Senior Associate – Cyber Operations, Incident Response

Jobtailor

Mexico

On-site

MXN 420,000 - 660,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Jobtailor is seeking a dedicated Cybersecurity Operations professional in Mexico City to lead monitoring, incident response, and threat hunting efforts. You will investigate incidents, perform forensic analysis, and implement robust playbooks and automation to strengthen security controls.

The role requires hands‑on experience in security monitoring, vulnerability remediation, and cross‑team collaboration, with 24x7 shift readiness and strong English communication.

Qualifications

  • Minimum 3 years of hands‑on experience in Cybersecurity Operations, SOC, Incident Response, or similar operational security roles.
  • Direct experience participating in security incident investigation and response.
  • Hands‑on exposure to threat hunting and security monitoring activities.
  • Experience supporting or performing forensic analysis during security investigations.
  • Experience identifying vulnerabilities, insecure configurations, and security risks and supporting their remediation.
  • Experience implementing or working with Incident Response processes and playbooks.
  • Understanding of security event analysis, alert triage, escalation, containment, remediation, and post‑incident activities.
  • Experience configuring, monitoring, or using security technologies within SOC or Incident Response environments.
  • Familiarity with endpoint, network, email, threat intelligence, and cloud security concepts.
  • Strong analytical and troubleshooting skills and the ability to investigate complex security events.
  • Ability to clearly communicate technical findings, risks, and recommended actions to different audiences.
  • Strong written and verbal English communication skills.
  • Advanced English.

Responsibilities

  • Participate directly in cybersecurity monitoring, incident investigation, containment, remediation, and response activities.
  • Investigate security incidents and alerts to determine scope, severity, impact, and appropriate mitigation actions.
  • Conduct threat hunting activities to identify suspicious behaviors and potential threats.
  • Support forensic analysis and incident investigations to identify root cause and understand attacker activity.
  • Identify vulnerabilities and insecure configurations and coordinate appropriate remediation actions.
  • Develop, implement, maintain, and improve incident response processes and playbooks.
  • Configure and monitor security tools, including alerts, correlation rules, dashboards, and reporting mechanisms.
  • Apply threat intelligence to security monitoring, vulnerability detection, and incident investigations.
  • Determine risk severity and appropriate mitigation approaches for security events.
  • Incorporate lessons learned into improved preventive and detective security controls.
  • Support automation and orchestration initiatives that improve monitoring and response efficiency.
  • Collaborate with internal technology, infrastructure, security, and business teams during investigations and remediation.
  • Document incident findings, technical evidence, remediation actions, and recommendations.
  • Stay current with emerging threats, attacker techniques, security technologies, and cybersecurity operations practices.
  • Work with international teams on sophisticated cybersecurity operations and Incident Response initiatives.

Skills

Cybersecurity Operations
Incident Response
Threat Hunting
Forensic Analysis
Vulnerability Identification
Security Monitoring
Automation and Orchestration
Scripting (Python, Shell)
Security Tool Configuration
Threat Intelligence Application
Post-Incident Activities

Tools

CrowdStrike
Microsoft Defender for Endpoint
Zscaler
Proofpoint
Recorded Future
Microsoft Azure
Palo Alto Cortex XSOAR
ServiceNow

Job description

  • Participate directly in cybersecurity monitoring, incident investigation, containment, remediation, and response activities
  • Investigate security incidents and alerts to determine scope, severity, impact, and appropriate mitigation actions
  • Conduct threat hunting activities to identify suspicious behaviors and potential threats
  • Support forensic analysis and incident investigations to identify root cause and understand attacker activity
  • Identify vulnerabilities and insecure configurations and coordinate appropriate remediation actions
  • Develop, implement, maintain, and improve incident response processes and playbooks
  • Configure and monitor security tools, including alerts, correlation rules, dashboards, and reporting mechanisms
  • Apply threat intelligence to security monitoring, vulnerability detection, and incident investigations
  • Determine risk severity and appropriate mitigation approaches for security events
  • Incorporate lessons learned into improved preventive and detective security controls
  • Support automation and orchestration initiatives that improve monitoring and response efficiency
  • Collaborate with internal technology, infrastructure, security, and business teams during investigations and remediation
  • Document incident findings, technical evidence, remediation actions, and recommendations
  • Stay current with emerging threats, attacker techniques, security technologies, and cybersecurity operations practices
  • Work with international teams on sophisticated cybersecurity operations and Incident Response initiatives
Requirements
  • Minimum 3 years of hands‑on experience in Cybersecurity Operations, SOC, Incident Response, or similar operational security roles
  • Direct experience participating in security incident investigation and response
  • Hands‑on exposure to threat hunting and security monitoring activities
  • Experience supporting or performing forensic analysis during security investigations
  • Experience identifying vulnerabilities, insecure configurations, and security risks and supporting their remediation
  • Experience implementing or working with Incident Response processes and playbooks
  • Understanding of security event analysis, alert triage, escalation, containment, remediation, and post‑incident activities
  • Experience configuring, monitoring, or using security technologies within SOC or Incident Response environments
  • Familiarity with endpoint, network, email, threat intelligence, and cloud security concepts
  • Strong analytical and troubleshooting skills and the ability to investigate complex security events
  • Ability to clearly communicate technical findings, risks, and recommended actions to different audiences
  • Strong written and verbal English communication skills
  • Advanced English
  • Candidates must be currently residing in Mexico
  • Candidates must be comfortable working one of the established 10‑hour Sunday–Wednesday or Wednesday–Saturday shifts
  • Hands‑on experience with CrowdStrike, Microsoft Defender for Endpoint, Zscaler, Proofpoint, Recorded Future, and Microsoft Azure is advantageous
  • Experience with Palo Alto Cortex XSOAR or comparable SOAR platforms is advantageous
  • Experience implementing security automation and orchestration workflows is advantageous
  • Scripting experience using Python, Shell, or similar languages is advantageous
  • Experience with ServiceNow in a cybersecurity operations environment is advantageous
  • Certifications such as CISSP, CCSP, CCSK, GSEC, GCIH, GCFE, GCFA, SC‑200, CEH, AZ‑900, or similar cybersecurity credentials are advantageous
  • Experience improving SOC processes, detection capabilities, or Incident Response playbooks is advantageous
  • Exposure to threat intelligence and ability to apply intelligence to active security monitoring and investigations is advantageous
  • Experience working in 24x7 cybersecurity operations environments is advantageous
Core Competencies

Demonstrates expertise in Cybersecurity Operations, Incident Response, and threat hunting, with a strong focus on vulnerability identification, forensic analysis, and security monitoring. Proficient in developing and implementing incident response processes and playbooks while effectively communicating technical findings to diverse audiences.

Highest-signal resume keywords
  • Cybersecurity Operations
  • Incident Response
  • Threat Hunting
  • Forensic Analysis
  • Vulnerability Identification
Hard Skills
  • Security Incident Investigation
  • Security Monitoring
  • Vulnerability Detection
  • Incident Response Processes
  • Security Event Analysis
  • Automation and Orchestration
  • Scripting (Python, Shell)
  • Security Tool Configuration
  • Threat Intelligence Application
  • Post‑Incident Activities
Soft Skills
  • Analytical Skills
  • Troubleshooting Skills
  • Communication Skills
Certifications & Qualifications
  • CISSP
  • CCSP
  • CCSK
  • GSEC
  • GCIH
  • GCFE
  • GCFA
  • SC‑200
  • CEH
  • AZ‑900
Industry Keywords
  • SOC
  • Cybersecurity
  • Incident Response
  • Threat Intelligence
  • 24x7 Operations
Tools & Technologies
  • CrowdStrike
  • Microsoft Defender for Endpoint
  • Zscaler
  • Proofpoint
  • Recorded Future
  • Microsoft Azure
  • Palo Alto Cortex XSOAR
  • ServiceNow
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000
Security Technician
Security Technician

Jobtailor • Pasig

On-site
PHP 600,000 - 900,000
Security Analyst – SOC
Security Analyst – SOC

Moder Solutions Inc. • Cebu City

On-site
PHP 420,000 - 720,000
Junior Cyber Security Engineer/Analyst
Junior Cyber Security Engineer/Analyst

PM Consulting • Philippines

On-site
PHP 600,000 - 900,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Morgan McKinley • Taguig

On-site
PHP 1,200,000 - 2,400,000
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
SOC Manager
SOC Manager

SM Investments • Philippines

On-site
PHP 1,200,000 - 2,000,000
Associate Security Analyst
Associate Security Analyst

itm8 PH • Dumaguete

On-site
PHP 420,000 - 680,000
Cybersecurity Engineer
Cybersecurity Engineer

Hrtx • Philippines

Hybrid
PHP 1,000,000 - 1,800,000
Hybrid work setup
SOC Manager
SOC Manager

Hammerjack Pty Ltd • Philippines

On-site
PHP 1,200,000 - 1,600,000