About this role
About the Role
Join one of Mexico's most emblematic companies. You will support implementing defined strategies to mitigate Information Security risks (SdI) by applying best practices to protect the Confidentiality, Integrity, and Availability of information. What You'll Do
-
Detect, analyze, and classify information security incidents.
-
Support coordinating the full incident response lifecycle: identification, containment, eradication, and recovery.
-
Prioritize incidents based on impact to confidentiality, integrity, availability, and reputation.
-
Facilitate development of event/incident analyses related to SdI.
-
Investigate attack vectors, scope, and impact.
-
Identify indicators of compromise (IoCs) and attacker tactics/techniques (MITRE ATT&CK).
-
Preserve digital evidence in line with forensic best practices.
-
Implement immediate actions to limit damage, coordinating isolation of compromised systems, revocation of access, traffic or account blocks.
-
Technical remediation with infrastructure, networks, and applications teams.
-
Act as facilitator for coordination during critical SdI events and incidents.
-
Support in criticality-based events to ERISI, CISO, Crisis Committee and Authorities.
-
Facilitate clear, timely, structured communication channels.
-
Conduct post-mortem analyses (lessons learned).
-
Propose improvements to controls, processes, and tools.
-
Feed use cases for SIEM/EDR, etc.
-
Reduce recurrence of similar incidents.
-
Support the development of playbooks and procedures, including incident response playbooks and operational runbooks to standardize response to malware, phishing, ransomware, data leakage, etc. What We're Looking For
-
Education: Bachelor's/Engineering in Technology or related; Bachelor's/Engineering in Computer Science or related; Master’s degree preferred; relevant certifications.
-
Certifications: At least one of CISSP, SSCP, CISM, CEH, CHFI.
-
Language: English – intermediate.
-
Experience: Not specified in posting.
-
Knowledge and Skills: Ability to manage security services efficiently, information literacy, risk analysis, effective written/spoken communication, regulatory/compliance knowledge, planning/project management (PMO), practical SIEM/EDR experience, playbooks/automation (SOAR), relationship management, time management, end-to-end incident handling, critical thinking, data analysis and reporting.
-
Competencies: Strategic vision, leadership, adaptability, customer focus, networking, negotiation, innovation, commitment, collaboration, results orientation, integrity. Nice to Have
-
Master’s degree and/or additional certifications in information security (e.g., CISSP, CISM, CEH, CHFI).
-
Practical experience with incident response playbooks and security automation.