Updated on August 11, 2026
Security Operations Engineer
Full-time / LATAM based – Remote
About the Сlient
We are representing a mature US-based B2B Enterprise software company. They develop an industry-leading ERP platform used by industrial businesses to run mission-critical workflows across inventory, sales, accounting, and logistics.
About the Role
We are looking for a hands-on Security Operations Engineer to help protect a hybrid technology environment spanning Microsoft Azure, Windows infrastructure, corporate endpoints, identity systems, and data center infrastructure.
This is a mid-level technical role focused on operational security: investigating alerts, protecting endpoints and identities, remediating vulnerabilities, supporting incident response, and partnering closely with Infrastructure and Engineering teams.
What We’re Looking For
- 3-5+ years in cybersecurity, security operations, incident response, infrastructure security, or a similar hands-on technical role. (Note: This is an operational role, not a Governance/Compliance/GRC role).
- Strong practical experience with CrowdStrike, Microsoft Defender, or comparable EDR technology.
- Strong familiarity with Windows environments, Active Directory, and Microsoft Entra ID.
- Practical experience securing or investigating workloads in Microsoft Azure.
- Fluent English, both written and verbal, with the ability to communicate risks clearly to technical teams.
- Proven ability to independently prioritize investigations and follow incidents through to resolution in a remote environment.
Bonus Points
- Experience investigating suspicious logins, MFA, VPN access, and Azure Virtual Desktop security.
- Experience coordinating or validating actual vulnerability remediation.
- Experience with Vault (or similar secrets-management platforms), PowerShell scripting, and AWS/Amazon EKS security exposure.
What You’ll Do
- Incident Response: Monitor, investigate, and triage security events across endpoint, identity, cloud, and infrastructure environments. Own incident response from detection through containment and remediation.
- Endpoint Security: Operate and maintain endpoint detection and response (EDR) controls using CrowdStrike and Microsoft Defender to investigate malware, suspicious processes, and persistence mechanisms.
- Identity Security: Monitor and investigate suspicious authentication activity, account compromise, privilege escalation, and unauthorized access involving Microsoft Entra ID and Active Directory.
- Cloud Security: Support security operations across Microsoft Azure and hybrid data center environments.
- Vulnerability Management: Review vulnerability findings, coordinate remediation with system owners, and validate that security controls are operating effectively.
What We Offer
- Location: Remote - LATAM
- $65k-$75k/year
- Flexible PTO Policy