Vidare till huvudinnehåll
Sök

SOC Analyst L1

Plats Zapopan, Jalisco, Mexico Jobb-id R-259326 Datum inlagd 09/02/2026

Are you ready to harness AI-driven security operations to outpace evolving threats and protect breakthroughs that change patients’ lives? This role places you at the center of our mission to secure the data, platforms and people that power discovery and delivery. You will help safeguard critical science and business operations through precision triage, rapid response and disciplined execution.

You will join a high-ownership technology team that experiments with leading tools, embraces agentic workflows and values evidence-led decision making. Here, you will use Microsoft Sentinel, Microsoft Defender and Security Copilot to accelerate investigations while ensuring human judgment stays in control. Can you picture yourself validating AI analysis at speed, orchestrating response across global teams and turning insights into resilient defenses that scale?

Accountabilities:

  • - AI-Enabled Triage and Investigation: Validate AI-generated analysis, distinguish true positives from false positives and investigate alerts using Microsoft Sentinel, Microsoft Defender and SIEM platforms to drive timely, high-quality decisions.
  • - Incident Response Execution: Follow predefined runbooks/playbooks to handle standard alerts such as phishing, malware and login anomalies; escalate complex cases and initiate response actions aligned to zero-trust and privacy requirements.
  • - Security Copilot Governance: Manage human approval points for high-impact actions; critically evaluate Copilot-generated summaries, KQL queries and recommendations; craft structured prompts and reusable investigation instructions to improve accuracy and repeatability.
  • - Evidence and Forensics Support: Perform basic to intermediate malware analysis; analyze packet captures and network traffic; reconstruct timelines, scope incidents, identify affected entities and collect evidence to support root-cause analysis.
  • - SIEM Monitoring and Continuous Improvement: Monitor SIEM tools (e.g., Microsoft Sentinel, Splunk), ensure alerts are tracked and closed, maintain detailed activity logs and incident tickets, and contribute to refining detection logic and automation workflows.
  • - Shift Operations and Handover Excellence: Operate within a 24x7 SOC model, maintain meticulous shift handover notes and ensure seamless transitions so no alerts or incidents are missed.
  • - Stakeholder Communication: Communicate clearly with technical and business stakeholders, providing concise updates, actionable recommendations and post-incident insights that reduce risk and strengthen trust.

Essential Skills/Experience:

  • - 4–7 years cybersecurity; strong cloud security, zero‑trust, and data privacy in regulated environments.
  • - Strong expertise in SIEM technologies (Microsoft Sentinel, Splunk, QRadar).
  • - Hands-on experience with Microsoft Defender XDR, CrowdStrike, Sentinel One, or similar EDR tools.
  • - Knowledge of Azure, AWS, and GCP security monitoring.
  • - Experience in incident response and digital forensics.
  • - Understanding of attack techniques, malware behaviour, and threat actor tactics.
  • - Ability to analyze packet captures and network traffic.
  • - Knowledge of SOAR platforms and automation workflows.
  • - Experience with Basic scripting for customization (e.g., Powershell, Python, VB Scripting).
  • - Participate in shift-based 24x7 SOC operations.
  • - Practical experience using Microsoft Security Copilot to summarise incidents, correlate alerts, analyse entities, generate investigation hypotheses, create KQL queries, interpret threat intelligence and recommend response actions.
  • - Ability to critically evaluate Copilot-generated summaries, queries, recommendations, classifications and response actions.
  • - Ability to create structured prompts and reusable investigation instructions.
  • - Use Copilot to accelerate, but not replace incident scoping, timeline reconstruction, root-cause analysis, affected-entity identification and evidence collection.
  • - Strong analytical and problem-solving ability.
  • - Clear communication with technical and business stakeholders.
  • - Ability to prioritize and work in high-pressure environments.
  • - Experience working with global/onshore-offshore teams.

Desirable Skills/Experience:

  • - Certifications such as CISSP; CISM/CISA; CCSP; ISO 27001 Lead Implementer/Auditor; SC-200; SC-300; AZ-500; GCIH; GCIA; CEH; CompTIA CySA+.

  • - Training in Security Copilot or Copilot Studio.

When we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.

Why AstraZeneca:Here, your security expertise directly supports the science that reaches patients, and you will do it with modern tools, rich data and a collaborative mindset. You will be empowered to take ownership, experiment in hackathons and shape how AI and automation elevate incident response, all while working alongside diverse specialists who value curiosity and kindness as much as technical excellence. With the investment, scale and ambition to move fast, we bring unexpected teams together to solve problems once thought impossible—so your work fortifies outcomes that truly matter.

Bring your craft, sharpen it with AI and help secure the breakthroughs that change lives—take the next step and submit your application today.

Date Posted

02-sept-2026

Closing Date

20-sept-2026

AstraZeneca embraces diversity and equality of opportunity.  We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills.  We believe that the more inclusive we are, the better our work will be.  We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics.  We comply with all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.



AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We comply with all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorisation and employment eligibility verification requirements.

Gå med i vårt talangnätverk

Bli först med att få jobbuppdateringar och nyheter från AstraZeneca

Registrera
Glassdoor logo Rated four stars on Glassdoor

Härlig kultur, stimulerande arbetsuppgifter, stöttande ledarskap. Utvecklings möjligher inom företaget. Vi värdesätter inkludering och mångfald.