Apply Edge Start your job search

Sr. Information Security Analyst

Tenneco · Puebla, Mexico

Apply & track with Apply Edge

About the CompanyAt Tenneco, we don’t follow industry standards; we set them, and we don’t settle for being best-in-class because we hustle to be better than best-in-class. Whether it’s our Core Values–radical candor, simplify, organizational velocity, tenacious execution and win–or our Get Stuff Done (GSD) mindset, we’re determined to become the most trusted partner and best manufacturer and distributor to the transportation industry. How do we make it happen? Through the Tenneco Way. Fueled by our Core Values, a winning mindset and a relentless commitment to excellence, the Tenneco Way is how we win. It’s what keeps Team Tenneco bold, driven, and unapologetically focused on pushing past limits and redefining success. Here, you’ll work alongside a team of relentless problem-solvers who are committed to making a tangible impact. If you’re ready to break boundaries, deliver results, and enjoy the ride along the way, you’ll thrive here. Want to learn more about who we are? Check out our website to discover the Tenneco Way.About the RoleIn this role you are Tenneco’s security operations presence in AMER. You own detection triage and incident handling during the region’s business day, you are the analyst closest to the plants and offices in your footprint, and you can tell the difference between a genuine intrusion and a maintenance window nobody announced. You handle escalations from the managed detection partner, you drive incidents to containment locally, and you carry the regional regulatory and operational context that no global tool captures.ResponsibilitiesOwn security alert triage, investigation, and escalation for the AMER region during regional coverage hours, and provide clean handover into the next region.Investigate escalations from the managed detection and response provider, validate findings independently against source telemetry, and reject weak analysis rather than passing it along.Lead containment and remediation for regional security incidents with regional IT, plant IT, and the global cyber operations lead, accounting for production impact before acting.Produce the incident facts required to meet NIS2 twenty-four hour early warning and seventy-two hour notification timelines for in-scope EU entities, and GDPR seventy two hour breach notification, and escalate the notification decision without delay.Build and maintain regional context including critical systems, plant schedules, local applications, and known benign behavior that would otherwise generate false positives.Support forensic evidence collection and preservation for regional incidents in coordination with Legal, Privacy, and where required local works councils.Identify detection gaps and tuning opportunities from regional investigations and submit them to detection engineering with supporting evidence.Contribute to incident documentation and post-incident review so that findings lead to a control change rather than a note in a file.Act as a regional security point of contact for IT and business stakeholders, including targeted awareness support during campaigns aimed at the region.Measured on: regional mean time to triage and contain; escalation accuracy against managed service partner findings; incident documentation completeness; regulatory notification inputs delivered within clock; and false positive reduction from submitted tuning. Reported weekly to the Cyber Operations Lead.QualificationsBachelor’s degree in Computer Science, Information Security, Information Systems, Engineering, or a related field; or an Associate degree plus two additional years of relevant experience; or six years of directly relevant experience in place of a degree.Required Skills5+ years of security operations, incident response, or security analysis experience.Hands-on capability with SIEM investigation, endpoint detection and response, email security, and identity telemetry.Working knowledge of Windows, Linux, cloud, and network fundamentals sufficient to reconstruct an event from logs.General Business - Tenneco Confiden al