Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com

Senior Associate – Cyber Operations (Incident Response)

EX Squared
🇲🇽 Mexico
Remote
Senior
2 days ago
  • Incident Response
  • ITIL
  • Threat Intelligence
  • triage
  • Microsoft Defender
  • Zscaler
  • Azure
  • Cortex
  • ServiceNow
  • CCSP
  • GSEC
  • GCIH
  • GCFA
  • CEH
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

AtEX Squared LATAM, we partner with leading organizations across global and regional markets to connect exceptional professionals with high-impact career opportunities.


Our client is a leading global organization in theprofessional services and consulting industry, supporting businesses with complex technology, cybersecurity, risk, compliance, and transformation initiatives.


For this position,EX Squared LATAM is supporting our client with the recruitment and selection process. The selected professional will be hired directly by the client under their local payroll in Mexico, becoming part of their internal team.


Role Overview

We’re currently looking for aSenior Associate – Cyber Operations (Incident Response) to support cybersecurity operations and respond directly to security incidents within a complex, global environment.


This is ahands-on operational cybersecurity role focused onSOC operations, Incident Response, threat hunting, forensic analysis, vulnerability identification, remediation, security monitoring, and incident response playbooks.

The ideal candidate will bring at least3 years of practical Cybersecurity Operations / Incident Response experience and will have participated directly in investigating and responding to security events rather than working primarily in coordination, ticket management, SLA tracking, escalation management, or ITIL-driven processes.


Location

Mexico. Candidates located inMexico City or Guadalajara are highly preferred.

  • For professionals based in Mexico City or Guadalajara, the position follows ahybrid model with onsite attendance approximately 2–3 days per week.
  • Candidates based in other cities in Mexico may be considered for a remote arrangement; however, Mexico City and Guadalajara profiles will receive priority.


Contract Duration

Permanent, direct employment with the client.

This is a100% payroll position in Mexico.


Working Hours

This position operates under10-hour shifts, with one of the following schedules:

  • Sunday through Wednesday, or
  • Wednesday through Saturday.


Available shifts are:

  • 7:00 a.m. – 5:00 p.m., or
  • 1:00 p.m. – 11:00 p.m.


Candidates must be comfortable working within one of these schedules and adapting to business needs.


Language Requirement

Advanced English.

Candidates must be comfortable communicating technical risks, incident findings, and security recommendations in English while collaborating directly with U.S.-based and multicultural teams.


What you'll do

  • Participate directly incybersecurity monitoring, incident investigation, containment, remediation, and response activities.
  • Investigate security incidents and alerts to determine scope, severity, impact, and appropriate mitigation actions.
  • Conductthreat hunting activities to identify suspicious behaviors and potential threats that may not be detected through standard alerts.
  • Supportforensic analysis and incident investigations to identify root cause and understand attacker activity.
  • Identify vulnerabilities and insecure configurations and coordinate appropriate remediation actions.
  • Develop, implement, maintain, and improveincident response processes and playbooks.
  • Configure and monitor security tools, includingalerts, correlation rules, dashboards, and reporting mechanisms.
  • Apply threat intelligence to security monitoring, vulnerability detection, and incident investigations.
  • Help determine risk severity and appropriate mitigation approaches for security events.
  • Incorporate lessons learned from incidents into improvedpreventive and detective security controls.
  • Support automation and orchestration initiatives that improve the efficiency of monitoring and response processes.
  • Collaborate with internal technology, infrastructure, security, and business teams during investigations and remediation efforts.
  • Document incident findings, technical evidence, remediation actions, and recommendations clearly.
  • Stay current with emerging threats, attacker techniques, security technologies, and cybersecurity operations practices.


What you'll bring

  • Minimum3 years of hands-on experience in Cybersecurity Operations, SOC, Incident Response, or similar operational security roles.
  • Direct experience participating insecurity incident investigation and response.
  • Hands-on exposure tothreat hunting and security monitoring activities.
  • Experience supporting or performingforensic analysis during security investigations.
  • Experience identifying vulnerabilities, insecure configurations, and security risks and supporting their remediation.
  • Experience implementing or working withIncident Response processes and playbooks.
  • Understanding of security event analysis, alert triage, escalation, containment, remediation, and post-incident activities.
  • Experience configuring, monitoring, or using security technologies within SOC or Incident Response environments.
  • Familiarity with endpoint, network, email, threat intelligence, and cloud security concepts.
  • Strong analytical and troubleshooting skills and the ability to investigate complex security events.
  • Ability to clearly communicate technical findings, risks, and recommended actions to different audiences.
  • Strong written and verbal English communication skills.


What will make you stand out

  • Hands-on experience with technologies such asCrowdStrike, Microsoft Defender for Endpoint, Zscaler, Proofpoint, Recorded Future, and Microsoft Azure.
  • Experience withPalo Alto Cortex XSOAR or comparable SOAR platforms.
  • Experience implementingsecurity automation and orchestration workflows.
  • Scripting experience usingPython, Shell, or similar languages.
  • Experience withServiceNow in a cybersecurity operations environment. The source JD specifically lists ServiceNow and Cortex XSOAR as pluses.
  • Certifications such asCISSP, CCSP, CCSK, GSEC, GCIH, GCFE, GCFA, SC-200, CEH, AZ-900, or similar cybersecurity credentials.
  • Experience improving SOC processes, detection capabilities, or Incident Response playbooks.
  • Exposure to threat intelligence and the ability to apply intelligence to active security monitoring and investigations.
  • Experience working in24x7 cybersecurity operations environments.


Why this opportunity?

This is an opportunity to join alarge, globally recognized organization in the professional services and consulting industry, working with international teams on sophisticated cybersecurity operations and Incident Response initiatives.


The role is especially suited for a cybersecurity professional who wants to remainclose to the technical and operational side of security, investigating real incidents, analyzing threats, improving detection capabilities, and supporting remediation across enterprise environments.


It offers exposure to modern security technologies, complex investigations, threat intelligence, automation, cloud environments, and U.S.-based stakeholders.


What the Client Offers

  • Career growth opportunities.
  • Annual performance review with potential salary adjustments and internal growth.
  • Meal/grocery vouchers.
  • Savings fund.
  • Vacation premium and statutory benefits.
  • Remote-work allowance, when applicable.


Selection Process

The selection process is expected to include:

  • Initial interview with the local/direct leader.
  • Technical interviews with the U.S.-based team, typically involving two interviewers per session.
  • Final interview with the U.S. Area Director.
  • Background check.


Eligibility Note

This opportunity is available to candidatescurrently residing in Mexico.


Candidates located inMexico City and Guadalajara are strongly preferred due to the hybrid working model.


Candidates located elsewhere in Mexico may also be considered for remote work depending on profile and business requirements.


Candidates must also be comfortable working one of the established10-hour Sunday–Wednesday or Wednesday–Saturday shifts.


Ready for your next career opportunity?

Apply throughEX Squared LATAM and take the next step toward joining a global organization where cybersecurity operations, Incident Response, threat intelligence, and hands-on security expertise come together.




Senior Associate – Cyber Operations (Incident Response) · EX Squared

Auto apply with Likeremote