29 ago
|
Ingeniosi
|
México
Job Description
The Senior Associate, Cyber Operations will join the Cyber Operations / Incident Response team and will be responsible for investigating, managing, and documenting cybersecurity incidents within a 24x7 security operations environment.
Key Responsibilities
Monitor, investigate, and respond to cybersecurity alerts and incidents, identifying potential threats and assessing their impact on the organization.
Manage security incidents throughout the Incident Response lifecycle, including identification, containment, eradication, recovery, and lessons learned.
Investigate security events using Endpoint Detection & Response (EDR) technologies such as CrowdStrike, Microsoft Defender for Endpoint (MDE), Zscaler, or equivalent platforms.
Support threat identification, incident investigation, containment, and remediation activities.
Document incident findings, investigation details, actions taken, and resolution outcomes.
Use ServiceNow or similar platforms for incident ticketing, tracking, and case management.
Support investigations related to email security threats such as phishing and malicious emails using tools such as Proofpoint or equivalent technologies.
Leverage Threat Intelligence platforms, such as Recorded Future or equivalent solutions, to identify Indicators of Compromise (IOCs) and support incident investigations.
Work within a predominantly Microsoft Azure environment and support security monitoring and incident response activities across cloud-based systems.
Use scripting, preferably Python or Shell Script, to automate small repetitive security tasks when applicable.
Support security automation and orchestration activities using Cortex XSOAR or equivalent SOAR platforms when required.
Stay current with cybersecurity threats, technologies, and security practices and contribute to continuous improvement of incident response processes and controls.
Job Requirements
Must-have
3–5 years of hands-on experience in Cybersecurity Incident Response / Incident Management.
Experience investigating and responding to cybersecurity alerts and incidents.
Hands-on experience with
EDR technologies
, such as CrowdStrike, Microsoft Defender for Endpoint (MDE), Zscaler, or equivalent platforms.
Solid understanding of the
Incident Response lifecycle:
Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
Ability to document incidents, investigations, actions taken, findings, and outcomes.
Strong analytical and problem-solving skills.
Excellent verbal and written English communication skills.
Availability to work rotating schedules according to operational needs, with schedule changes approximately every quarter.
Availability to work
100% remotely
.
Preferred / Nice to Have
Experience with
ServiceNow
for security incident ticketing and case management.
Experience working in
Microsoft Azure
environments; approximately *****% of the current environment is Azure-based.
Basic scripting experience, preferably
Python
; Shell Script is also valuable.
Experience with
Proofpoint
or equivalent email security platforms.
Experience with
Recorded Future
or other Threat Intelligence platforms, including working with Indicators of Compromise (IOCs).
Experience with
Cortex XSOAR
or another SOAR platform for security automation and orchestration.
Exposure to
Threat Hunting
and
Digital Forensics
.
Preferred Certifications
Certifications are desirable but not mandatory. Particularly valued certifications include:
GCIH – GIAC Certified Incident Handler
GCFE – GIAC Certified Forensic Examiner
GCFA – GIAC Certified Forensic Analyst
Microsoft Azure certifications, such as
AZ-900 – Microsoft Azure Fundamentals
Other relevant cybersecurity certifications may also be considered.
📌 Senior Associate, Cyber Operations - Incident Response (México)
🏢 Ingeniosi
📍 México