远程工作雷达

高级网络安全防御专家

Senior Cybersecurity Defense Specialist

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司TD SYNNEX
薪资未公开
工作地点Mexico
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 Mexico 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

职位职责:
高级网络安全专家负责在全球范围内设计、实施和管理安全技术解决方案。在涉及多学科IT安全项目的领导或作为有经验的技术资源,旨在持续改进安全基础设施和操作流程。掌握最新技术,并识别利用这些技术提升TD SYNNEX网络保护、检测和响应能力的机会。职责包括审查TD SYNNEX所有运营地区的现有安全措施和流程,通过渗透测试和红队演练识别并解决弱点,及时应对可能的安全漏洞。持续改进身份与访问管理、威胁狩猎与分析、漏洞管理、安全监控和事件响应的核心流程,涵盖本地和云环境。编写操作规程和运行手册,并培训支持团队。
关于团队:
安全自动化工程小组是未来全栈安全工程功能的体现。它将SIEM专长、SOAR自动化、检测工艺和AI/ML熟练度融合到一个高速运作的小组中——通过智能系统作为增效工具,在安全运营堆栈的每一层进行构建、自动化和检测。与其他工程小组不同,该小组将AI视为原生的、第一类的能力,融入每个工作流:这些工程师不仅使用AI工具,还构建、调整和管理它们。该团队支持一家拥有25,000名员工的企业。
职位概述
一名全栈安全工程师,能够在SIEM管理、剧本开发、检测规则创建和AI系统实施之间灵活运作。负责一个领域重点,同时保持跨学科能力。
主要职责

  • 使用ML异常模型、LLM生成的Sigma/SPL/KQL以及行为分析开发和部署基于AI的检测规则。
  • 构建利用LLM推理的智能SOAR剧本,实现动态决策和自适应响应。
  • 实施并优化基于AI的警报优先级系统——基于ML分类器的自动评分、丰富和路由。
  • 管理SIEM平台组件:索引优化、搜索性能和数据模型维护。
  • 设计提示工程框架和评估机制
查看英文原文

Job Purpose:
The Senior Cyber Security Specialist is responsible for designing, implementing and managing security technology solutions globally. Leads or serves as experienced technical resource in multi-discipline IT security projects intended to continually improve the security infrastructure and operating procedures. Keeps abreast of the latest technologies and identifies opportunities to leverage them to improve TD SYNNEX's cyber protection, detection and response capabilities. The responsibilities include reviewing our current security measures and processes in all geographies TD SYNNEX operates in, identifying and addressing areas of weakness through penetration testing and red teaming, and responding promptly to possible security breaches. Continuously improves core processes in identity & access management, threat hunting and analysis, vulnerability management, security monitoring and incident response both on-premise and in the cloud. Documents operating procedures and run books and trains the support team(s).
ABOUT THE TEAM:
The Security Automation Engineering pod is the full-stack security engineering function of the future. It blends SIEM mastery, SOAR automation, detection craft, and AI/ML fluency into a single high-velocity pod — building, automating, and detecting across every layer of the security operations stack with intelligent systems as its force multiplier. Unlike other engineering pods where AI is an enhancement opportunity, this pod treats AI as a native, first-class capability woven into every workflow: these engineers don't just use AI tools — they build, tune, and govern them. The team supports a 25,000-employee enterprise.
POSITION SUMMARY
A full-stack security engineer who operates fluidly across SIEM administration, playbook development, detection rule creation, and AI system implementation. Owns a domain focus area while maintaining cross-functional capability across all disciplines.
KEY RESPONSIBILITIES

  • Develop and deploy AI-powered detection rules using ML anomaly models, LLM-generated Sigma/SPL/KQL, and behavioral analytics.
  • Build intelligent SOAR playbooks that leverage LLM reasoning for dynamic decision-making and adaptive response.
  • Implement and tune AI-driven alert triage systems — automated scoring, enrichment, and routing based on ML classifiers.
  • Manage SIEM platform components: index optimization, search performance, and data model maintenance.
  • Design prompt engineering frameworks and evaluation harnesses for security-focused LLM applications.
  • Build RAG (Retrieval-Augmented Generation) pipelines using internal security knowledge bases, runbooks, and threat intel.
  • Conduct AI-augmented threat hunting — using LLMs to generate hypotheses and ML to identify anomalous patterns at scale.
  • Develop and maintain CI/CD pipelines for detection rules, playbooks, and ML model deployments.

Responsibilities:

  • Technical design, implementation, enhancement and ongoing support for security technologies (30%)
  • Executes and continually improves core security processes such as vulnerability management, threat analysis, security monitoring and incident response, identity and access management(10%)
  • AppSec reviews, penetration testing and red teaming activities to identify gaps and weaknesses. Utilize red team learnings to improve detection capabilities and response automation (20%)
  • Process automation, orchestration for improving team efficiency, documentation and training(20%)
  • Data analytics and KPI reporting for ensuring operational effectiveness and controls health (10%)
  • Collects, processes, preserves, analyzes, and presents computer-related evidence in support of breaches, vulnerability mitigation and/or criminal, fraud, counterintelligence, or law enforcement investigations. (10%)

Knowledge, Skills and Experience:

  • Bachelor's Degree with IT field of study required.
  • 8 to 10 Years of relevant work experience.
  • 5+ years in security engineering with demonstrated cross-domain experience (SIEM + SOAR or SIEM + Detection).
  • Proficiency in SIEM query languages (SPL, KQL) AND SOAR playbook development (Python, low-code platforms).
  • Experience building or integrating AI/ML models for security use cases.
  • Strong Python skills with familiarity in ML frameworks (scikit-learn, PyTorch) and LLM APIs.
  • Detection engineering experience: Sigma rules, MITRE ATT&CK mapping, rule tuning methodology.
  • Git-based workflow proficiency for detection-as-code and infrastructure-as-code.
  • Other Education / Certifications: selection of security and technology certifications and/or equivalent proven work experience
  • Able to recognize and attend to important details with accuracy and efficiency.
  • Able to communicate clearly and convey necessary information.
  • Able to converse and write effectively in English and local language.
  • Able to create and conduct formal presentations.
  • Able to interact effectively with all levels of management
  • Possesses strong multi-cultural interpersonal skills.
  • Possesses strong leadership skills with a willingness to lead, create new ideas, and be assertive.
  • Possesses strong organizational and time management skills, driving tasks to completion.
  • Able to constructively work under stress and pressure when faced with high workloads and deadlines.
  • Able to maintain and promote social, ethical, and organizational standards in conducting internal and external business activities.
  • Able to work independently with minimum supervision.
  • Able to exhibit ability to be sensitive to the needs, concerns, and feelings of others.
  • Able to quickly learn new systems and technology.
  • Able to use relevant computer system applications at an advanced level.

Working Conditions:

  • Occasional non-standard work hours or overtime as business requires.
  • On-call availability required as necessary.
  • Some travel required.

At TD SYNNEX, our values guide everything we do: Together, We Own It, We Dare to Go, We Grow and Win, and above all, We Do the Right Thing. These principles shape how we work with each other, our partners, and our communities as we drive innovation and create lasting impact.
What’s In It For You?

  • Elective Benefits: Our programs are tailored to your country to best accommodate your lifestyle.
  • Grow Your Career: Accelerate your path to success (and keep up with the future) with formal programs on leadership and professional development, and many more on-demand courses.
  • Elevate Your Personal Well-Being: Boost your financial, physical, and mental well-being through seminars, events, and our global Life Empowerment Assistance Program.
  • Diversity, Equity & Inclusion: It’s not just a phrase to us; valuing every voice is how we succeed. Join us in celebrating our global diversity through inclusive education, meaningful peer-to-peer conversations, and equitable growth and development opportunities.
  • Make the Most of our Global Organization: Network with other new co-workers within your first 30 days through our onboarding program.
  • Connect with Your Community: Participate in internal, peer-led inclusive communities and activities, including business resource groups, local volunteering events, and more environmental and social initiatives.

Don’t meet every single requirement? Apply anyway.
At TD SYNNEX, we’re proud to be recognized as a great place to work and a leader in the promotion and practice of diversity, equity and inclusion. If you’re excited about working for our company and believe you’re a good fit for this role, we encourage you to apply. You may be exactly the person we’re looking for!
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级项目经理,IT

TD SYNNEXUnited States$105,000/年Full Time今天
职能支持限定地区(需当地身份)

← 返回全部职位