
Information Security Analyst III – Security Operations, WAF, AppSec
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Brazil.
• Manage, configure, oversee, and improve Web Application Firewall (WAF) along with application and API protection solutions.
• Develop, refine, and sustain policies, rules, signatures, exception lists, and protection profiles.
• Perform tuning to minimize false positives, collaborating with business, product, and development teams to track impacts.
• Examine Layer 7 events and blocks to identify attacks, vulnerability exploitation, API misuse, scraping, and bots.
• Implement controls against L7 DDoS attacks, OWASP Top 10 vulnerabilities, credential stuffing, enumeration, and feature misuse.
• Assist in the onboarding of applications, domains, and APIs onto protection solutions.
• Monitor effectiveness, coverage, blocking volume, and metrics for policy maturity.
• Engage in digital certificate management, which includes mTLS, TLS, eCPF, and eCNPJ.
• Aid in the administration, monitoring, and upkeep of Hardware Security Modules (HSMs), including the management of cryptographic key lifecycles and integrations.
• Manage, administer, and optimize security tools within the environment.
• Provide support for security monitoring, triage, investigation, and incident response efforts.
• Contribute to detection engineering, including use cases, rules, and enhancements in visibility.
• Assist in hardening efforts, attack surface reduction, vulnerability remediation, and configuration fortification.
• Participate in the analysis of technical incidents, including root-cause analysis, containment, eradication, lessons learned, and war room activities.
• Collaborate with teams in Infrastructure, Networks, Cloud, Architecture, Application Security, DevSecOps, CSIRT, and various vendors.
• Prepare and maintain technical documentation, procedures, runbooks, and configuration standards.
• Support audits, regulatory inquiries, and the curation of evidence.
• Act as a technical reference for junior and mid-level analysts through mentoring and conducting technical reviews.
• Assist in solution assessments, proof-of-concept projects, and roadmap evolutions.
• Contribute to ongoing improvements, routine automation, and standardization of delivery processes.
• Demonstrated experience in information security operations in mid-sized or large corporate settings.
• Practical experience in managing WAF and application and API protection solutions, covering configuration, tuning, policy management, and event analysis.
• Familiarity with the OWASP Top 10 and OWASP API Security guidelines.
• Understanding of web application attack methodologies and the related mitigation strategies.
• Knowledge of HTTP/HTTPS, TLS, DNS, reverse proxies, load balancers, CDNs, and service publishing architectures.
• Acquainted with firewalls, IPS/IDS, EDR, SIEM, vulnerability management, and network segmentation practices.
• Comprehension of cloud environments, containers, microservices, APIs, and their integration with development pipelines.
• Capable of analyzing logs, correlating events, and executing technical incident investigations.
• Proficiency in automation and scripting to enhance operational routines is advantageous.
• Relevant industry certifications in offensive or defensive security, cloud, or the application protection solutions in use are preferred.
• Medical Insurance
• Dental Insurance
• Renascer Program
• Special Events and Milestones
• Education Investment Program
• Profit-Sharing Plan
• Individual Development Plan
• Private Pension Plan
• Life Insurance
• Tempo Juntos Program
• Meal and/or Food Allowance
• Transportation Allowance
• Childcare/Nanny Assistance
NBCUniversal
BDR Solutions LLC
Sigma Software Group
Sigma Software Group
Get handpicked remote jobs straight to your inbox weekly.