About this role
About EdgeUno
EdgeUno is a US-based technology infrastructure company headquartered in Miami, with a strong operational presence across Latin America, including Colombia, Brazil, Argentina, Chile, Peru, Mexico, and Ecuador. We enable digital businesses to scale with high performance and reliability by providing connectivity, IP Transit, private networks, data centers, bare metal, and cloud solutions to ISPs, content providers, hyperscalers, and global technology companies.
Through our own infrastructure platform and strategic interconnection with major global hubs and content networks, we bring content closer to end users and deliver low latency, security, and operational resilience across the Americas and beyond.
Role Overview
EdgeUno is looking for Network Security Analysts to join the Security Operations Center, working in staggered shifts to detect, triage, and mitigate attacks against the backbone and against customers across Latin America and the United States. This is the front line of assisted response: analysis, assisted mitigation, threshold tuning, routing anomaly handling, and post-event reporting to customers.
About the Role
This is a network role with a security focus, not a SIEM or endpoint analyst role. The ideal candidate comes from a NOC or network operations background at an ISP, carrier, or data center, is comfortable reading a BGP table and a flow graph under pressure, and wants to specialize in network defense. EdgeUno expects to develop this person technically, with a structured certification track as part of the first six months, so a solid networking foundation and genuine curiosity matter more than an existing security title.
Core Responsibilities
Detection, Triage & Assisted Mitigation
- Monitor detection platforms and flow telemetry for attack traffic and traffic anomalies during the assigned shift.
- Triage and classify events by severity, applying the escalation matrix consistently.
- Execute assisted mitigation according to runbook: FlowSpec rules, RTBH, and diversion to scrubbing.
- Validate automated mitigation, identify and correct false positives, and confirm customer traffic has recovered.
- Escalate to Tier 3 and to the on-call engineer according to defined criteria, without holding an event past its threshold.
Threshold Tuning & Operational Improvement
- Tune per-customer detection thresholds against observed traffic baselines.
- Identify recurring attack vectors and propose runbook and automation improvements.
- Track and report auto-mitigation coverage, time to detect, time to mitigate, and false-positive rate.
Routing & Control-Plane Monitoring
- Monitor routing integrity alerts: RPKI ROV invalid, IRR mismatch, and unexpected AS origin on managed prefixes.
- Monitor control-plane health indicators on PE and border routers.
- Escalate routing and control-plane anomalies regardless of traffic volume; these are never triaged by bandwidth alone.
Customer-Facing Incident Handling & Documentation
- Draft post-event reports for customers within the contractual SLA, describing vector, volume, duration, action taken, and recommendation.
- Handle the abuse desk queue for malicious traffic originating from EdgeUno customers, within the applicable notification deadlines.
- Maintain accurate ticket records and complete shift handover documentation.
- Keep runbooks and operational procedures current as the environment changes.
Cross-Functional Collaboration
- Work alongside the NOC on incidents that have both availability and security impact.
- Support Customer Success with technical context during customer-affecting events.
- Participate in the on-call rotation covering nights and weekends.
Requirements
- English proficiency, B2 level minimum.
- 3+ years in a NOC, network operations, or network engineering role at an ISP, carrier, telecom, or data center.
- Hands-on experience with BGP and with OSPF or IS-IS in a production network.
- Junos CLI in production (Cisco IOS-XR or IOS accepted with demonstrated ability to cross over).
- Ability to read and interpret flow data (NetFlow, IPFIX, sFlow) and identify anomalies against a baseline.
- Packet capture analysis and traffic troubleshooting.
- Working understanding of DDoS attack vectors: volumetric, protocol, amplification and reflection, and carpet bombing.
- MPLS, VRF, and VLAN fundamentals.
- Linux command line.
- Basic scripting (Python or shell).
- Ticketing discipline and clear written communication (this role writes documents customers read).
- Availability for staggered shift work and for an on-call rotation.
Nice to Have
- JNCIA-Junos or CCNA; Security+, BTL1, or equivalent.
- Exposure to a commercial DDoS mitigation platform (Corero, NETSCOUT Arbor, Radware, or similar).
- Operational experience with BGP FlowSpec or RTBH.
- Familiarity with RPKI, IRR objects, and prefix filtering.
- Experience writing customer-facing incident reports.
- Experience in telecommunications, ISP, carrier, backbone, or data center environments.
- Exposure to high-availability and low-latency network environments.
What We Offer
- Competitive compensation package.
- Training and development opportunities.
- Exposure to regional and international projects.
- Collaborative and technical work environment.
- Opportunity to impact digital infrastructure growth in Latin America.
