EX Squared logo

Senior Associate – Cyber Operations (Incident Response)

EX Squared
Posted 6 hours ago
MexicoHybridEngineering & Development
Is this job info correct?

At EX Squared LATAM, we partner with leading organizations across global and regional markets to connect exceptional professionals with high-impact career opportunities.


Our client is a leading global organization in the professional services and consulting industry, supporting businesses with complex technology, cybersecurity, risk, compliance, and transformation initiatives.


For this position, EX Squared LATAM is supporting our client with the recruitment and selection process. The selected professional will be hired directly by the client under their local payroll in Mexico, becoming part of their internal team.


Role Overview

We’re currently looking for a Senior Associate – Cyber Operations (Incident Response) to support cybersecurity operations and respond directly to security incidents within a complex, global environment.


This is a hands-on operational cybersecurity role focused on SOC operations, Incident Response, threat hunting, forensic analysis, vulnerability identification, remediation, security monitoring, and incident response playbooks.

The ideal candidate will bring at least 3 years of practical Cybersecurity Operations / Incident Response experience and will have participated directly in investigating and responding to security events rather than working primarily in coordination, ticket management, SLA tracking, escalation management, or ITIL-driven processes.


Location

Mexico. Candidates located in Mexico City or Guadalajara are highly preferred.

  • For professionals based in Mexico City or Guadalajara, the position follows a hybrid model with onsite attendance approximately 2–3 days per week.
  • Candidates based in other cities in Mexico may be considered for a remote arrangement; however, Mexico City and Guadalajara profiles will receive priority.


Contract Duration

Permanent, direct employment with the client.

This is a 100% payroll position in Mexico.


Working Hours

This position operates under 10-hour shifts, with one of the following schedules:

  • Sunday through Wednesday, or
  • Wednesday through Saturday.


Available shifts are:

  • 7:00 a.m. – 5:00 p.m., or
  • 1:00 p.m. – 11:00 p.m.


Candidates must be comfortable working within one of these schedules and adapting to business needs.


Language Requirement

Advanced English.

Candidates must be comfortable communicating technical risks, incident findings, and security recommendations in English while collaborating directly with U.S.-based and multicultural teams.


What you'll do

  • Participate directly in cybersecurity monitoring, incident investigation, containment, remediation, and response activities.
  • Investigate security incidents and alerts to determine scope, severity, impact, and appropriate mitigation actions.
  • Conduct threat hunting activities to identify suspicious behaviors and potential threats that may not be detected through standard alerts.
  • Support forensic analysis and incident investigations to identify root cause and understand attacker activity.
  • Identify vulnerabilities and insecure configurations and coordinate appropriate remediation actions.
  • Develop, implement, maintain, and improve incident response processes and playbooks.
  • Configure and monitor security tools, including alerts, correlation rules, dashboards, and reporting mechanisms.
  • Apply threat intelligence to security monitoring, vulnerability detection, and incident investigations.
  • Help determine risk severity and appropriate mitigation approaches for security events.
  • Incorporate lessons learned from incidents into improved preventive and detective security controls.
  • Support automation and orchestration initiatives that improve the efficiency of monitoring and response processes.
  • Collaborate with internal technology, infrastructure, security, and business teams during investigations and remediation efforts.
  • Document incident findings, technical evidence, remediation actions, and recommendations clearly.
  • Stay current with emerging threats, attacker techniques, security technologies, and cybersecurity operations practices.


What you'll bring

  • Minimum 3 years of hands-on experience in Cybersecurity Operations, SOC, Incident Response, or similar operational security roles.
  • Direct experience participating in security incident investigation and response.
  • Hands-on exposure to threat hunting and security monitoring activities.
  • Experience supporting or performing forensic analysis during security investigations.
  • Experience identifying vulnerabilities, insecure configurations, and security risks and supporting their remediation.
  • Experience implementing or working with Incident Response processes and playbooks.
  • Understanding of security event analysis, alert triage, escalation, containment, remediation, and post-incident activities.
  • Experience configuring, monitoring, or using security technologies within SOC or Incident Response environments.
  • Familiarity with endpoint, network, email, threat intelligence, and cloud security concepts.
  • Strong analytical and troubleshooting skills and the ability to investigate complex security events.
  • Ability to clearly communicate technical findings, risks, and recommended actions to different audiences.
  • Strong written and verbal English communication skills.


What will make you stand out

  • Hands-on experience with technologies such as CrowdStrike, Microsoft Defender for Endpoint, Zscaler, Proofpoint, Recorded Future, and Microsoft Azure.
  • Experience with Palo Alto Cortex XSOAR or comparable SOAR platforms.
  • Experience implementing security automation and orchestration workflows.
  • Scripting experience using Python, Shell, or similar languages.
  • Experience with ServiceNow in a cybersecurity operations environment. The source JD specifically lists ServiceNow and Cortex XSOAR as pluses.
  • Certifications such as CISSP, CCSP, CCSK, GSEC, GCIH, GCFE, GCFA, SC-200, CEH, AZ-900, or similar cybersecurity credentials.
  • Experience improving SOC processes, detection capabilities, or Incident Response playbooks.
  • Exposure to threat intelligence and the ability to apply intelligence to active security monitoring and investigations.
  • Experience working in 24x7 cybersecurity operations environments.


Why this opportunity?

This is an opportunity to join a large, globally recognized organization in the professional services and consulting industry, working with international teams on sophisticated cybersecurity operations and Incident Response initiatives.


The role is especially suited for a cybersecurity professional who wants to remain close to the technical and operational side of security, investigating real incidents, analyzing threats, improving detection capabilities, and supporting remediation across enterprise environments.


It offers exposure to modern security technologies, complex investigations, threat intelligence, automation, cloud environments, and U.S.-based stakeholders.


What the Client Offers

  • Career growth opportunities.
  • Annual performance review with potential salary adjustments and internal growth.
  • Meal/grocery vouchers.
  • Savings fund.
  • Vacation premium and statutory benefits.
  • Remote-work allowance, when applicable.


Selection Process

The selection process is expected to include:

  • Initial interview with the local/direct leader.
  • Technical interviews with the U.S.-based team, typically involving two interviewers per session.
  • Final interview with the U.S. Area Director.
  • Background check.


Eligibility Note

This opportunity is available to candidates currently residing in Mexico.


Candidates located in Mexico City and Guadalajara are strongly preferred due to the hybrid working model.


Candidates located elsewhere in Mexico may also be considered for remote work depending on profile and business requirements.


Candidates must also be comfortable working one of the established 10-hour Sunday–Wednesday or Wednesday–Saturday shifts.


Ready for your next career opportunity?

Apply through EX Squared LATAM and take the next step toward joining a global organization where cybersecurity operations, Incident Response, threat intelligence, and hands-on security expertise come together.




Similar jobs