Guardar vacante Volver a la búsqueda Descripción Resumen Empleos SimilaresExperience in Incident Response, Digital Forensics, Threat Hunting, or SOC.Lead high-impact cybersecurity incident response effortsSobre nuestro clienteGlobal CompanyDescripciónLead the response to high-impact cybersecurity incidents, including ransomware, identity compromise, business email compromise (BEC), insider threats, supply chain attacks, and data breaches.Act as the Incident Commander, coordinating investigation, containment, recovery, and executive-level communications.Manage, mentor, and develop a team of cybersecurity investigators and incident responders.Define investigative strategies across endpoint, cloud, identity, email, SaaS, and network environments.Oversee digital forensics activities, root cause analysis, evidence handling, attack timeline reconstruction, and remediation planning.Integrate threat intelligence and threat hunting activities to strengthen detection and prevention capabilities.Manage relationships with external incident response providers, MDR/MSSP partners, and specialized security vendors.Collaborate with SOC, Detection Engineering, Cloud Security, Vulnerability Management, and Offensive Security teams to improve cyber resilience.Define, monitor, and optimize key incident response metrics such as MTTD, MTTR, detection effectiveness, and investigation quality.Drive automation and AI adoption through SOAR platforms, scripting, APIs, and workflow optimization.Lead readiness exercises, update playbooks and runbooks, and continuously improve incident response processes.Communicate cyber risks, findings, and incident updates to executive stakeholders while coordinating with Legal, Compliance, Privacy, and Regulatory teams.Perfil buscado10+ years of cybersecurity experience, including significant experience in Incident Response, Digital Forensics, Threat Hunting, or Security Operations.Proven experience leading large-scale enterprise cyber incidents as an Incident Commander or technical lead.Strong leadership experience managing technical cybersecurity teams and driving operational excellence.Advanced hands-on expertise in cyber incident investigations across endpoint, cloud, identity, and enterprise environments.Experience working within global or Follow-the-Sun security operations models.Ability to communicate effectively with executive stakeholders and provide risk-based updates during critical incidents.Deep knowledge of Cyber Incident Response and Incident Command methodologies.Experience with endpoint forensics, memory analysis, and EDR investigations across Windows and Linux environments.Expertise conducting investigations in AWS, Azure, Microsoft Entra ID, and Microsoft 365 environments.Experience performing Threat Hunting using KQL and other SIEM query languages.Strong understanding of network, email, phishing, BEC, malware analysis, and adversary TTPs.Experience with Python or PowerShell scripting, APIs, SOAR platforms, and security automation.In-depth knowledge of the MITRE ATT&CK framework, modern attack techniques, and detection engineering.Ability to lead investigations, perform root cause analysis, and oversee remediation efforts for complex cybersecurity incidents.Bachelor's degree in Computer Science, Cybersecurity, or equivalent practical experience (preferred but strongly valued).Qué OfrecemosSalary & BenefitsBase Salary: Up to MXN $160,000 gross per month.Annual Bonus.Christmas Bonus (Aguinaldo): 41 days.Vacation Premium: 105%.Company Car: Assigned vehicle, renewed every 4 years.Fuel Allowance (Gas Vouchers).Grocery Vouchers.Savings Fund: 13% company contribution (subject to policy caps).Savings Plan (Caja de Ahorro).Relocation Package (for candidates outside Monterrey)Relocation assistance.Flight expenses covered.Family relocation support is also available when applicable.ContactoJackie RodriguezIngresar referencia para vacanteJN-102026-7123075Descripción de la vacanteSectorTecnologías de la informaciónSub SectorSeguridad de SistemasIndustriaTechnology & TelecomsUbicaciónMonterreyTipo de contratoPermanenteNombre del consultorJackie RodriguezReferencia de la vacanteJN-102026-7123075Modalidad de empleoTrabajo Remoto