Senior Manager Cybersecurity Incident Response

Hace 3 horas

Mexico, chihuahua British American Tobacco Jornada completa
Senior Manager Cybersecurity Incident Response

Empresa : British American Tobacco Tipo de empleo : Tiempo completo Monterrey, Mexico

Descripción del trabajo - Senior Manager Cybersecurity Incident Response

BAT is evolving at pace into a global multi-category business. With products like VELO, VUSE and GLO we are on a mission to decrease the health impact of our industry

To achieve our ambition, we are looking for colleagues who are ready to Be The Change. Come, join us on this journey

British American Tobacco Mexico has an exciting opportunity for a Senior Manager Cybersecurity Incident Response in Monterrey.

This role combinesprincipal-level technical expertise with people leadership and major incident command. The successful candidate will lead a team of investigators, act as Incident Commander during high-severity cyber incidents, remain technically engaged in complex investigations, and drive continuous improvement across BAT's detection, response and cyber resilience capabilities within a global 24x7 Follow-the-Sun operating model.

Your key responsibilities will include:

  • Lead and act as Incident Commander for major cyber incidents, including ransomware, nation-state activity, identity compromise, BEC, insider threats, supply-chain attacks and data breaches, overseeing investigation, containment, recovery and executive communications.
  • Provide risk-based updates to senior leadership and coordinate with Legal, Compliance, Privacy, Regulatory Affairs, Internal Audit and external stakeholders on incident response, regulatory obligations and breach notifications.
  • Participate in the CDC management on-call rotation, ensuring effective Follow-the-Sun operations, governance, vendor management and coordination of external IR retainers, MDR/MSSP providers and specialist partners.
  • Define and lead investigative strategies across endpoint, cloud, identity, SaaS, email and network environments, providing hands‑on leadership during complex investigations and ensuring high standards of evidence handling, technical quality and reporting.
  • Conduct in-depth technical analysis of sophisticated cyber threats, establishing attack timelines, identifying root causes, assessing business impact and driving effective containment, eradication and recovery activities.
  • Drive operational excellence through continuous improvement of Incident Response metrics, automation, AI adoption, playbooks, workflows, readiness exercises and post‑incident remediation tracking.
  • Partner closely with SOC, Detection Engineering, SecOps, Cloud Security, Identity, Vulnerability Management and Offensive Security teams to strengthen enterprise cyber resilience and address systemic risks.
  • Recruit, mentor and develop high‑performing incident responders while maintaining strong hands‑on expertise in enterprise incident response and incident command, endpoint forensics and memory analysis (Windows/Linux), cloud and identity investigations (AWS, Azure, Entra ID and Microsoft 365), threat hunting, network, email and malware analysis, adversary TTPs, Python/PowerShell scripting, SOAR, automation, enterprise detection engineering and the MITRE ATT&CK framework.

What are we looking for?

  • Bachelor's Degree in Computer Science, Cybersecurity or equivalent practical experience.
  • 6 to 10 years of cybersecurity experience, including significant experience in Incident Response, Digital Forensics, Threat Hunting or Security Operations.
  • Proven experience leading large‑scale enterprise cyber incidents as Incident Commander or technical lead.
  • Experience leading technical teams through people management or operational leadership.
  • Demonstrated principal‑level investigative capability across endpoint, cloud, identity and enterprise environments.
  • Experience working within global or Follow‑the‑Sun security operations and communicating with executive stakeholders.
  • Experience within a multinational enterprise, cloud provider, technology company or leading incident response consultancy.(Desirable)
  • GIAC certifications (GCFA, GCIH, GREM, GNFA, GCTI), CISSP or CISM. (Desirable)

What we offer you?

  • We offer a market leading annual performance bonus (subject to eligibility)
  • Our range of benefits varies by country and includes diverse health plans, initiatives for work‑life balance, transportation support, and a flexible holiday plan with additional incentives
  • Your journey with us isn't limited by boundaries; it's propelled by your aspirations. Join us at BAT and become a part of an environment that thrives on internal advancement, where your career progression isn't just a statement – it's a reality we're eager to build together. Seize the opportunity and own your development;