
Analista de Segurança da Informação Sr – Resposta a Incidente
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Brazil.
• Incident Management: Lead the technical response to complex security incidents (Ransomware, APTs, Insider Threats), from detection to lessons learned (Post-Mortem).
• Threat Hunting: Conduct proactive threat hunting within the network and endpoints, based on hypotheses derived from Threat Intelligence.
• Digital Forensics: Collect and analyze digital artifacts (memory, disk, logs) to reconstruct the attack timeline.
• Detection Engineering: Create and optimize correlation rules in the SIEM and detection signatures (YARA, Snort/Suricata).
• Automation (SOAR): Develop playbooks and scripts (Python/PowerShell) to automate responses to repetitive alerts.
• Mentoring: Support the technical development of junior and mid-level analysts (N1/N2).
• Solid Experience: Proven experience in Blue Team, SOC, or CSIRT (minimum of 3 years recommended).
• Frameworks: Proficiency in NIST CSF and particularly in MITRE ATT&CK for mapping of TTPs (Tactics, Techniques, and Procedures).
• Operating Systems: In-depth knowledge of Windows internals (Event Logs, Registry, Prefetch) and Linux (Logs, Kernel, Bash).
• Defense Tools: Hands-on experience with SIEM tools (Splunk, Elastic, Sentinel, or QRadar) and EDR/XDR solutions (CrowdStrike, SentinelOne, Defender).
• Networking: Deep analysis of network traffic (PCAP) using Wireshark or Zeek.
• 100% remote work
• Administrative support
Solo Network
Agile Defense
ExtraHop
EMCOR Group, Inc.
Get handpicked remote jobs straight to your inbox weekly.