
Cyber Defense Analyst, Tier 2 – Incident Analysis
Posted 8 hours ago

Posted 8 hours ago
This is a fully remote position, open to applicants in Brazil.
• Manage, process, and analyze requests, incidents, problems, and tasks pertaining to cybersecurity.
• Conduct in-depth analyses of events and alerts generated by SIEM, EDR, firewalls, IDS/IPS, proxy, Active Directory, and other telemetry sources.
• Correlate events to detect malicious activities.
• Investigate security incidents, focusing on IOCs, TTPs, lateral movement, privilege escalation, persistence, and potential data exfiltration.
• Engage in war room activities during high-severity incidents.
• Assist in the containment, eradication, mitigation, and recovery processes for compromised environments.
• Execute specialized analyses of firewall devices.
• Support DFIR operations by gathering and preserving evidence.
• Create technical and executive-level incident reports.
• Maintain formal communication with clients and internal teams during incidents.
• Conduct proactive threat hunting based on hypotheses, IOCs, and suspicious behaviors.
• Develop, review, and revise playbooks, runbooks, procedures, knowledge bases, and incident response workflows.
• Aid in enhancing detection use cases, correlation rules, and response automations.
• Contribute to key performance indicators such as MTTD, MTTA, MTTR, false-positive rate, and overall operational efficiency.
• Triage, classify, prioritize, and escalate incidents accordingly.
• Implement immediate containment measures, including host isolation, IOC blocking, and revocation of compromised credentials.
• Carry out technical investigations in EDR, firewall, and SIEM environments independently in medium- and high-complexity scenarios.
• Provide technical support to the Tier 1 team and engage in technical decision-making during critical incidents.
• Bachelor’s degree in Information Technology or a related field.
• Minimum of 2 years of demonstrable experience in information security operations, maintenance, and support.
• Professional experience in information security, computer networks, and IT infrastructure.
• Familiarity with security frameworks and standards such as CIS, MITRE ATT&CK, NIST, and ISO 27001.
• Capability to create and update security procedures, processes, and documentation.
• Preferred knowledge of advanced security concepts, including authentication, authorization, and encryption.
• Experience with or knowledge of identity and access management, Azure AD, firewalls, IDS/IPS, and VPNs.
• Intermediate English proficiency for technical communication and documentation purposes.
• Strong communication skills for effective interaction with clients, internal teams, and partners.
• Ability to work with DDoS mitigation solutions.
• Understanding of web security protocols: SSL, TLS, and HTTPS.
• Preferred experience in the triage and analysis of security events, monitoring, and threat detection using tools such as SIEM.
• Bradesco Top Nacional health insurance.
• Odontoprev dental insurance.
• Life insurance.
• Pipo Saúde: Digital healthcare and corporate benefits brokerage.
• TotalPass.
• Transportation allowance.
• Alelo Tudo: Meal and food benefits on a single card.
• Private pension plan with double employer matching.
• Birthday day off.
• Employee referral program.
• Discounts at educational institutions.
• Vision Baby Kit.
• Exclusive discounts through the SESC group.
• Welcome kit.
• Morning and afternoon coffee with fresh fruit on in-office days.
• DeepLearning: Our corporate university.
• Opportunities for professional growth.
• A culture focused on feedback and development.
• Exclusive leadership program.
• A relaxed environment driven by innovation.
• Accessible leadership.
Hotelbeds
PointClickCare
Método Engenharia
ASAAS
Get handpicked remote jobs straight to your inbox weekly.