applying AI and agentic security concepts to real-world operations
Ability to own initiatives from idea to implementation and collaborate across teams
Fluent in Spanish and English
Collaborative mindset
Proactive problem-solving
Clear communication across technical and non-technical stakeholders
KQL
SPL
SIEM