Aspenview Technology Partners logo
Hiring from
United States
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Build the Future with AspenView Technology Partners

At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently.

As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries.

Why Join AspenView?

At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.

Here’s what you can expect:

  • Competitive base
  • Flexible work model: hybrid, remote, or in-office
  • Real growth opportunities and leadership visibility
  • Inclusive, respectful culture that blends U.S. innovation with Colombian heart
  • A company that listens, invests in you, and celebrates wins together

The Incident Response Lead is a senior, hands-on professional responsible for leading incident response and the embedded digital forensics capability for a large US consumer lender. The client's 24/7 security operations run from a nearshore team in Bogotá, Medellin and Buenos Aires, and you will be one of two US-based seniors on the service, highly visible to the client's security leadership. When the client declares a major incident, you will be the incident lead on its bridge. The client declares incidents and executes containment; your job is to tell it what happened, how far it reached and what to contain, with the evidence to back it. You will report to the SOC / Cyber Operations Lead and provide technical direction to two Tier 3 analysts in Latin America.

What you will do:

Major Incident Leadership

  • Serve as incident lead on the client's major-incident bridge, working alongside its incident commander and keeping the client, the partner and the analysts aligned on one version of events.
  • Scope incidents and deliver evidence-backed containment recommendations for the client's infrastructure, identity, endpoint and application teams to execute.
  • Write operational updates for responders and executive summaries for client leadership during incidents, and lead the post-incident review afterwards.

Digital Forensics & Investigation

  • Own the DFIR work inside the service, including host and memory triage and analysis of CrowdStrike and Defender endpoint telemetry.
  • Investigate Okta sessions and tokens, and AWS activity through CloudTrail, GuardDuty and VPC flow logs.
  • Build investigation records and timelines that give the client what it needs for its own regulatory notification decisions under NYDFS Part 500 and GLBA.

Readiness & Team Direction

  • Develop IR playbooks and runbooks, including a review of the client's existing content.
  • Run tabletop exercises with the client's security, legal and risk teams.
  • Guide two Tier 3 analysts in Latin America who act as your first line on overnight investigations.

Tools & Technologies:

  • SIEM & Case Management: Elastic, Abstract Security and ServiceNow SecOps (Splunk or Sentinel also relevant).
  • Endpoint & Identity: CrowdStrike Falcon, Microsoft Defender and Okta (or Entra ID).
  • Cloud: AWS CloudTrail, GuardDuty and VPC flow logs (Azure or GCP accepted).
  • Email & Network (Bonus): Proofpoint and Palo Alto, or equivalents.
  • Forensics (Bonus): Velociraptor, KAPE, Volatility, FTK, EnCase or X-Ways.

What you bring:

  • Experience: Senior enough to lead the technical response to a major incident, and able to walk through one end to end, including what went wrong and what you changed afterwards. Hands-on forensics on Windows and Linux hosts and investigations in at least one major cloud.
  • Technical Independence: You query SIEM, EDR and identity logs directly rather than waiting for an analyst to pull the data.
  • Judgment: The ability to recommend containment that stops an attacker without taking down a lending platform at month end.
  • Communication / Leadership: Incident reports that a CISO, a lawyer and an examiner can each read without a translator. Proven ability to lead people you don't line-manage, including analysts in another country.
  • Availability: Remote work from the United States on US Eastern business hours, plus a 24/7 on-call rotation and periodic travel to the client and to Bogotá and Buenos Aires. US work authorization is required, and access requires identity, criminal background, employment and education checks, repeated periodically.
  • Bonus Qualifications: Incident response inside a bank, lender, card issuer or insurer; working knowledge of NYDFS Part 500, GLBA, FFIEC, SOX and PCI DSS incident obligations; experience with ransomware, business email compromise or fraud-driven intrusions in consumer finance; consultancy or MSSP background; GCIH, GCFA, GCFE, GREM or CISSP; and Spanish, which helps with the nearshore team but isn't required.

Visa Sponsorship

AspenView does not sponsor employment visas for this role. Applicants must be permanently authorized to work in their country of residence and must not require visa sponsorship now or in the future.

Equal Opportunity Employer

AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.

Similar jobs

Apply for this job