
Incident Response Specialist – Digital Forensics (DFIR)
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in Brazil.
• Respond to cybersecurity incidents by executing identification, containment, eradication, recovery, and post-incident analysis.
• Conduct forensic examinations on workstations, servers, virtual environments, mobile devices, and cloud infrastructures.
• Gather, maintain, and evaluate digital evidence, ensuring the integrity of the chain of custody is preserved.
• Execute memory forensics, disk forensics, and analyze operating system artifacts.
• Identify the techniques, tactics, and procedures (TTPs) utilized by malicious entities.
• Carry out investigations into compromises related to malware, ransomware, phishing, credential theft, lateral movement, persistence, data exfiltration, and privilege escalation.
• Formulate and implement Threat Hunting hypotheses during incident investigations.
• Create technical and executive reports that include event timelines, attack analyses, impact assessments, root causes, indicators of compromise (IoCs), and recommendations for mitigation.
• Collaborate with SOC, Engineering, Infrastructure, and Cloud teams during containment and recovery efforts.
• Analyze logs from SIEM, EDR, Firewalls, Active Directory, Microsoft 365, Entra ID, VPN, Proxy, IDS/IPS, and various other telemetry sources.
• Develop scripts and automation processes to enhance investigation and response efficiency.
• Assist in the development and refinement of playbooks, operational procedures, and technical documentation.
• Engage in incident response war rooms, collaborating with multidisciplinary teams and clients during critical situations.
• Contribute to tabletop exercises and ongoing improvement initiatives for incident response capabilities.
• Remain informed about emerging threats, vulnerabilities, offensive techniques, and investigative tools.
• A Bachelor's degree in Information Technology or a related field in Information Security is preferred.
• A minimum of 3 years of experience in incident response, forensic analysis, and managing cyber threats.
• Strong background in intrusion detection, log analysis, and security tools including SIEM, EDR, Firewalls, and WAF.
• Practical understanding of security frameworks such as MITRE ATT&CK, NIST, and OWASP.
• Familiarity with cyber threat analysis and security models like the Cyber Kill Chain.
• Hands-on experience with security systems, including Firewalls, WAF, Endpoint Security, Proxy, and Anti-spam solutions.
• Capability to prepare comprehensive technical reports.
• Intermediate English proficiency for technical interpretation and communication in international settings.
• Bradesco Top National Health Plan.
• Odontoprev Dental Plan.
• Life insurance coverage.
• Pipo Saúde: Digital health and corporate benefits brokerage.
• TotalPass: A platform connecting you to various networks to enhance your well-being (and your family's).
• Transportation voucher (commuting allowance).
• Alelo Tudo: A combined food and meal card.
• Private pension plan with double matching — VISION contributes on your behalf.
• Birthday day off: enjoy a day off during your birthday month.
• Referral program: earn cash for successful referrals.
• Discounts available at educational institutions.
• Vision Baby Kit: because new beginnings deserve care and celebration.
• Exclusive discounts with the SESC group: leisure opportunities for you and your family.
• Welcome kit: a comprehensive kit to support your daily work activities.
• Breakfast and afternoon fruit provided on-site during workdays.
The Cigna Group
Handspring Health
Bicycle Health
Get handpicked remote jobs straight to your inbox weekly.