WHAT MAKES US A GREAT PLACE TO WORK
We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.
WHO YOU’LL WORK WITH
You’ll join our Enterprise Technology team, part of Bain’s digital capabilities practice. In this multidisciplinary group, you’ll help modernize our technology strategy, architecture, and systems—aligning technology with business goals to drive efficiency, agility, and innovation. You’ll collaborate with Cyber Operations, Infrastructure, and Technology teams to strengthen Bain’s security posture and support resilient, secure operations across the firm.
WHERE YOU’LL FIT WITHIN THE TEAM
As a Security Operations Analyst within Bain’s Cyber Operations team, you'll help safeguard the firm's digital assets, systems, and data. You'll monitor, analyze, and respond to cybersecurity threats while supporting the implementation and continuous improvement of security controls that align with regulatory requirements and industry best practices.
Depending on business priorities and your experience, you'll contribute across multiple Security Operations disciplines—including Security Monitoring, Incident Detection and Response, Threat Intelligence, Vulnerability Management, and Proactive Security Testing—or develop deeper expertise within a specialized area.
WHAT YOU’LL DO
Security Monitoring (40%)
- Continuously monitor security systems, logs, and alerts to identify potential security incidents and vulnerabilities.
- Administer and optimize security technologies including SIEM platforms, IDS/IPS, firewalls, endpoint detection and response (EDR), antivirus, and data loss prevention (DLP) solutions.
- Research emerging cyber threats, vulnerabilities, and attack techniques, incorporating relevant intelligence into monitoring and detection activities.
- Help improve the effectiveness of monitoring capabilities through ongoing tuning and process enhancements.
Incident Detection & Response (50%)
- Investigate and analyze security events, including malware, unauthorized access attempts, suspicious activity, and potential data breaches.
- Assess incident severity and business impact, escalating and responding appropriately.
- Execute and continuously improve incident response playbooks to contain threats and restore normal operations.
- Produce regular and ad hoc reporting on security incidents, trends, vulnerabilities, and operational metrics.
- Validate that security controls are operating effectively and remain aligned with internal security policies and standards.
- Collaborate with cross-functional teams to resolve incidents and strengthen the firm's overall security posture.
Professional Development & Continuous Improvement (10%)
- Stay current on evolving cybersecurity technologies, threats, and industry best practices.
- Contribute to automation, process optimization, and operational improvements across the Security Operations function.
- Pursue relevant technical training and professional certifications in partnership with leadership.
- Share knowledge and collaborate with colleagues across Cyber Operations, Enterprise Technology, and business teams.
ABOUT YOU
You're a curious, collaborative cybersecurity professional who enjoys solving complex problems and continuously improving security operations in a fast-paced, global environment.
Required qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or an equivalent combination of education, training, and experience.
- 3-5+ years of experience in Security Operations, Incident Response, or a related cybersecurity function.
- Professional proficiency in English.
- Hands-on experience with SIEM platforms (such as Splunk or Palo Alto XSIAM/XSOAR) and endpoint detection and response (EDR) solutions including CrowdStrike, Microsoft Defender, or similar technologies.
- Experience working with enterprise security technologies including firewalls, IDS/IPS, SIEM, EDR, antivirus, CASB, and DLP solutions.
- Experience investigating and responding to cybersecurity incidents.
- Familiarity with security frameworks such as NIST, ISO 27001, CIS Controls, or CSA.
- Strong analytical, troubleshooting, and problem-solving skills.
- Ability to communicate technical concepts clearly to both technical and non-technical stakeholders.
- Ability to manage multiple priorities while working independently and collaboratively within a global team.
Nice to have
- Experience with vulnerability management and attack surface management platforms.
- Exposure to threat intelligence platforms, digital forensics, deception technologies, or third-party cyber risk tools.
- Experience implementing or administering endpoint security controls.
- Experience automating security processes through scripting or orchestration.
- Familiarity with cloud security frameworks and controls.
- Relevant cybersecurity certifications such as Security+, CySA+, GSEC, GCIH, GCIA, or CISSP.
WORKING MODEL
This role follows a hybrid model, requiring in-office presence two days per week at our Polanco office in Mexico City.