
Purple Team Analyst
Posted Aug 18

Posted Aug 18
This is a fully remote position, open to applicants in Brazil.
• Design and implement attack simulations that reflect real-world scenarios and Cyber Threat Intelligence (CTI), utilizing the MITRE ATT&CK framework.
• Regularly evaluate the effectiveness of security tools, including SIEM, EDR, NDR, and firewalls.
• Collaborate with SOC analysts and Detection Engineering to develop, adjust, and enhance detection rules.
• Improve alert accuracy while minimizing false positives and reducing operational fatigue.
• Set up and oversee automated testing using Breach and Attack Simulation (BAS) tools or open-source frameworks.
• Identify visibility gaps, such as logs that fail to reach the SIEM.
• Convert emulation findings into actionable reports, root cause analyses (RCA), and enhancement plans for technical teams and management.
• Ensure the completion of the learning cycle.
• Strong previous experience in Incident Response, SOC L2/L3, Threat Hunting, or Penetration Testing/Red Teaming.
• Ability to convert adversary TTPs into effective tests and monitoring rules.
• Proficient in using SIEM platforms such as Splunk, Microsoft Sentinel, and QRadar.
• Familiarity with EDR/XDR platforms including CrowdStrike, Defender for Endpoint, and Cortex XDR.
• Understanding of scripting languages and automation techniques.
• Extensive knowledge of Windows and Linux operating systems.
• Awareness of Active Directory (AD) and Entra ID architectures as well as associated vulnerabilities.
• A degree in Information Technology, Cybersecurity, or similar fields is preferred.
• Intermediate English proficiency for reading and analyzing technical documentation and collaborating with international teams.
• Experience with Atomic Red Team, Caldera, Prelude, or BAS platforms like Picus, AttackIQ, and Cymulate.
• Proficient in writing Sigma and YARA rules.
• Familiarity with security testing and native logs in AWS, Azure, and GCP.
• Experience in creating, refining, and validating detection rules, hunting queries, and correlations for SIEM, EDR/XDR, and monitoring platforms.
• Bradesco Top National health insurance.
• Odontoprev dental plan.
• Life insurance coverage.
• Pipo Saúde: digital health and corporate benefits broker.
• TotalPass.
• Transportation allowance provided.
• Alelo Tudo: food and meal expenses on a single card.
• Private pension plan with a double employer match.
• Birthday day off.
• Employee referral program.
• Tuition discounts available at educational institutions.
• Vision Baby kit for employees.
• Exclusive discounts with the SESC group.
• Welcome kit for new hires.
• Breakfast and afternoon fruit provided on in-office days.
• DeepLearning: Corporate University for continued education.
• Opportunities for professional advancement.
• A culture focused on feedback and development.
• Exclusive leadership training program.
• A relaxed, innovation-driven work environment.
• Accessible leadership for all employees.
Millennium Physician Group
Sanford Health
Get handpicked remote jobs straight to your inbox weekly.