Cyber Security Specialist

Posted Aug 18

This is a fully remote position, open to applicants in Brazil.

📋 Description

• Take ownership of the entire incident response lifecycle from detection to post-mortem: triage, containment, eradication, and recovery.

• Create and sustain playbooks, runbooks, and procedures for incident response.

• Develop and manage SOAR detection and response automations to streamline workflows and minimize manual effort.

• Operate and fine-tune the Elastic detection stack, which includes queries, dashboards, alerts, and event correlation.

• Oversee the maintenance of Elastic infrastructure on Linux.

• Administer CrowdStrike EDR, actively engaging in threat hunting and containment measures.

• Investigate and respond to incidents in AWS involving CloudTrail, GuardDuty, IAM, VPC, and other related services.

• Generate incident reports and metrics for Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) to ensure leadership visibility.

• Work collaboratively with engineering, infrastructure, and compliance teams to address vulnerabilities and minimize the attack surface.


⛳️ Requirements

• Extensive hands-on experience in security incident response within complex, high-volume environments.

• Strong expertise in Elasticsearch/Elastic Stack for detection, threat hunting, and alert development.

• Familiarity with AWS security services and experience in cloud log investigations.

• Practical experience with CrowdStrike or a comparable EDR solution.

• Background in SOAR or automation-platform workflow orchestration.

• Proficient in Linux administration and hardening practices.

• Knowledge of BTT (Boitatá), Apura’s threat intelligence tool.

• Experience in managing mTLS certificate lifecycles and AWS ACM (Certificate Manager).

• Proficient understanding of MITRE ATT&CK, NIST IR, and standard incident taxonomies.

• Ability to exercise independent judgment under pressure and make containment decisions with limited information.

• Capability to convert security findings into actionable insights for engineering and infrastructure teams.

• Skill in maintaining current playbooks, runbooks, and post-mortem documentation.

• Nice to have: experience in financial services, fintech, or high-volume transactional environments.

• Nice to have: Python/Bash scripting skills for automation and tool integration.

• Nice to have: certifications such as GCIH, GCIA, GCFA, OSCP, or equivalent.

• Nice to have: familiarity with PCI-DSS and LGPD compliance requirements.


🏝️ Benefits

• Competitive and market-aligned salary.

• Remote work — no matter where you are, you’re part of the team!

• Home office allowance provided through a monthly deposit in the RecargaPay app.

• Health and dental plans with no co-payment required.

• Life insurance coverage.

• Flexible meal allowance (via Flash).

• TotalPass membership to support your health.

People also viewed

GitLab1 day ago

Staff Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$168k – $238k/year
ApplyView job
GitLab1 day ago

Principal Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$203.2k – $275k/year
ApplyView job
Cisco1 day ago

Software Security Lead

US flagNorth Carolina OnlyFull-timeCybersecurity / Security Engineer$151.6k – $222.4k/year
ApplyView job
Lovesac1 day ago

Senior Engineer, Information Security Architect

US flagConnecticut OnlyFull-timeCybersecurity / Security Engineer$95k – $125k/year
ApplyView job
General Dynamics Information Technology1 day ago

Cybersecurity Architect

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$149.5k – $184k/year
ApplyView job
PGTEK1 day ago

Senior Security Agent / AI Red Team Engineer

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers