AI Jobs Map

Ingeniosi · Mexico

Senior Associate, Cyber Operations – Incident Response

Remoteseniorfull timePosted 6 days ago
Apply on LinkedInLinkedInOpens the original posting. AI Jobs Map never asks for your details.

Stack mentioned

cybersecuritycrowdstrikeazurepythonbashincident-responsethreat-intelligence

Job Description

The Senior Associate, Cyber Operations will join the Cyber Operations / Incident Response team and will be responsible for investigating, managing, and documenting cybersecurity incidents within a 24x7 security operations environment.

Key Responsibilities

- Monitor, investigate, and respond to cybersecurity alerts and incidents, identifying potential threats and assessing their impact on the organization.

- Manage security incidents throughout the Incident Response lifecycle, including identification, containment, eradication, recovery, and lessons learned.

- Investigate security events using Endpoint Detection & Response (EDR) technologies such as CrowdStrike, Microsoft Defender for Endpoint (MDE), Zscaler, or equivalent platforms.

- Support threat identification, incident investigation, containment, and remediation activities.

- Document incident findings, investigation details, actions taken, and resolution outcomes.

- Use ServiceNow or similar platforms for incident ticketing, tracking, and case management.

- Support investigations related to email security threats such as phishing and malicious emails using tools such as Proofpoint or equivalent technologies.

- Leverage Threat Intelligence platforms, such as Recorded Future or equivalent solutions, to identify Indicators of Compromise (IOCs) and support incident investigations.

- Work within a predominantly Microsoft Azure environment and support security monitoring and incident response activities across cloud-based systems.

- Use scripting, preferably Python or Shell Script, to automate small repetitive security tasks when applicable.

- Support security automation and orchestration activities using Cortex XSOAR or equivalent SOAR platforms when required.

- Stay current with cybersecurity threats, technologies, and security practices and contribute to continuous improvement of incident response processes and controls.

Job Requirements

Must-have

- 3–5 years of hands-on experience in Cybersecurity Incident Response / Incident Management.

- Experience investigating and responding to cybersecurity alerts and incidents.

- Hands-on experience with EDR technologies, such as CrowdStrike, Microsoft Defender for Endpoint (MDE), Zscaler, or equivalent platforms.

- Solid understanding of the Incident Response lifecycle: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.

- Ability to document incidents, investigations, actions taken, findings, and outcomes.

- Strong analytical and problem-solving skills.

- Excellent verbal and written English communication skills.

- Availability to work rotating schedules according to operational needs, with schedule changes approximately every quarter.

- Availability to work 100% remotely.

Preferred / Nice to Have

- Experience with ServiceNow for security incident ticketing and case management.

- Experience working in Microsoft Azure environments; approximately 80–90% of the current environment is Azure-based.

- Basic scripting experience, preferably Python; Shell Script is also valuable.

- Experience with Proofpoint or equivalent email security platforms.

- Experience with Recorded Future or other Threat Intelligence platforms, including working with Indicators of Compromise (IOCs).

- Experience with Cortex XSOAR or another SOAR platform for security automation and orchestration.

- Exposure to Threat Hunting and Digital Forensics.

Preferred Certifications

Certifications are desirable but not mandatory. Particularly valued certifications include:

- GCIH – GIAC Certified Incident Handler

- GCFE – GIAC Certified Forensic Examiner

- GCFA – GIAC Certified Forensic Analyst

- Microsoft Azure certifications, such as AZ-900 – Microsoft Azure Fundamentals

Other relevant cybersecurity certifications may also be considered.

More jobs at Ingeniosi