
Senior Cyber Security Analyst
Posted Aug 18

Posted Aug 18
This is a fully remote position, open to applicants in Brazil.
• Serve as a senior responder throughout the entire incident lifecycle: detection, triage, containment, eradication, recovery, and post-incident analysis.
• Conduct threat hunting and proactive investigations across endpoints, cloud infrastructures, and network telemetry.
• Create, adjust, and oversee detection rules, dashboards, and alerts on Elastic (Elasticsearch/Kibana), aiming to decrease false positives and enhance signal quality.
• Design and sustain detection and response automations (SOAR) to streamline workflows and minimize manual efforts.
• Investigate and address endpoint incidents using CrowdStrike (EDR), including containment procedures and root-cause analysis.
• Respond to incidents within AWS, covering CloudTrail, GuardDuty, IAM, and VPC.
• Perform log analysis and investigations on Linux systems.
• Contribute to and uphold playbooks, runbooks, and response protocols.
• Generate clear incident documentation, timelines, and lessons-learned reports.
• Work collaboratively with engineering, infrastructure, and compliance teams to address vulnerabilities and enhance security measures.
• Extensive hands-on experience as a security analyst in a SOC/CSIRT or Blue Team, managing real incidents from start to finish.
• Proficient understanding of Elasticsearch/Elastic Stack for detection engineering, threat hunting, and alerting.
• Familiarity with AWS security services and cloud log analysis.
• Practical experience with CrowdStrike or a comparable EDR solution.
• Knowledge of workflow automation and orchestration using a SOAR/automation platform.
• Strong Linux skills, encompassing administration, hardening, and log analysis.
• Familiarity with MITRE ATT&CK, NIST IR, and incident taxonomies.
• Excellent analytical abilities and capacity to maintain effectiveness under pressure during active incidents.
• Capability to take full ownership of assigned incidents through to post-incident analysis.
• Ability to identify gaps in detection coverage and enhance rule quality.
• Strong communication skills during active incidents, ensuring clarity and conciseness.
• Ability to collaborate effectively with engineering and infrastructure teams on vulnerability remediation.
• Commitment to continuous learning about threats pertinent to fintech and payment sectors.
• Nice-to-have: experience in financial services, fintech, or high-volume transactional environments.
• Nice-to-have: skills in Python or Bash scripting for automation and tool integration.
• Nice-to-have: relevant certifications such as GCIH, GCIA, GCFA, GNFA, or equivalent.
• Nice-to-have: familiarity with PCI-DSS and LGPD compliance requirements.
• Competitive salary aligned with market standards.
• Remote work flexibility—be part of the team from anywhere!
• Monthly home office allowance provided through the RecargaPay app.
• Comprehensive health and dental plans with no co-payment required.
• Life insurance coverage.
• Flexible meal allowance provided via Flash.
• TotalPass membership for your health and wellness needs.
ImageTrend
Satellite Office
Stefanini LATAM
Cox Enterprises
Get handpicked remote jobs straight to your inbox weekly.