Security Analyst
Aplazo
IT
Mexico City, Mexico
Posted on Aug 13, 2025
Role’s Mission
The Security Analyst plays a key role in strengthening Aplazo’s cybersecurity posture. The main mission of this role is to protect the company’s technological assets through continuous monitoring, technical analysis, regulatory compliance, and offensive security testing. This position has a direct impact on risk reduction, adherence to standards such as ISO 27001, and efficient incident response.
Key responsibilities
Incident Response:
- Monitor, detect, investigate, and respond to security incidents.
- Manage tools such as SIEM, EDR, and alert systems.
- Perform basic forensic analysis and document technical findings.
- Coordinate incident handling with other departments (IT, Legal, Product, etc.).
Compliance:
- Support internal and external audits (ISO 27001, SOC 2, PCI-DSS, among others).
- Ensure adherence to security policies, standards, and procedures.
- Participate in risk management and internal controls.
Cloud Security:
- Assess and strengthen secure configurations in cloud environments.
- Perform periodic reviews of permissions, identities, and exposed services.
- Collaborate with DevOps and development teams to ensure secure pipelines.
- Automate security processes.
Vulnerability Assessment and Pentesting:
- Perform vulnerability scans (e.g., Nessus, OpenVAS).
- Participate in internal and external penetration tests.
- Identify weaknesses in applications, networks, and infrastructure.
- Document findings and follow up on remediation actions with responsible teams.
Requirements
Must have:
Experience:
- Minimum 2 years in information security-related roles.
Technical skills:
- Familiarity with frameworks such as OWASP, MITRE ATT&CK, NIST, ISO 27001.
- Experience with tools like Burp Suite, Wireshark, Nessus, ZAP.
- Solid knowledge of operating systems (Linux/Windows) and networks.
- Hands-on experience in cloud environments.
- Familiarity with incident response and forensic analysis processes.
Soft skills:
- High attention to detail.
- Ability to clearly communicate technical findings.
- Team collaboration and cross-functional coordination.
Academic background (studies or certifications):
- Bachelor’s degree in Systems, Cybersecurity, Computer Science, or related fields.
Nice to have:
- Certifications: Security+, CEH, AWS Security, ISO 27001 LI.
- Scripting knowledge: Python, Bash, PowerShell.
- Experience in automating security processes.
Languages:
- Spanish: Native
- English: Intermediate