← Todos los empleos

Tier 2 Cyber Defense Analyst – Incident Analysis

Sobre el puesto

• Process, analyze, and manage cybersecurity requests, incidents, problems, and tasks
• Perform advanced analysis of events and alerts from SIEM, EDR, firewalls, IDS/IPS, proxy, Active Directory, and other telemetry sources
• Correlate events to identify malicious behavior
• Investigate incidents, including IOCs, TTPs, lateral movement, privilege escalation, persistence, and potential data exfiltration
• Participate in crisis rooms (war rooms) for high-severity incidents
• Contribute to the containment, eradication, mitigation, and recovery of compromised environments
• Analyze firewall logs, blocks, suspicious sessions, C2 communications, exploitation attempts, lateral movement, and exfiltration
• Support DFIR operations by preserving and collecting evidence
• Prepare technical and executive incident reports
• Maintain technical and formal communication with clients and internal teams during incidents
• Conduct proactive threat hunting
• Develop, review, and update playbooks, runbooks, procedures, knowledge bases, and response workflows
• Support the evolution of detection use cases, correlation rules, and response automations
• Contribute to KPIs such as MTTD, MTTA, MTTR, false-positive rate, and operational efficiency
• Perform advanced incident triage, classification, prioritization, and escalation
• Execute immediate containment, including host isolation, IOC blocking, and revocation of compromised credentials
• Conduct EDR, firewall, and SIEM investigations without direct supervision in medium- and high-complexity scenarios
• Request emergency blocks in security controls
• Propose improvements to detection rules, playbooks, processes, and cyber defense policies
• Provide technical support to the Tier 1 team for complex escalations
• Validate indicators of compromise and recommend engaging specialized teams
• Participate in technical decision-making during critical incidents

• A bachelor’s degree in Information Technology or another field is preferred
• At least 2 years of proven experience in information security operations, maintenance, and support
• Knowledge of information security, computer networks, and IT infrastructure
• Experience with or knowledge of security event triage and analysis, monitoring, and threat and attack detection using tools such as SIEM is preferred
• Knowledge of CIS, MITRE ATT&CK, NIST, and ISO 27001
• Ability to create and update security procedures, processes, and documentation
• Knowledge of authentication, authorization, and cryptography is preferred
• Experience with or knowledge of identity and access management, Azure AD, firewalls, IDS/IPS, and VPNs
• Intermediate English proficiency for technical communication and documentation
• Strong communication skills for interacting with clients, internal teams, and partners
• Ability to work with DDoS mitigation solutions
• Knowledge of SSL, TLS, and HTTPS

• Bradesco Top Nacional health insurance
• Odontoprev dental insurance
• Life insurance
• Pipo Saúde
• TotalPass
• Public transportation allowance
• Alelo Tudo: meal and food benefits on a single card
• Private pension plan with a 2:1 employer matching contribution
• Birthday day off
• Employee referral program
• Discounts at educational institutions
• Vision Baby Kit
• Exclusive discounts through the SESC group
• Welcome kit
• Morning and afternoon coffee with fruit on in-office days
• DeepLearning: Corporate University
• Professional growth opportunities
• Feedback and development culture
• Exclusive leadership program
• Relaxed and innovative environment
• Accessible leadership