SOC Analyst L1
Guadalajara - Mexico
Job Summary
Are you ready to harness AI-driven security operations to outpace evolving threats and protect breakthroughs that change patients lives This role places you at the center of our mission to secure the data platforms and people that power discovery and delivery. You will help safeguard critical science and business operations through precision triage rapid response and disciplined execution.
You will join a high-ownership technology team that experiments with leading tools embraces agentic workflows and values evidence-led decision making. Here you will use Microsoft Sentinel Microsoft Defender and Security Copilot to accelerate investigations while ensuring human judgment stays in control. Can you picture yourself validating AI analysis at speed orchestrating response across global teams and turning insights into resilient defenses that scale
- - AI-Enabled Triage and Investigation: Validate AI-generated analysis distinguish true positives from false positives and investigate alerts using Microsoft Sentinel Microsoft Defender and SIEM platforms to drive timely high-quality decisions.
- - Incident Response Execution: Follow predefined runbooks/playbooks to handle standard alerts such as phishing malware and login anomalies; escalate complex cases and initiate response actions aligned to zero-trust and privacy requirements.
- - Security Copilot Governance: Manage human approval points for high-impact actions; critically evaluate Copilot-generated summaries KQL queries and recommendations; craft structured prompts and reusable investigation instructions to improve accuracy and repeatability.
- - Evidence and Forensics Support: Perform basic to intermediate malware analysis; analyze packet captures and network traffic; reconstruct timelines scope incidents identify affected entities and collect evidence to support root-cause analysis.
- - SIEM Monitoring and Continuous Improvement: Monitor SIEM tools (e.g. Microsoft Sentinel Splunk) ensure alerts are tracked and closed maintain detailed activity logs and incident tickets and contribute to refining detection logic and automation workflows.
- - Shift Operations and Handover Excellence: Operate within a 24x7 SOC model maintain meticulous shift handover notes and ensure seamless transitions so no alerts or incidents are missed.
- - Stakeholder Communication: Communicate clearly with technical and business stakeholders providing concise updates actionable recommendations and post-incident insights that reduce risk and strengthen trust.
- - 47 years cybersecurity; strong cloud security zerotrust and data privacy in regulated environments.
- - Strong expertise in SIEM technologies (Microsoft Sentinel Splunk QRadar).
- - Hands-on experience with Microsoft Defender XDR CrowdStrike Sentinel One or similar EDR tools.
- - Knowledge of Azure AWS and GCP security monitoring.
- - Experience in incident response and digital forensics.
- - Understanding of attack techniques malware behaviour and threat actor tactics.
- - Ability to analyze packet captures and network traffic.
- - Knowledge of SOAR platforms and automation workflows.
- - Experience with Basic scripting for customization (e.g. Powershell Python VB Scripting).
- - Participate in shift-based 24x7 SOC operations.
- - Practical experience using Microsoft Security Copilot to summarise incidents correlate alerts analyse entities generate investigation hypotheses create KQL queries interpret threat intelligence and recommend response actions.
- - Ability to critically evaluate Copilot-generated summaries queries recommendations classifications and response actions.
- - Ability to create structured prompts and reusable investigation instructions.
- - Use Copilot to accelerate but not replace incident scoping timeline reconstruction root-cause analysis affected-entity identification and evidence collection.
- - Strong analytical and problem-solving ability.
- - Clear communication with technical and business stakeholders.
- - Ability to prioritize and work in high-pressure environments.
- - Experience working with global/onshore-offshore teams.
- Certifications such as CISSP; CISM/CISA; CCSP; ISO 27001 Lead Implementer/Auditor; SC-200; SC-300; AZ-500; GCIH; GCIA; CEH; CompTIA CySA.
- Training in Security Copilot or Copilot Studio.
When we put unexpected teams in the same room we unleash bold thinking with the power to inspire life-changing -person working gives us the platform we need to connect work at pace and challenge perceptions. Thats why we work on average a minimum of three days per week from the office. But that doesnt mean were not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.
Why AstraZeneca:
Here your security expertise directly supports the science that reaches patients and you will do it with modern tools rich data and a collaborative mindset. You will be empowered to take ownership experiment in hackathons and shape how AI and automation elevate incident response all while working alongside diverse specialists who value curiosity and kindness as much as technical excellence. With the investment scale and ambition to move fast we bring unexpected teams together to solve problems once thought impossibleso your work fortifies outcomes that truly matter.
Bring your craft sharpen it with AI and help secure the breakthroughs that change livestake the next step and submit your application today.
Date Posted
02-sept-2026Closing Date
20-sept-2026AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds with as wide a range of perspectives as possible and harnessing industry-leading skills. We believe that the more inclusive we are the better our work will be. We welcome and consider applications to join our team from all qualified candidates regardless of their characteristics. We comply with all applicable laws and regulations on non-discrimination in employment (and recruitment) as well as work authorization and employment eligibility verification requirements.
Required Experience:
IC
About Company
AstraZeneca is an equal opportunity employer. AstraZeneca will consider all qualified applicants for employment without discrimination on grounds of disability, sex or sexual orientation, pregnancy or maternity leave status, race or national or ethnic origin, age, religion or belief, ... View more