
Mid-Level Analyst – Offensive Security and Detection
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Brazil.
• Carry out adversary simulations and offensive security initiatives utilizing MITRE ATT&CK as a guiding framework.
• Strategize and implement controlled attack scenarios, taking into account techniques, tactics, and attack paths pertinent to the environment.
• Assess the effectiveness of current prevention, protection, and monitoring measures.
• Detect security vulnerabilities based on the outcomes of offensive exercises.
• Engage in detection engineering by converting exercised techniques into use cases, rules, alerts, and monitoring systems.
• Confirm whether the techniques applied during exercises are effectively detected and provide evidence of control coverage.
• Collaborate closely with Cyber Defense, Application Security, and other technical teams to strengthen security protocols.
• Prioritize remediation suggestions based on demonstrated attack paths and identified risks.
• Document scenarios, techniques employed, test outcomes, recognized gaps, and recommendations.
• Occasionally assist with security incident investigations.
• Aid in the automation of security routines, tests, validations, and processes associated with detection and response.
• Contribute to the ongoing enhancement of ROIT’s Cybersecurity maturity.
• Practical experience in offensive security, Purple Team, or Red Team operations.
• Applied understanding of the MITRE ATT&CK framework.
• Experience in simulating adversary tactics and behaviors.
• Knowledge of detection engineering, including the development of rules, use cases, and alerts.
• Capability to evaluate whether an attack technique is adequately detected by existing security measures.
• Familiarity with SOC, SIEM, EDR/XDR, and security monitoring concepts.
• Proficiency in interpreting technical evidence and translating it into improvement recommendations.
• Understanding of operating systems, networks, applications, and fundamental security principles.
• Comfort with automation and scripting for security processes.
• Strong skills in documentation and technical communication.
• Analytical, investigative, and evidence-driven mindset.
• Experience in Purple Team environments.
• Experience in developing and fine-tuning detection rules.
• Knowledge of SIEM, EDR/XDR, and security platforms.
• Experience with automation utilizing Python, PowerShell, Bash, or similar technologies.
• Understanding of Cybersecurity frameworks and industry best practices.
• Experience in incident investigation and response.
• Certifications related to offensive security, defense, or detection.
• Competitive salary and performance-based bonuses.
• Opportunities for professional development and certifications.
• Flexible working hours and remote work options.
• Comprehensive health and wellness benefits.
• Collaborative and innovative work environment.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.