
Mid-Level Cybersecurity Analyst
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in Brazil.
• Continuously oversee security events and alerts, conducting triage, analysis, investigation, classification, and management.
• Examine suspicious activities by correlating data from SIEM, EDR/XDR, firewalls, email security, identity management, networks, and other security tools.
• Implement and monitor vulnerability management activities, including identification, classification, prioritization, assignment, remediation tracking, and validation of remediation efforts.
• Assess vulnerabilities based on technical severity, exposure, exploitability, business importance, and known exploits.
• Operate, manage, and maintain security tools, ensuring availability, proper configurations, integrations, policies, rules, versions, and agents.
• Develop and review security rules, policies, alerts, exceptions, and configurations.
• Assist in the hardening process of servers, workstations, systems, devices, and other technological components.
• Evaluate compliance with security baselines and best practices, identifying deviations and monitoring remediation efforts.
• Aid in incident response, encompassing investigation, containment, eradication, recovery, and evidence collection.
• Support root-cause analyses and post-incident activities, outlining corrective and preventive measures.
• Create and maintain technical documentation, procedures, playbooks, workflows, standards, baselines, evidence, inventories, and records.
• Generate reports and metrics on vulnerabilities, alerts, incidents, tools, hardening, and security controls.
• Collaborate with Infrastructure, Networks, Cloud, Workplace, Systems, Architecture, Service Desk, and vendor teams.
• Assist with infrastructure and systems projects and changes by evaluating security and recommending appropriate controls.
• Keep abreast of information related to vulnerabilities, threats, attack techniques, and indicators of compromise.
• Contribute to automation, enhanced coverage, and operational efficiency across Cybersecurity processes.
• Facilitate audits, security assessments, and compliance processes by providing necessary technical evidence.
• Bachelor’s degree in Computer Science, Information Systems, Software Engineering, Systems Analysis and Development, Information Security, or a related discipline.
• Practical experience in security operations, alert investigation, and incident response support.
• Familiarity with SIEM, EDR/XDR, and vulnerability management tools.
• Knowledge of the vulnerability management lifecycle, including risk-based prioritization and validation of remediation efforts.
• Understanding of networks, protocols, Windows, Linux, and Active Directory as they pertain to security analysis.
• Experience in administering security tools, fine-tuning rules and policies, and implementing secure configurations (hardening).
• Capability to prepare technical documentation, playbooks, and metrics while collaborating with technology teams.
• Experience in automating processes using Artificial Intelligence, Python, PowerShell, APIs, or SOAR.
• Knowledge of cloud security and identity solutions such as Entra ID and SOC environments.
• Proven experience in creating and enhancing detection rules and performing proactive threat investigations (threat hunting).
• Experience working within regulated environments, ideally in the pharmaceutical sector.
• Certifications related to security operations or tools utilized by the organization are advantageous.
• Meal voucher
• Food allowance
• 100% coverage for Libbs medications
• Pharmacy benefits through Vidalink
• PPR (Profit-Sharing and Results Program)
• Parking, transportation allowance, or company shuttle
• USE Program: subsidy for purchasing work-related equipment, which can also be used for personal purposes
• Flexible benefits (TotalPass, life insurance, private pension plan, medical and dental insurance, and food allowance)
• Flexible working hours (start between 7:00 a.m. and 9:00 a.m.; finish between 4:00 p.m. and 6:00 p.m.)
• Remote work with occasional, organized in-person meetings
• Access to coworking spaces worldwide
Vision Cybersecurity
Stefanini LATAM
Bancorbrás
Kemper
Get handpicked remote jobs straight to your inbox weekly.