Senior Manager, Cybersecurity Incident Response(Monterrey)

Michael Page International México Reclutamiento Especializado S.A. de C.V

Monterrey

On-site

MXN 1,071,000 - 1,786,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Annual Bonus
Christmas Bonus (Aguinaldo) 41 días
Company Car
Fuel Allowance
Grocery Vouchers
Savings Fund 13%
Caja de Ahorro
Relocation assistance

Job summary

Michael Page International México Reclutamiento Especializado S.A. de C.V. busca un líder de Respuesta a Incidentes de ciberseguridad con más de 10 años de experiencia para dirigir respuestas a incidentes de alto impacto y coordinar equipos especializados.

El candidato ideal gestionará investigaciones, análisis forense y recuperación, trabajando con proveedores externos y socios MDR/MSSP, reportando a ejecutivos y asegurando la mejora continua de procesos y métricas de rendimiento.

Qualifications

  • 10+ years of cybersecurity experience including Incident Response, Digital Forensics, Threat Hunting or SOC.
  • Proven experience leading large-scale enterprise cyber incidents as Incident Commander or technical lead.
  • Strong leadership experience managing technical cybersecurity teams and driving operational excellence.
  • Advanced hands-on expertise in cyber incident investigations across endpoint, cloud, identity, and enterprise environments.
  • Experience with global or Follow-the-Sun security operations models.
  • Ability to communicate effectively with executive stakeholders and provide risk-based updates during critical incidents.

Responsibilities

  • Lead the response to high-impact cybersecurity incidents, including ransomware, identity compromise, BEC, insider threats, supply chain attacks, and data breaches.
  • Act as the Incident Commander, coordinating investigation, containment, recovery, and executive-level communications.
  • Manage, mentor, and develop a team of cybersecurity investigators and incident responders.
  • Define investigative strategies across endpoint, cloud, identity, email, SaaS, and network environments.
  • Oversee digital forensics activities, root cause analysis, evidence handling, attack timeline reconstruction, and remediation planning.
  • Integrate threat intelligence and threat hunting to strengthen detection and prevention capabilities.
  • Manage relationships with external incident response providers and MDR/MSSP partners.
  • Collaborate with SOC, Detection Engineering, Cloud Security, Vulnerability Management and Offensive Security teams to improve cyber resilience.
  • Define, monitor, and optimize incident response metrics (MTTD, MTTR, detection effectiveness, investigation quality).
  • Drive automation and AI adoption through SOAR platforms, scripting, APIs, and workflow optimization.
  • Lead readiness exercises, update playbooks/runbooks, and continuously improve incident response processes.
  • Communicate cyber risks, findings and incident updates to executives while coordinating with Legal/Compliance/Privacy/Regulatory teams.

Skills

Incident Response
Digital Forensics
Threat Hunting
SOC
Leadership
Team Management
Python
PowerShell
SOAR
MITRE ATT&CK
EDR investigations
AWS
Azure
Microsoft Entra ID
Microsoft 365
KQL
SIEM

Education

Bachelor's degree in Computer Science or Cybersecurity

Tools

SIEM
SOAR
EDR

Job description

  • Experience in Incident Response, Digital Forensics, Threat Hunting, or SOC.
  • Lead high-impact cybersecurity incident response efforts
Sobre nuestro cliente

Global Company

Descripción
  • Lead the response to high-impact cybersecurity incidents, including ransomware, identity compromise, business email compromise (BEC), insider threats, supply chain attacks, and data breaches.
  • Act as the Incident Commander, coordinating investigation, containment, recovery, and executive-level communications.
  • Manage, mentor, and develop a team of cybersecurity investigators and incident responders.
  • Define investigative strategies across endpoint, cloud, identity, email, SaaS, and network environments.
  • Oversee digital forensics activities, root cause analysis, evidence handling, attack timeline reconstruction, and remediation planning.
  • Integrate threat intelligence and threat hunting activities to strengthen detection and prevention capabilities.
  • Manage relationships with external incident response providers, MDR/MSSP partners, and specialized security vendors.
  • Collaborate with SOC, Detection Engineering, Cloud Security, Vulnerability Management, and Offensive Security teams to improve cyber resilience.
  • Define, monitor, and optimize key incident response metrics such as MTTD, MTTR, detection effectiveness, and investigation quality.
  • Drive automation and AI adoption through SOAR platforms, scripting, APIs, and workflow optimization.
  • Lead readiness exercises, update playbooks and runbooks, and continuously improve incident response processes.
  • Communicate cyber risks, findings, and incident updates to executive stakeholders while coordinating with Legal, Compliance, Privacy, and Regulatory teams.
Perfil buscado
  • 10+ years of cybersecurity experience, including significant experience in Incident Response, Digital Forensics, Threat Hunting, or Security Operations.
  • Proven experience leading large-scale enterprise cyber incidents as an Incident Commander or technical lead.
  • Strong leadership experience managing technical cybersecurity teams and driving operational excellence.
  • Advanced hands-on expertise in cyber incident investigations across endpoint, cloud, identity, and enterprise environments.
  • Experience working within global or Follow-the-Sun security operations models.
  • Ability to communicate effectively with executive stakeholders and provide risk-based updates during critical incidents.
  • Deep knowledge of Cyber Incident Response and Incident Command methodologies.
  • Experience with endpoint forensics, memory analysis, and EDR investigations across Windows and Linux environments.
  • Expertise conducting investigations in AWS, Azure, Microsoft Entra ID, and Microsoft 365 environments.
  • Experience performing Threat Hunting using KQL and other SIEM query languages.
  • Strong understanding of network, email, phishing, BEC, malware analysis, and adversary TTPs.
  • Experience with Python or PowerShell scripting, APIs, SOAR platforms, and security automation.
  • In-depth knowledge of the MITRE ATT&CK framework, modern attack techniques, and detection engineering.
  • Ability to lead investigations, perform root cause analysis, and oversee remediation efforts for complex cybersecurity incidents.
  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent practical experience (preferred but strongly valued).
Qué Ofrecemos
Salary & Benefits
  • Base Salary: Up to MXN $160,000 gross per month.
  • Annual Bonus.
  • Christmas Bonus (Aguinaldo): 41 days.
  • Vacation Premium: 105%.
  • Company Car: Assigned vehicle, renewed every 4 years.
  • Fuel Allowance (Gas Vouchers).
  • Grocery Vouchers.
  • Savings Fund: 13% company contribution (subject to policy caps).
  • Savings Plan (Caja de Ahorro).
Relocation Package (for candidates outside Monterrey)
  • Relocation assistance.
  • Flight expenses covered.
  • Family relocation support is also available when applicable.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Michael Page International México Reclutamiento Especializado S.A. de C.V • Ciudad de México

Hybrid
MXN 500,000 - 750,000
Hybrid working model in Mexico City
Exposure to global stakeholders
Clear career development path
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Michael Page • Xico

Hybrid
MXN 600,000 - 900,000
Competitive compensation package
Incentives based on performance
Hybrid work model in Mexico City
+1
Analista de Respuesta a Incidentes - Ciberseguridad
Analista de Respuesta a Incidentes - Ciberseguridad

Placements24 • Tijuana

Hybrid
MXN 446,000 - 725,000
Bonos por desempeño
Seguro médico
Seguro de vida
+2
Run Rate & Revenue Integrity Analyst
Run Rate & Revenue Integrity Analyst

Msci- • Monterrey

Remote
MXN 300,000 - 540,000
Salario competitivo
Paquete de beneficios completo
Trabajo remoto
+1
Consultor Senior de Ciberseguridad
Consultor Senior de Ciberseguridad

KPMG México • Monterrey

On-site
MXN 223,200 - 245,520
SOC Engineer I (Mexico)
SOC Engineer I (Mexico)

Dyopath • Monterrey

On-site
MXN 279,000 - 335,000
Major Medical Insurance
Life Insurance
Quarterly Bonus
+3
Arquitecto de Seguridad de la Información - Ciberseguridad
Arquitecto de Seguridad de la Información - Ciberseguridad

Placements24 • Monterrey

On-site
MXN 1,200,000 - 2,100,000
Salud premium
Plan de retiro corporativo
Certificaciones y conferencias
+1
Senior Risk Advisory Consultant - Remote (Mexico)
Senior Risk Advisory Consultant - Remote (Mexico)

Echelon Risk + Cyber • Ciudad de México

Remote
MXN 900,000 - 1,200,000
Private medical insurance
Life insurance
30-day Christmas bonus and stipend
+5
SOC Analyst L2
SOC Analyst L2

Capital Empresarial Horizonte • Ciudad de México

On-site
MXN 446,400 - 781,200
Horario de oficina
Esquema 100% nómina
Prestaciones de ley
+1
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

A2MAC1 - Decode the future • Santiago de Querétaro

On-site
MXN 700,000 - 1,100,000
Biweekly pay
IMSS
Christmas bonus
+6