Senior Associate, Cyber Operations – Incident Response

Ingeniosi

México

Presencial

MXN 600.000 - 900.000

Jornada completa

hace 31 horas
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Ingeniosi is seeking a Senior Associate, Cyber Operations to join our Cyber Operations / Incident Response team and manage investigations in a 24x7 security operations environment.

You will monitor, investigate, and respond to alerts, document findings, and support remediation across Microsoft Azure and other platforms using scripting and automation tools.

Formación

  • 3–5 years hands-on experience in Cybersecurity Incident Response / Incident Management.
  • Experience investigating and responding to cybersecurity alerts and incidents.
  • Hands-on with EDR technologies (CrowdStrike, MDE, Zscaler or equivalent).
  • Thorough understanding of the Incident Response lifecycle and playbooks.
  • Ability to document incidents, investigations and outcomes clearly.
  • Strong analytical and problem-solving skills; English communication proficiency.
  • Availability for rotating schedules and 100% remote work.

Responsabilidades

  • Monitor, investigate, and respond to cybersecurity alerts and incidents.
  • Manage incidents through the Incident Response lifecycle from identification to lessons learned.
  • Investigate events using EDR platforms and security tools.
  • Document findings, actions, and resolution outcomes for each case.
  • Utilize ServiceNow or similar platforms for ticketing and case management.
  • Support investigations related to email threats (phishing) using Proofpoint or similar.
  • Leverage Threat Intelligence to identify IOCs and support investigations.
  • Work within a predominantly Microsoft Azure environment and support cloud security monitoring.
  • Use scripting to automate small repetitive tasks; support SOAR workflows as needed.
  • Stay current with threats and contribute to incident response process improvements.

Conocimientos

Incident Response
Cybersecurity
EDR tools
Azure
Python scripting
Shell scripting
Documentation
English comms
Remote work

Herramientas

CrowdStrike
MDE
Zscaler
ServiceNow
Proofpoint
Cortex XSOAR
Recorded Future

Descripción del empleo

The Senior Associate, Cyber Operations will join the Cyber Operations / Incident Response team and will be responsible for investigating, managing, and documenting cybersecurity incidents within a 24x7 security operations environment.

Key Responsibilities
  • Monitor, investigate, and respond to cybersecurity alerts and incidents, identifying potential threats and assessing their impact on the organization.
  • Manage security incidents throughout the Incident Response lifecycle, including identification, containment, eradication, recovery, and lessons learned.
  • Investigate security events using Endpoint Detection & Response (EDR) technologies such as CrowdStrike, Microsoft Defender for Endpoint (MDE), Zscaler, or equivalent platforms.
  • Support threat identification, incident investigation, containment, and remediation activities.
  • Document incident findings, investigation details, actions taken, and resolution outcomes.
  • Use ServiceNow or similar platforms for incident ticketing, tracking, and case management.
  • Support investigations related to email security threats such as phishing and malicious emails using tools such as Proofpoint or equivalent technologies.
  • Leverage Threat Intelligence platforms, such as Recorded Future or equivalent solutions, to identify Indicators of Compromise (IOCs) and support incident investigations.
  • Work within a predominantly Microsoft Azure environment and support security monitoring and incident response activities across cloud-based systems.
  • Use scripting, preferably Python or Shell Script, to automate small repetitive security tasks when applicable.
  • Support security automation and orchestration activities using Cortex XSOAR or equivalent SOAR platforms when required.
  • Stay current with cybersecurity threats, technologies, and security practices and contribute to continuous improvement of incident response processes and controls.
Job Requirements
Must-have
  • 3–5 years of hands-on experience in Cybersecurity Incident Response / Incident Management.
  • Experience investigating and responding to cybersecurity alerts and incidents.
  • Hands-on experience with EDR technologies, such as CrowdStrike, Microsoft Defender for Endpoint (MDE), Zscaler, or equivalent platforms.
  • Solid understanding of the Incident Response lifecycle: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
  • Ability to document incidents, investigations, actions taken, findings, and outcomes.
  • Strong analytical and problem-solving skills.
  • Excellent verbal and written English communication skills.
  • Availability to work rotating schedules according to operational needs, with schedule changes approximately every quarter.
  • Availability to work 100% remotely.
Preferred / Nice to Have
  • Experience with ServiceNow for security incident ticketing and case management.
  • Experience working in Microsoft Azure environments; approximately 80–90% of the current environment is Azure-based.
  • Basic scripting experience, preferably Python; Shell Script is also valuable.
  • Experience with Proofpoint or equivalent email security platforms.
  • Experience with Recorded Future or other Threat Intelligence platforms, including working with Indicators of Compromise (IOCs).
  • Experience with Cortex XSOAR or another SOAR platform for security automation and orchestration.
  • Exposure to Threat Hunting and Digital Forensics.
Preferred Certifications

Certifications are desirable but not mandatory. Particularly valued certifications include:

  • GCFE – GIAC Certified Forensic Examiner
  • GCFA – GIAC Certified Forensic Analyst

Other relevant cybersecurity certifications may also be considered.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Remote Senior Cyber Incident Response Specialist
Remote Senior Cyber Incident Response Specialist

Ingeniosi • México

Presencial
MXN 600.000 - 900.000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

A2MAC1 - Decode the future • Santiago de Querétaro

Presencial
MXN 700.000 - 1.100.000
Biweekly pay
IMSS
Christmas bonus
+6
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

A2MAC1 • Santiago de Querétaro

Presencial
MXN 1.200.000 - 1.800.000
Biweekly Payment
IMSS
Christmas Bonus
+5
SOC Analyst Consultant (CrowdStrike Experience) - Remote (Mexico)
SOC Analyst Consultant (CrowdStrike Experience) - Remote (Mexico)

Echelon Risk + Cyber • México

Híbrido
PHP 1.487.000 - 1.912.000
Access to private medical insurance
Life insurance via MetLife
30-day Christmas bonus and a monthly技术
+3
SOC Analyst Consultant (CrowdStrike Experience) - Remote (Mexico) Posted on Aug 06 / 2026
SOC Analyst Consultant (CrowdStrike Experience) - Remote (Mexico) Posted on Aug 06 / 2026

EmergencyMD • México

Híbrido
MXN 600.000 - 900.000
Private medical insurance
Life insurance
Christmas bonus and technology stipend
+3
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Dematic • Guadalupe

Presencial
MXN 700.000 - 1.000.000
Career Development
Competitive Compensation and Benefits
Pay Transparency
+1
Senior Security Developer
Senior Security Developer

Dematic • Guadalupe

Híbrido
MXN 1.203.000 - 1.719.000
Career Development
Competitive Compensation and Benefits
Pay Transparency
+1
Security Analyst
Security Analyst

Gravity IT Resources • Monterrey

Presencial
MXN 600.000 - 800.000
SOC Analyst – CrowdStrike / Cybersecurity Specialist
SOC Analyst – CrowdStrike / Cybersecurity Specialist

Arcadion • Polanco (Ranchería Mineral Polanco)

Presencial
MXN 300.000 - 400.000
Competitive compensation
Modern, innovation-driven culture
Opportunities for career growth
Infrastructure and Cybersecurity Analyst
Infrastructure and Cybersecurity Analyst

LUXSHARE • Tijuana

Presencial
MXN 360.000 - 480.000