06 sep
|
Ingeniosi
|
México
the senior associate, cyber operations will join the cyber operations / incident response team and will be responsible for investigating, managing, and documenting cybersecurity incidents within a 24x7 security operations environment.
key responsibilities
- monitor, investigate, and respond to cybersecurity alerts and incidents, identifying potential threats and assessing their impact on the organization.
- manage security incidents throughout the incident response lifecycle, including identification, containment, eradication, recovery, and lessons learned.
- investigate security events using endpoint detection & response (edr) technologies such as crowdstrike, microsoft defender for endpoint (mde), zscaler, or equivalent platforms.
- support threat identification, incident investigation, containment, and remediation activities.
- document incident findings, investigation details, actions taken, and resolution outcomes.
- use servicenow or similar platforms for incident ticketing, tracking, and case management.
- support investigations related to email security threats such as phishing and malicious emails using tools such as proofpoint or equivalent technologies.
- leverage threat intelligence platforms, such as recorded future or equivalent solutions, to identify indicators of compromise (iocs) and support incident investigations.
- work within a predominantly microsoft azure environment and support security monitoring and incident response activities across cloud-based systems.
- use scripting, preferably python or shell script, to automate small repetitive security tasks when applicable.
- support security automation and orchestration activities using cortex xsoar or equivalent soar platforms when required.
- stay current with cybersecurity threats, technologies,
and security practices and contribute to continuous improvement of incident response processes and controls.
job requirements
must-have
- 3–5 years of hands-on experience in cybersecurity incident response / incident management.
- experience investigating and responding to cybersecurity alerts and incidents.
- hands-on experience with edr technologies , such as crowdstrike, microsoft defender for endpoint (mde), zscaler, or equivalent platforms.
- solid understanding of the incident response lifecycle: preparation, identification, containment, eradication, recovery, and lessons learned.
- ability to document incidents, investigations, actions taken, findings, and outcomes.
- strong analytical and problem-solving skills.
- excellent verbal and written english communication skills.
- availability to work rotating schedules according to operational needs, with schedule changes approximately every quarter.
- availability to work 100% remotely .
preferred / nice to have
- experience with servicenow for security incident ticketing and case management.
- experience working in microsoft azure environments; approximately 80–90% of the current environment is azure-based.
- basic scripting experience, preferably python ; shell script is also valuable.
- experience with proofpoint or equivalent email security platforms.
- experience with recorded future or other threat intelligence platforms, including working with indicators of compromise (iocs).
- experience with cortex xsoar or another soar platform for security automation and orchestration.
- exposure to threat hunting and digital forensics .
preferred certifications
certifications are desirable but not mandatory. Particularly valued certifications include:
- gcfe – giac certified forensic examiner
- gcfa – giac certified forensic analyst
other relevant cybersecurity certifications may also be considered.
#j-18808-ljbffr
📌 Remote senior cyber incident response specialist (México)
🏢 Ingeniosi
📍 México