
Mid-Level SOC Analyst – Evening Shift
Posted 12 hours ago

Posted 12 hours ago
This is a fully remote position, open to applicants in Brazil.
• Oversee, prioritize, and enhance security alerts of varying complexities generated by the SIEM.
• Examine logs from ZTNA, EDR/XDR, cloud environments, databases, DLP, WAF, and CSPM.
• Perform thorough analyses of security alerts and events, linking various indicators prior to concluding investigations.
• Investigate and react to cyber incidents, recommending corrective and preventive measures.
• Administer ticket workflows, ensuring accurate logging, tracking, and escalation as necessary.
• Create, assess, and refine playbooks, runbooks, and standard operating procedures (SOPs).
• Offer structured feedback to Detection Engineering regarding necessary use cases and rule adjustments.
• Recognize monitoring deficiencies and propose new SIEM use cases based on MITRE ATT&CK, pertinent TTPs, essential assets, and emerging threats.
• Participate in Cyber Threat Intelligence (CTI) and Threat Hunting initiatives.
• Propel continuous SOC enhancement through automation and process improvement.
• Generate technical and management reports on security status and incidents addressed.
• Aid in compliance with PCI DSS, ISO 27001, Brazil’s LGPD, and BACEN regulations.
• Assist in internal audits by supplying evidence and technical documentation.
• Strong experience in SOC operations, alert triage, and incident response.
• Practical expertise with SIEM platforms, encompassing query development, alert evaluation, and event correlation.
• Familiarity with EDR/XDR, ZTNA, DLP, WAF, and CSPM.
• Understanding of the MITRE ATT&CK framework as it relates to detection and inquiry.
• Knowledge of regulatory standards including PCI DSS, ISO 27001, Brazil’s LGPD, and BACEN requirements.
• Proficient in producing technical documentation and reports.
• Detail-oriented and analytical mindset, capable of scrutinizing security events, challenging hypotheses, and substantiating conclusions with solid evidence.
• Ability to propose and structure monitoring use cases by converting suspicious activities into identified threats and actionable SIEM detection rules.
• Bachelor’s degree in Information Security or a related discipline — preferred.
• Experience with SOAR and playbook automation — preferred.
• Familiarity with PCI DSS and ISO 27001 certification processes — preferred.
• Security+, CySA+, CSA, or equivalent certifications — preferred.
• Experience securing Azure, GCP, or Oracle cloud environments — preferred.
• Availability to work 8 hours a day, Monday to Friday.
• Availability for the afternoon/evening shift, from 2:00 p.m. to 11:00 p.m.
• Availability for weekend on-call duty, working 1 weekend followed by 2 weekends off.
• Medical and dental insurance with no copay.
• Life insurance.
• Prescription medication assistance.
• Fitness and wellness allowance.
• Four complimentary monthly therapy or nutritionist sessions through Zenklub.
• Quick massage services at the headquarters.
• Flexible meal and food allowance on a Visa card.
• Complimentary meals at headquarters.
• Childcare allowance.
• Parental support program.
• Extended maternity and paternity leave.
• In-house training platform.
• Education assistance covering 70% of undergraduate and language course tuition, along with course and book purchases.
• Home office allowance.
• Work equipment provided.
• Home office furniture allowance.
• Partnership with WOBA for coworking access across Brazil.
• Day off during the birthday month.
• Happy hour allowance.
• Referral bonus for recommending new employees.
• Bonus based on annual objectives.
• Stock option plan.
• No dress code.
Axians Somnitec AG
Motive
Reinsurance Group of America, Incorporated
Kryptus SA
Get handpicked remote jobs straight to your inbox weekly.