
Mid-level Information Security Analyst – Detection, SIEM, Perimeter, NGFW
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Brazil.
• Manage and facilitate the upkeep of the SIEM platform, ensuring accurate collection of log sources, as well as the integrity and quality of incoming data.
• Assist in the development, assessment, and refinement of detection rules and use cases to minimize false positives and enhance alert efficiency.
• Operate and oversee Next-Generation Firewalls (NGFW): implement access rules, NAT, VPNs, maintain justification documentation, and conduct periodic reviews of orphaned rules.
• Actively engage in network segmentation efforts, traffic rule management, and strengthening of perimeter security.
• Monitor, categorize, and investigate security alerts produced by the SIEM, firewalls, and other perimeter security tools.
• Conduct triage and preliminary analysis of perimeter security incidents, executing structured escalation to a Specialist when required.
• Generate operational reports, traffic maps, and indicators regarding security incidents and blocks.
• Develop and maintain up-to-date technical documentation of network topologies, flows, and standard operating procedures (SOPs).
• Professional experience in Information Security, Networking, IT Infrastructure, or related areas with a focus on security.
• Hands-on experience in monitoring, log triage, and regular operation of SIEM platforms.
• Experience in managing and administering Next-Generation Firewalls (such as Check Point, Palo Alto, Fortinet, or equivalents).
• Strong practical understanding of TCP/IP networking, routing, network segmentation (VLANs, DMZs), and communication protocols.
• Knowledge of detection rules, event correlation, and log header analysis.
• Familiarity with both Windows and Linux environments.
• Demonstrated technical analysis skills and thoroughness in documenting activities.
• Excellent analytical capabilities, attention to detail, and an investigative mindset.
• Ability to organize and adhere to Change Management processes.
• Strong communication skills for engaging with infrastructure, telecom teams, and external partners.
• A proactive approach and enthusiasm for ongoing technical development in SecOps.
• Specific experience with Wazuh, Elastic Stack (ELK), or other open-source SIEM platforms.
• Practical knowledge of detection rules aligned with the MITRE ATT&CK framework.
• Basic understanding of Identity and Access Management (IAM) and Active Directory structures.
• Awareness of ISO/IEC 27001 and CIS Controls frameworks.
• Basic scripting skills (Python, Bash, or PowerShell) for automating log analysis tasks.
• Entry-level security or networking certifications (e.g., Security+, CCNA, NSE 4 Fortinet, CCSA Check Point).
• Life insurance;
• Health and dental plans;
• Portobello Corporate University platform;
• Profit Sharing (PPR);
• Discounts at local pharmacies;
• Private pension plan;
• Union membership;
• Discount network – partnerships with various educational institutions;
• Discounts on Portobello product purchases;
• Vacation bonus;
• 'Portobello Mom' allowance – for baby layette purchases;
• Nursery assistance;
• Support for dependents with disabilities (PCD);
• Professional training and development programs;
• Wellhub and many more!!!
Solo Network
Agile Defense
ExtraHop
EMCOR Group, Inc.
Get handpicked remote jobs straight to your inbox weekly.