27 ago
|
Ingeniosi
|
Ciudad de México
27 ago
Ingeniosi
Ciudad de México
Job Description
The Senior Associate, Cyber Operations will join the Cyber Operations / Incident Response team and will be responsible for investigating, managing, and documenting cybersecurity incidents within a 24x7 security operations environment.
Key Responsibilities
- Monitor, investigate, and respond to cybersecurity alerts and incidents, identifying potential threats and assessing their impact on the organization.
- Manage security incidents throughout the Incident Response lifecycle, including identification, containment, eradication, recovery, and lessons learned.
- Investigate security events using Endpoint Detection & Response (EDR) technologies such as CrowdStrike, Microsoft Defender for Endpoint (MDE), Zscaler, or equivalent platforms.
- Support threat identification, incident investigation, containment, and remediation activities.
- Document incident findings, investigation details, actions taken, and resolution outcomes.
- Use ServiceNow or similar platforms for incident ticketing, tracking, and case management.
- Support investigations related to email security threats such as phishing and malicious emails using tools such as Proofpoint or equivalent technologies.
- Leverage Threat Intelligence platforms, such as Recorded Future or equivalent solutions, to identify Indicators of Compromise (IOCs) and support incident investigations.
- Work within a predominantly Microsoft Azure environment and support security monitoring and incident response activities across cloud-based systems.
- Use scripting, preferably Python or Shell Script, to automate small repetitive security tasks when applicable.
- Support security automation and orchestration activities using Cortex XSOAR or equivalent SOAR platforms when required.
- Stay current with cybersecurity threats, technologies, and security practices and contribute to continuous improvement of incident response processes and controls.
Job Requirements
Must-have
- 3–5 years of hands-on experience in Cybersecurity Incident Response / Incident Management.
- Experience investigating and responding to cybersecurity alerts and incidents.
- Hands-on experience with EDR technologies , such as CrowdStrike, Microsoft Defender for Endpoint (MDE), Zscaler, or equivalent platforms.
- Solid understanding of the Incident Response lifecycle: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
- Ability to document incidents, investigations, actions taken, findings, and outcomes.
- Strong analytical and problem-solving skills.
- Excellent verbal and written English communication skills.
- Availability to work rotating schedules according to operational needs, with schedule changes approximately every quarter.
- Availability to work 100% remotely .
Preferred / Nice to Have
- Experience with ServiceNow for security incident ticketing and case management.
- Experience working in Microsoft Azure environments; approximately 80–90% of the current environment is Azure-based.
- Basic scripting experience, preferably Python ; Shell Script is also valuable.
- Experience with Proofpoint or equivalent email security platforms.
- Experience with Recorded Future or other Threat Intelligence platforms, including working with Indicators of Compromise (IOCs).
- Experience with Cortex XSOAR or another SOAR platform for security automation and orchestration.
- Exposure to Threat Hunting and Digital Forensics .
Preferred Certifications
Certifications are desirable but not mandatory. Particularly valued certifications include:
- GCIH – GIAC Certified Incident Handler
- GCFE – GIAC Certified Forensic Examiner
- GCFA – GIAC Certified Forensic Analyst
- Microsoft Azure certifications, such as AZ-900 – Microsoft Azure Fundamentals
Other relevant cybersecurity certifications may also be considered.
📌 Senior Associate, Cyber Operations - Incident Response (Ciudad de México)
🏢 Ingeniosi
📍 Ciudad de México