Logo for Outcoding

Senior Associate – Cyber Operations (Incident Response)

Role overview

Qualifications

  • Minimum 3 years of hands-on experience in Cybersecurity Operations, SOC, Incident Response, or similar operational security roles
  • Direct experience participating in security incident investigation and response
  • Strong written and verbal English communication skills
  • Experience identifying vulnerabilities, insecure configurations, and security risks

Responsibilities

  • Participate directly in cybersecurity monitoring, incident investigation, containment, remediation, and response activities
  • Conduct threat hunting activities to identify suspicious behaviors and potential threats
  • Support forensic analysis and incident investigations to identify root cause and understand attacker activity
  • Document incident findings, technical evidence, remediation actions, and recommendations clearly

Key facts

  • Remote from: Mexico
  • Full time
  • Senior (5-10 years)
  • English

Hard skills

Other skills

  • Analytical Skills
  • Troubleshooting (Problem Solving)
  • Communication
  • Collaboration

About the company

Outcoding logo

Outcoding

IT Services & IT Consulting

Welcome to Outcoding, an EX Squared company - your premier nearshore outsourcing solution provider! Combining technical expertise with creative execution, we serve as a subsidiary of the renowned technology services provider, EX Squared. With over two decades of experience in the software industry, we excel in delivering high-quality solutions for businesses worldwide.Our team consists of creative minds and technical experts who imagine, build, and evolve digital futures for organizations across the globe. Experience the best of technology and innovation with Outcoding.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

At EX Squared LATAM, we partner with leading organizations across global and regional markets to connect exceptional professionals with high-impact career opportunities.

Our client is a leading global organization in the professional services and consulting industry, supporting businesses with complex technology, cybersecurity, risk, compliance, and transformation initiatives.

For this position, EX Squared LATAM is supporting our client with the recruitment and selection process. The selected professional will be hired directly by the client under their local payroll in Mexico, becoming part of their internal team.

Role Overview

We’re currently looking for a Senior Associate – Cyber Operations (Incident Response) to support cybersecurity operations and respond directly to security incidents within a complex, global environment.

This is a hands-on operational cybersecurity role focused on SOC operations, Incident Response, threat hunting, forensic analysis, vulnerability identification, remediation, security monitoring, and incident response playbooks.

The ideal candidate will bring at least 3 years of practical Cybersecurity Operations / Incident Response experience and will have participated directly in investigating and responding to security events rather than working primarily in coordination, ticket management, SLA tracking, escalation management, or ITIL-driven processes.

Location

Mexico. Candidates located in Mexico City or Guadalajara are highly preferred.

  • For professionals based in Mexico City or Guadalajara, the position follows a hybrid model with onsite attendance approximately 2–3 days per week.
  • Candidates based in other cities in Mexico may be considered for a remote arrangement; however, Mexico City and Guadalajara profiles will receive priority.

Contract Duration

Permanent, direct employment with the client.

This is a 100% payroll position in Mexico.

Working Hours

This position operates under 10-hour shifts, with one of the following schedules:

  • Sunday through Wednesday, or
  • Wednesday through Saturday.

Available shifts are:

  • 7:00 a.m. – 5:00 p.m., or
  • 1:00 p.m. – 11:00 p.m.

Candidates must be comfortable working within one of these schedules and adapting to business needs.

Language Requirement

Advanced English.

Candidates must be comfortable communicating technical risks, incident findings, and security recommendations in English while collaborating directly with U.S.-based and multicultural teams.

What you'll do

  • Participate directly in cybersecurity monitoring, incident investigation, containment, remediation, and response activities.
  • Investigate security incidents and alerts to determine scope, severity, impact, and appropriate mitigation actions.
  • Conduct threat hunting activities to identify suspicious behaviors and potential threats that may not be detected through standard alerts.
  • Support forensic analysis and incident investigations to identify root cause and understand attacker activity.
  • Identify vulnerabilities and insecure configurations and coordinate appropriate remediation actions.
  • Develop, implement, maintain, and improve incident response processes and playbooks.
  • Configure and monitor security tools, including alerts, correlation rules, dashboards, and reporting mechanisms.
  • Apply threat intelligence to security monitoring, vulnerability detection, and incident investigations.
  • Help determine risk severity and appropriate mitigation approaches for security events.
  • Incorporate lessons learned from incidents into improved preventive and detective security controls.
  • Support automation and orchestration initiatives that improve the efficiency of monitoring and response processes.
  • Collaborate with internal technology, infrastructure, security, and business teams during investigations and remediation efforts.
  • Document incident findings, technical evidence, remediation actions, and recommendations clearly.
  • Stay current with emerging threats, attacker techniques, security technologies, and cybersecurity operations practices.

What you'll bring

  • Minimum 3 years of hands-on experience in Cybersecurity Operations, SOC, Incident Response, or similar operational security roles.
  • Direct experience participating in security incident investigation and response.
  • Hands-on exposure to threat hunting and security monitoring activities.
  • Experience supporting or performing forensic analysis during security investigations.
  • Experience identifying vulnerabilities, insecure configurations, and security risks and supporting their remediation.
  • Experience implementing or working with Incident Response processes and playbooks.
  • Understanding of security event analysis, alert triage, escalation, containment, remediation, and post-incident activities.
  • Experience configuring, monitoring, or using security technologies within SOC or Incident Response environments.
  • Familiarity with endpoint, network, email, threat intelligence, and cloud security concepts.
  • Strong analytical and troubleshooting skills and the ability to investigate complex security events.
  • Ability to clearly communicate technical findings, risks, and recommended actions to different audiences.
  • Strong written and verbal English communication skills.

What will make you stand out

  • Hands-on experience with technologies such as CrowdStrike, Microsoft Defender for Endpoint, Zscaler, Proofpoint, Recorded Future, and Microsoft Azure.
  • Experience with Palo Alto Cortex XSOAR or comparable SOAR platforms.
  • Experience implementing security automation and orchestration workflows.
  • Scripting experience using Python, Shell, or similar languages.
  • Experience with ServiceNow in a cybersecurity operations environment. The source JD specifically lists ServiceNow and Cortex XSOAR as pluses.
  • Certifications such as CISSP, CCSP, CCSK, GSEC, GCIH, GCFE, GCFA, SC-200, CEH, AZ-900, or similar cybersecurity credentials.
  • Experience improving SOC processes, detection capabilities, or Incident Response playbooks.
  • Exposure to threat intelligence and the ability to apply intelligence to active security monitoring and investigations.
  • Experience working in 24x7 cybersecurity operations environments.

Why this opportunity?

This is an opportunity to join a large, globally recognized organization in the professional services and consulting industry, working with international teams on sophisticated cybersecurity operations and Incident Response initiatives.

The role is especially suited for a cybersecurity professional who wants to remain close to the technical and operational side of security, investigating real incidents, analyzing threats, improving detection capabilities, and supporting remediation across enterprise environments.

It offers exposure to modern security technologies, complex investigations, threat intelligence, automation, cloud environments, and U.S.-based stakeholders.

What the Client Offers

  • Career growth opportunities.
  • Annual performance review with potential salary adjustments and internal growth.
  • Meal/grocery vouchers.
  • Savings fund.
  • Vacation premium and statutory benefits.
  • Remote-work allowance, when applicable.

Selection Process

The selection process is expected to include:

  • Initial interview with the local/direct leader.
  • Technical interviews with the U.S.-based team, typically involving two interviewers per session.
  • Final interview with the U.S. Area Director.
  • Background check.

Eligibility Note

This opportunity is available to candidates currently residing in Mexico.

Candidates located in Mexico City and Guadalajara are strongly preferred due to the hybrid working model.

Candidates located elsewhere in Mexico may also be considered for remote work depending on profile and business requirements.

Candidates must also be comfortable working one of the established 10-hour Sunday–Wednesday or Wednesday–Saturday shifts.

Ready for your next career opportunity?

Apply through EX Squared LATAM and take the next step toward joining a global organization where cybersecurity operations, Incident Response, threat intelligence, and hands-on security expertise come together.




Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Outcoding

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.