Senior Security Operations Engineer
Bitso · México · 2026-03-17
Sobre el puesto
<div class="content-intro"><h3 class="p1"><span class="s1">Working At Bitso</span></h3> <p class="p1"><span class="s1" style="font-size: 12pt;">We are a diverse team that takes pride in understanding the perspectives of others. We fully embrace working remotely and we are eager to act, improve and accelerate progress inside and outside of our organization.</span></p> <p class="p1"><span class="s1" style="font-size: 12pt;">To drive revolutionary changes in society and make crypto useful, we delight our customers with world-class products, deep care, and intentional empathy.</span></p></div><p><strong><span style="font-size: 12pt;">Your Purpose</span></strong></p> <p><span style="font-size: 12pt;">The Senior Security Engineer is a versatile member of the Security Operations team who brings deep expertise in vulnerability management while actively contributing across the full scope of security operations. You will own the vulnerability management function, but your involvement doesn’t stop there. You are expected to operate as a well-rounded security professional who supports the team across multiple disciplines, including:</span></p> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Vulnerability Management</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Cyber Incident Management</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Threat Intelligence and Threat Hunting</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Security Assessments and Tool Evaluations</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Regulatory Compliance and Audit Support</span></li> </ul> <p><span style="font-size: 12pt;">This is a hands-on, execution-focused role within the Security Operations team. The ideal candidate owns the vulnerability management function with discipline and rigor, while consistently contributing to incident response, threat analysis, compliance support, and other operational priorities as they arise. This role requires a senior security professional who operates with a generalist mindset, brings expertise in vulnerability management, and is capable of mentoring junior team members and driving strategic improvements to the security program.</span></p> <p><strong><span style="font-size: 12pt;">Reports To</span></strong></p> <p><span style="font-size: 12pt;">Security Operations Lead</span></p> <p><strong><span style="font-size: 12pt;">Who You Are</span></strong></p> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Experience</strong>: 5+ years of technical experience in security operations, with strong hands-on experience in vulnerability management. You’ve worked in a SOC, CSIRT, or similar operational security environment where you wore multiple hats and operated with a high degree of autonomy.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Ops Mindset</strong>: You possess a strong sense of urgency and ownership. You don’t wait to be told what to do, you see gaps and fill them. You are willing to participate in a scheduled on-call rotation to effectively address and mitigate critical security incidents outside of business hours.</span></li> </ul> <p><span style="font-weight: 400; font-size: 12pt;"><strong>Technical Proficiency:</strong></span></p> <ol> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Hands-on experience with enterprise vulnerability scanning platforms (Qualys, Tenable, Rapid7, or equivalent).</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Strong understanding of risk-based vulnerability prioritization beyond CVSS factoring in exploit availability, threat intelligence, asset exposure, and business context.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience investigating security alerts using EDRs and SIEM platforms.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Familiarity with endpoint security policies, secure email gateways, and DLP concepts.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Ability to produce clear, data-driven reporting for technical and executive audiences.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience working with Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, or Ansible, including the ability to review and secure infrastructure configurations.</span></li> </ol> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Cloud Native</strong>: Experience working within cloud environments, preferably AWS, with an understanding of cloud-native vulnerability considerations including containers and serverless.</span></li> <li style="font-size: 12pt;"><span…
Competencias solicitadas
- terraform
- ansible
- aws
- python
- bash
Tu próximo puesto ya está aquí.
Busca ofertas en directo de miles de empresas, guarda las que merecen una segunda mirada y deja que JobBob vigile el resto.