Apply Edge Start your job search

Senior Cybersecurity Operations Analyst

Kruger Inc. · Medellín Metropolitan Area

Apply & track with Apply Edge

POSITION SUMMARYReporting to the Manager, Cybersecurity Operations, the Senior Cybersecurity Operations Analyst is a key technical leader who supports cybersecurity operations, including incident response, threat monitoring, vulnerability management, operational process optimization, and risk-based guidance for IT and business stakeholders.Beyond day-to-day operations, this role provides strategic input into security roadmap decisions and the development of operational playbooks and processes. The role also ensures that operational security practices align with business risks and compliance requirements.RESPONSIBILITIESSecurity Incident and Service Request ManagementLead the analysis and resolution of complex cybersecurity incidents and service requests.Conduct technical investigations and root cause analyses, and develop post-incident recommendations.Monitoring and Event AnalysisSupport and optimize cybersecurity platforms used for monitoring, detection, endpoint protection, vulnerability management, and data protection.Analyze security events, logs, vulnerability data, and anomalies to identify threats and risk exposure.Translate technical findings into risk-based recommendations for IT and business stakeholders.Vulnerability and Risk Exposure ManagementIdentify, assess, and prioritize vulnerabilities across IT, OT, cloud, and endpoint environments.Coordinate remediation follow-ups with technical and business teams based on risk and asset criticality.Track vulnerability KPIs, exceptions, risk acceptance decisions, and improvements to remediation processes.Support cloud security posture management by assessing misconfigurations, identity risks, and exposure across cloud services.Operational Process and Playbook OptimizationMaintain and improve incident response playbooks, operational procedures, and security processes.Support operational readiness through exercises, testing, and alignment with industry standards and compliance frameworks.Provide guidance on integrating security controls into IT and OT environments.Cross-Functional ContributionsAct as a cybersecurity subject matter expert and support IT teams, projects, audits, and risk assessments.Contribute to the security roadmap, technology evaluations, and security maturity improvements.Support security awareness, stakeholder engagement, and after-hours response to high-severity incidents.QUALIFICATIONSACADEMICBachelor’s degree in computer science, information security, or a related field.Advanced industry certifications are strongly preferred, including CISSP, CISM, GIAC (GCIA, GCFA, or equivalent), Microsoft Azure Fundamentals (AZ-900), Microsoft Azure Security Engineer Associate (AZ-500), or other relevant cloud security certifications such as CCSP, AWS Certified Security – Specialty, or Google Professional Cloud Security Engineer.EXPERIENCESeven (7) years or more of experience in cybersecurity.Demonstrated experience supporting cybersecurity operations, including incident response, vulnerability management, security monitoring, and continuous improvement of security processes.SKILLS AND ABILITIESTechnical SkillsAdvanced expertise with security monitoring and analysis tools, including SIEM, EDR, firewalls, and DLP solutions.Strong knowledge of vulnerability and exposure management practices, including CVSS, exploitability, asset criticality, remediation service levels, compensating controls, exceptions, and risk acceptance workflows.Hands-on experience with digital forensics, malware analysis, and advanced investigation techniques.Strong knowledge of network protocols, Windows and Linux operating systems, and enterprise applications.Strong knowledge of cloud security principles, including identity and access management, secure configuration, logging, and cloud security posture management.Solid understanding of attack vectors, adversary tactics described in MITRE ATT&CK, and defensive strategies.Familiarity with security architecture, asset classification, and risk management frameworks.Ability to correlate vulnerabilities with asset criticality, threat intelligence, and business impact.Non-Technical SkillsDemonstrated ability to lead during high-severity incidents and drive a coordinated response.Strong communication skills with executives, technical teams, and non-technical stakeholders.Ability to mentor and coach colleagues outside the security function, fostering awareness and a strong security culture.Analytical and decisive, with the ability to translate technical risks into business impacts.Resilient under pressure and committed to organizational success.Results-oriented and committed to team success.LANGUAGESFluent in English, both spoken and written, with the ability to produce professional technical documentation and communicate effectively with stakeholders at all levels.