
Tier 2 Cyber Defense Analyst – Incident Analysis
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Brazil.
• Manage, process, and analyze cybersecurity requests, incidents, problems, and tasks.
• Conduct advanced analysis of events and alerts from SIEM, EDR, firewalls, IDS/IPS, proxy, Active Directory, and various telemetry sources.
• Correlate events to detect malicious activities.
• Investigate incidents, including indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), lateral movement, privilege escalation, persistence, and potential data exfiltration.
• Participate in crisis management sessions (war rooms) for high-severity incidents.
• Assist in the containment, eradication, mitigation, and recovery of compromised environments.
• Analyze firewall logs, session blocks, suspicious activities, command and control (C2) communications, exploitation attempts, lateral movement, and data exfiltration.
• Support Digital Forensics and Incident Response (DFIR) operations by preserving and collecting evidence.
• Prepare both technical and executive incident reports.
• Maintain effective technical and formal communication with clients and internal teams during incidents.
• Engage in proactive threat hunting exercises.
• Develop, review, and update playbooks, runbooks, procedures, knowledge bases, and response workflows.
• Facilitate the advancement of detection use cases, correlation rules, and response automations.
• Contribute to key performance indicators such as Mean Time to Detect (MTTD), Mean Time to Acknowledge (MTTA), Mean Time to Recovery (MTTR), false-positive rate, and overall operational efficiency.
• Perform advanced incident triage, classification, prioritization, and escalation.
• Execute immediate containment actions, including host isolation, IOC blocking, and revocation of compromised credentials.
• Conduct investigations using EDR, firewall, and SIEM tools without direct supervision in medium- to high-complexity scenarios.
• Request emergency blocks in security controls as needed.
• Suggest enhancements to detection rules, playbooks, processes, and cybersecurity defense policies.
• Provide technical support to the Tier 1 team for complex escalation issues.
• Validate indicators of compromise and recommend collaboration with specialized teams.
• Take part in technical decision-making during critical incidents.
• A bachelor’s degree in Information Technology or a related field is preferred.
• Minimum of 2 years of demonstrable experience in information security operations, maintenance, and support.
• Solid understanding of information security, computer networks, and IT infrastructure.
• Experience or familiarity with security event triage and analysis, monitoring, and threat detection using tools such as SIEM is preferred.
• Knowledge of frameworks such as CIS, MITRE ATT&CK, NIST, and ISO 27001.
• Ability to create and update security procedures, processes, and documentation.
• Understanding of authentication, authorization, and cryptography is preferred.
• Experience or knowledge in identity and access management, Azure AD, firewalls, IDS/IPS, and VPNs.
• Intermediate English proficiency for technical communication and documentation purposes.
• Strong communication skills for engagement with clients, internal teams, and partners.
• Capability to work with DDoS mitigation solutions.
• Familiarity with SSL, TLS, and HTTPS protocols.
• Bradesco Top Nacional health insurance.
• Odontoprev dental insurance.
• Life insurance.
• Pipo Saúde health program.
• TotalPass fitness program.
• Public transportation allowance.
• Alelo Tudo: meal and food benefits on a single card.
• Private pension plan with a 2:1 employer matching contribution.
• Birthday day off.
• Employee referral program.
• Discounts at educational institutions.
• Vision Baby Kit.
• Exclusive discounts through the SESC group.
• Welcome kit.
• Morning and afternoon coffee with fruit on in-office days.
• DeepLearning: Corporate University.
• Opportunities for professional growth.
• Culture of feedback and development.
• Exclusive leadership program.
• Relaxed and innovative work environment.
• Accessible leadership.
St. Charles Health System
Mars
Velocity, A Managed Solutions Company
Fennemore
Get handpicked remote jobs straight to your inbox weekly.