Cyber Security Analyst

Stefanini Latamgupypublished 08/19/2026
Must-have:PythonAWSAzureCloudQA/TestSecurity
Machine translation — original language: Spanish.Show original

Cyber Security Analyst, professional in Systems Engineering, Electronics, Telecommunications or related fields, with a minimum of 2 years of experience in cybersecurity. The position will be responsible for supporting integral vulnerability management, performing analysis, prioritization, monitoring, and validation of remediations; as well as the coordination and monitoring of security tests, including internal and external Ethical Hacking and application testing, social engineering, Red Team, and attack simulations. They will participate in defining scopes, validation and QA of tests, preparation and socialization of reports, monitoring of findings, and security validations for new applications. Additionally, they will provide specialized N3 support to the SOC, supporting the analysis of events, incidents, and suspicious processes. Knowledge in vulnerability management, Ethical Hacking, log analysis, application security, networks, Windows/Linux, SIEM, and security solutions is required. Experience with tools such as Tenable/Nessus, Burp Suite, Nmap, as well as knowledge in OWASP, CVSS, MITRE ATT&CK, and scripting will be valued. The position includes participation in a 7x24 on-call scheme, according to the established schedule. We are looking for an analytical, proactive, autonomous person, with customer orientation, monitoring capacity, and good communication skills.

Responsibilities and attributions

We are looking for a Cyber Security Analyst responsible for supporting integral vulnerability management, security testing, and specialized attention to cybersecurity events and incidents. Their main responsibilities include:

  • Managing the vulnerability lifecycle, from identification, analysis, and prioritization to remediation monitoring and closure validation.
  • Coordinating and participating in security tests such as internal and external Ethical Hacking, application testing, social engineering, Red Team, and attack simulations.
  • Defining and managing the technical scope of security tests, coordinating their execution with the different teams involved.
  • Performing validation and QA activities for findings, results, and security reports.
  • Preparing technical and executive reports, indicators, and progress reports, as well as socializing results.
  • Participating in the security evaluation of new applications and services, identifying risks, and recommending mitigation controls.
  • Analyzing logs, alerts, suspicious processes, indicators of compromise, and other security evidence.
  • Handling N3 escalations from the SOC, supporting the analysis of events and incidents that require a higher level of specialization.
  • Participating in the 7x24 on-call scheme, according to the established schedule.
  • Performing technical monitoring of assigned activities, ensuring their continuity, documentation, and closure.
  • Participating in technical meetings with clients and internal teams, maintaining clear communication regarding progress, risks, and required actions.

Expected experience

Professional in Systems Engineering, Electronics, Telecommunications, or related fields, with a minimum of 2 years of experience in cybersecurity, preferably in vulnerability management, Ethical Hacking, SOC, or incident analysis.

Experience or knowledge is expected in vulnerability management and scanning tools, log analysis, SIEM, EDR/XDR, network and application security, as well as fundamentals of OWASP, CVE/CVSS, MITRE ATT&CK, Windows/Linux, TCP/IP networks, and scripting.

Requirements and qualifications

  • Professional in Systems Engineering, Electronics, Telecommunications, Informatics, or related fields.
  • Minimum 2 years of experience in cybersecurity, preferably in vulnerability management, Ethical Hacking, SOC, incident analysis, or application security.
  • Knowledge of vulnerability management and scanning tools such as Tenable/Nessus, Qualys, Rapid7, or similar.
  • Handling or knowledge of offensive security and analysis tools such as Burp Suite, Nmap, Metasploit, or equivalents.
  • Knowledge of SIEM platforms, log analysis and correlation, as well as EDR/XDR, Firewall, WAF, IDS/IPS, and other security technologies.
  • Knowledge of OWASP Top 10, CVE/CVSS, MITRE ATT&CK, hardening, and incident response fundamentals.
  • Knowledge of Windows/Linux, TCP/IP networks, application security, and Cloud fundamentals (Azure/AWS).
  • Desirable knowledge of scripting with Python, PowerShell, or Bash for analysis and task automation.
  • Desirable specialization, diploma, or courses in Cybersecurity, Ethical Hacking, Vulnerability Management, Offensive Security, or Incident Response.
  • Certifications such as CompTIA Security+, CEH, eJPT, OSCP, or equivalent certifications related to cybersecurity will be valued.
  • Technical English, especially for interpreting documentation, advisories, vulnerabilities, and manufacturer documentation.
  • Analytical and problem-solving skills, effective communication, report writing, teamwork, autonomy, proactivity, customer orientation, and monitoring of activities until closure.
  • Availability to participate in a 7x24 on-call scheme, according to the operation's schedule.

Additional information