SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Join Novartis' Cyber Security Operations Center (CSOC) as a Threat Detection & Response Senior Specialist. This role is central to the company's active defense against sophisticated IT security threats and attacks affecting networks, systems, users, and applications globally.
You will monitor security controls and consoles in real time across the Novartis IT ecosystem, detect and investigate security incidents, and coordinate response activities with technical and non-technical teams. Key responsibilities include forensics and incident response (scoping, communication, reporting, remediation planning), host-based and network packet analysis, malware analysis, and SIEM/big data analysis to identify abnormal activity and extract insights.
You will work with engineering teams to design, test, and implement playbooks, orchestration workflows, and automations. You'll develop and maintain documentation including response playbooks and processes, perform quality assurance reviews of analyst investigations, and develop incident analysis reports for management with gap identification and improvement recommendations.
This is a mentoring role: you will provide guidance to junior staff and serve as a point of escalation for higher-severity incidents, though you will not have direct people management responsibility. You'll also research and test new security technologies and platforms, recommend improvements, and tune existing sensors and security controls.
Required: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience. 3+ years in cybersecurity with significant incident response, threat detection, or security operations experience. Strong hands-on enterprise incident investigation and response skills. Deep understanding of attacker techniques across endpoint, identity, network, cloud, and email surfaces. Experience in a CSOC, SOC, or incident response function in large, complex organizations. Strong knowledge of security operations workflows, alert triage, escalation management, and response coordination. Experience with SIEM, EDR/XDR, email security, identity monitoring, and case management tools. Ability to analyze logs, alerts, and forensic artifacts. Strong written and verbal communication skills.
Desirable: Scripting experience (Python, PowerShell, Bash), malware analysis or reverse engineering experience. The role is hybrid, requiring approximately 12 days per month in the Mexico City office.