Skip to content

Open nowPosted 56 days ago

Incident Response Analyst

Orbia261 open roles

Where
Heredia, Costa Rica; San Antonio de Belén, Costa Rica
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIncident Response AnalystOrbia · Heredia, Costa Rica; San Antonio de Belén, Costa Rica
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Orbia's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.4%1 day
  2. 3.5%3 days
  3. 7.7%7 days
  4. 13.4%14 days
  5. 34.5%30 days
This job: posted 56 days ago

The posting

About Orbia:

Orbia Advance Corporation is a Purpose-led company with big aspirations. We are out to advance life around the world while maximising value to our shareholders, customers and employees. The Company is passionate about the topics that define how people will live and thrive tomorrow: the future of cities, buildings, agriculture, and materials. Orbia Advance Corporation has five business groups which offer innovative solutions across multiple industries including building and infrastructure, data communications, chemicals and more. In 2018, Orbia Advance Corporation bought a majority stake in Israeli-based Netafim, the world’s leader in drip irrigation, and is helping the world ‘grow more with less’ as it helps to solve food and water scarcity. Orbia Advance Corporation has operations in 41 countries with more than 22,000 employees.

We started as a producer of commodities and have evolved to become a provider of innovative solutions that address the global issues of rapid urbanisation, water and food scarcity, and a growing and aging population. We’re already a global leader in Polymers, Fluor, Building & Infrastructure, Datacom, and Precision Irrigation. We have embarked on a CEO-led transformation, as part of our journey to become a truly purpose-led, future fit company.

Purpose

The Staff Incident Response Analyst is a staff-level individual contributor within Orbia's Cyber Incident Response Team (CIRT), responsible for shaping how the organization prepares for, investigates, contains, and recovers from cybersecurity incidents at global scale. This role leads the most complex and high-impact incident response efforts while also building the systems, playbooks, automation, metrics, and readiness frameworks that improve the effectiveness of the broader incident response function.

Main Responsibilities

  • Lead Orbia's most complex and high-impact security incidents, serving as a senior technical escalation point and coordinating response activity across internal teams, service providers, and business stakeholders.
  • Design, maintain, and continuously improve incident response playbooks, runbooks, decision trees, and escalation procedures for the most critical incident types.
  • Build and mature incident response automation and orchestration capabilities, including evidence collection workflows, enrichment pipelines, repeatable containment patterns, and case-management efficiency improvements.
  • Design and lead cross-organizational incident readiness activities, including technical tabletop exercises, pre-staged response kits, crisis-response technical preparation, and business-unit escalation readiness.
  • Drive proactive threat hunting and technical validation of detection and control coverage against emerging threats, using threat intelligence, incident learnings, behavioral analytics, and data from across Orbia's detection stack.
  • Shape the incident response tooling strategy by evaluating integrations, identifying capability gaps, and partnering with engineering teams and vendors to improve the response toolset.
  • Define, track, and report incident response operational metrics such as time to detect, time to contain, time to recover, case quality, and exercise outcomes, using the results to prioritize process and tooling improvements.
  • Partner with Legal and Compliance, Security Architecture and Engineering, Cyber Threat Operations, and IT leaders to ensure evidence handling, forensic support, response coordination, and remediation execution are aligned during active incidents.
  • Lead post-incident reviews and root-cause analysis for major incidents, translating findings into improvements in detection logic, response procedures, security controls, and operational resilience.

Experience and knowledge required

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent hands-on experience
  • Desirable: Master's degree in Cybersecurity, Computer Science, Engineering, or Business
  • English: Fluent, written and verbal
  • 8 to 12 years of experience in one or more of the following areas: incident response, digital forensics, security operations, cyber threat hunting, cyber threat intelligence, or cyber defense engineering
  • Demonstrated experience leading complex, high-severity incidents and serving as a senior escalation point for technically difficult or business-impacting cases
  • Strong experience building or maturing incident response capabilities beyond case handling alone, including playbooks, automation, tooling integration, readiness exercises, or metrics programs
  • Deep technical experience with the incident management lifecycle, containment strategy, evidence handling, forensic support, and post-incident root-cause analysis
  • Strong working knowledge of enterprise security platforms such as SIEM, EDR/XDR, SOAR, email security, DNS security, identity telemetry, network security tooling, and forensic collection or analysis tools
  • Strong knowledge of threat actor tactics, techniques, and procedures, including use of frameworks such as MITRE ATT&CK and incident response models such as NIST SP 800-61
  • Hands-on capability with scripting or automation in Python, PowerShell, or similar languages to improve response workflows and reduce repetitive work
  • Experience influencing IT, security engineering, legal, compliance, and business stakeholders in a matrixed enterprise environment without formal authority Our Global brands: Dura-Line, Koura Global, Vestolit, Netafim, Alphagary, Wavin.

They offer a broad range of value-added solutions and finished products that contribute to customers’ success and ultimate improve the quality of life for people around the world. Along its commitment to good citizenship, Orbia Advance Corporation delivers Total Value to customers, employees and investors worldwide, every day.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Orbia's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Orbia's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Orbia's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.