A2MAC1

Senior Cybersecurity Engineer

A2MAC1 · Querétaro, Querétaro, Mexico

Software Development · 501-1,000 employees

2 d ago
Senior (5-10 yrs) Full-time Mexico
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves managing security capabilities and leading complex L3 incident response and preventive engineering. You will drive structural improvements across identity, endpoint, cloud, and product security while mentoring teams on secure engineering practices.

What they look for

Azure M365 Entra Defender Intune Purview Sentinel SIEM SOAR DevOps PowerShell Python Vulnerability management Incident response Cybersecurity Network security

Requirements

Candidates must have 5-8 years of experience in IT infrastructure, application security, and cybersecurity operations. Proficiency in Azure security architecture, scripting, and strong communication skills are essential for this position.

Benefits

Biweekly payment Christmas bonus Vacations by the law Vacation bonus by the law Food vouchers Gas vouchers Medical insurance Life insurance

Full description

Manage security capabilities and lead complex L3 incident response and preventive engineering, ensuring the outsourced SOC’s detections and escalations translate into structural improvements across identity, endpoint, email, DLP, cloud, DevOps, Product and AI security.

The Senior role designs and drives resilient security solutions and reduces exposure surface by turning repeated incidents, vulnerabilities, and audit findings into prioritized roadmaps, automation, and guardrails—balancing security, usability, and compliance.

Tasks & Responsabilities

·        End-to-end ownership of one or more security capabilities/platforms: design, implement, operate, and evolve them with threats and business needs.

·        Serve as L3 technical authority for complex/high-impact incidents: lead investigations, perform deep RCA, and define long-term preventive engineering actions.

·        Drive exposure surface reduction by improving vulnerability management processes, prioritization, and engineering remediation patterns.

·        Ensure operational excellence for anti-phishing and DLP (advanced tuning, policy design, exception governance, evidence-by-default).

·        Embed security into DevOps and product environments: threat modeling facilitation, application security tooling/guardrails, and automation to shift left.

·        Design and maintain AI security implementation patterns (data protection, identity controls, safe usage guardrails) aligned with compliance needs.

·        Strengthen the SOC partner operating model: refine escalation criteria, enrich context, improve runbooks, and reduce noise via engineering.

·        Mentor/coach (as IC leadership) on secure engineering practices, troubleshooting methodology, and standards adoption across teams.

Professional Experience & Studies

  • Experience: 5–8 years of significant successful experience in IT infrastructure, application security and cybersecurity operations or engineering.
  • Studies: Engineering degree or Master’s in IT/Security is a plus; Bachelor’s remains acceptable with strong track record (consistent with your baseline).
  • Language: Professional English; strong written skills for standards and audit evidence narratives.

Certifications

Must have

  • Azure Security & Governance, Sentinel/Defender, Purview, Entra IAM, Azure Security Architecture.

Nice to have

  • Ethical hacking experience.

Skills & Abilities

Must have

  • Strong communication, negotiation, leadership behaviors (“can do”, “team player”), problem-solving and analytical skills.
  • Expert-level hands-on expertise: Azure/M365/Entra, Defender, Intune, Purview DLP/MIP, Sentinel SIEM/SOAR automation, Azure DevOps CI/CD.
  • Strong networking and system foundations (Windows/Linux/AD, firewall/VPN/DNS/DHCP/Wi‑Fi) and ability to drive complex remediation.
  • Strong security fundamentals: vulnerability management, OWASP, pentesting concepts, AI security; ability to turn incidents/findings into structural improvements.
  • Strong scripting/automation capability (PowerShell/Python) and ability to operate with agile/Kanban.
  • Knowledge of standards and governance: ITIL/ITSM, ISO27001/NIST, regulatory context (GDPR/TISAX).

Nice to have

  • Automotive/industrial experience; additional professional languages (French/German/Chinese).

Biweekly Payment

IMSS

Chritsmas Bonus

Vacations by the law

Vacations bonus by the law

Food Vouchers

Gas Vouchers

Medical Insurance only for employee

Life Insurance only for employee