← Todas as vagas

Cyber Defense Analyst, Tier 2 – Incident Analysis

Sobre a vaga

• Process, analyze, and manage requests, incidents, problems, and tasks related to cybersecurity
• Perform advanced analysis of events and alerts from SIEM, EDR, firewalls, IDS/IPS, proxy, Active Directory, and other telemetry sources
• Correlate events to identify malicious behavior
• Investigate security incidents, including IOCs, TTPs, lateral movement, privilege escalation, persistence, and potential data exfiltration
• Participate in war rooms during high-severity incidents
• Contribute to the containment, eradication, mitigation, and recovery of compromised environments
• Perform specialized analyses of firewall devices
• Support DFIR operations by preserving and collecting evidence
• Prepare technical and executive incident reports
• Maintain formal technical communication with clients and internal teams during incidents
• Conduct proactive threat hunting based on hypotheses, IOCs, and suspicious behavior
• Develop, review, and update playbooks, runbooks, procedures, knowledge bases, and incident response workflows
• Support the enhancement of detection use cases, correlation rules, and response automations
• Contribute to KPIs such as MTTD, MTTA, MTTR, false-positive rate, and operational efficiency
• Triage, classify, prioritize, and escalate incidents
• Perform immediate containment, including host isolation, IOC blocking, and revocation of compromised credentials
• Conduct technical investigations in EDR, firewall, and SIEM environments without direct supervision in medium- and high-complexity scenarios
• Provide technical support to the Tier 1 team and participate in technical decision-making during critical incidents

• Bachelor’s degree in Information Technology or a related field
• At least 2 years of proven experience in information security operations, maintenance, and support
• Professional experience in information security, computer networks, and IT infrastructure
• Knowledge of security frameworks and standards such as CIS, MITRE ATT&CK, NIST, and ISO 27001
• Ability to create and update security procedures, processes, and documentation
• Preferred knowledge of advanced security concepts, including authentication, authorization, and encryption
• Experience with or knowledge of identity and access management, Azure AD, firewalls, IDS/IPS, and VPNs
• Intermediate English proficiency for technical communication and documentation
• Strong communication skills for interacting with clients, internal teams, and partners
• Ability to work with DDoS mitigation solutions
• Knowledge of web security protocols: SSL, TLS, and HTTPS
• Preferred experience with the triage and analysis of security events, monitoring, and threat and attack detection using tools such as SIEM

• Bradesco Top Nacional health insurance
• Odontoprev dental insurance
• Life insurance
• Pipo Saúde: Digital healthcare and corporate benefits brokerage
• TotalPass
• Transportation allowance
• Alelo Tudo: Meal and food benefits on a single card
• Private pension plan with double employer matching
• Birthday day off
• Employee referral program
• Discounts at educational institutions
• Vision Baby Kit
• Exclusive discounts through the SESC group
• Welcome kit
• Morning and afternoon coffee with fresh fruit on in-office days
• DeepLearning: Our corporate university
• Professional growth opportunities
• Feedback and development culture
• Exclusive leadership program
• Relaxed environment driven by innovation
• Accessible leadership