Insider Risk Security Engineer

CloudWalk, Inc.

São Paulo

Presencial

BRL 300 000 - 420 000

Tempo integral

Há 3 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

CloudWalk, Inc. is seeking an Insider Risk Security Engineer to build and operate our insider threat program. You will analyze user behavior across our stack, tune detection engines, and automate triage to make investigations faster and deeper.

The role bridges security operations, detection engineering, and automation, partnering with Legal, People, and IT to protect data from exfiltration. You will write TypeScript tools, craft YARA-L rules, and pursue proactive threat hunting across cloud and

Qualificações

  • Hands-on SOC experience required.
  • Strong investigative and analytical mindset.
  • Ability to query logs and write detection rules.
  • Familiar with cloud security and data loss prevention.
  • Proficient in TypeScript and scripting.
  • Discretion and ethical handling of sensitive data.
  • Excellent communication with non-technical stakeholders.

Responsabilidades

  • Build, tune detections across Chronicle, Wiz, and SentinelOne.
  • Investigate insider risk alerts and reconstruct user timelines.
  • Tune alerts to reduce false positives.
  • Automate triage tasks with TypeScript.
  • Develop LLM-powered agents for investigations.
  • Collaborate with Legal, People, and Security teams.
  • Hunt for anomalous behavior across endpoints and cloud.

Conhecimentos

SOC experience
Insider threat
Analytical mindset
Forensic investigation
Detection rule writing
Incident response
Communication
Privacy compliance

Ferramentas

TypeScript
Python
Bash
Google Workspace Admin SDK
Chronicle (YARA-L)
Wiz
SentinelOne
JumpCloud
Tailscale
GCP IAM
DLP/UEBA tools
Splunk
SIEM

Descrição da oferta de emprego

At CloudWalk, we are building the future of payments with security at the core of every decision. We are hiring a hands-on Insider Risk Security Engineer to build, tune, and operate our insider threat program. This is not a ticket-triage or compliance-report role. You will be in the trenches analyzing user behaviour, tuning detection engines, reconstructing timelines across our entire stack, and writing the automation that makes investigations faster, deeper, and more consistent.

You will act as the technical engine of our team, bridging security operations, detection engineering, and automation - while partnering discreetly with Legal, People, and IT to protect our most critical data from accidental exposure and malicious exfiltration. One day you are reconstructing a user timeline across five platforms to determine if a data exfiltration happened. Next, you are writing a detection rule in YARA-L to catch that class of behavior going forward, or shipping a tool that automates the triage you just did manually.

What You'll Do
  • Build & Tune Detections: Design, implement, and fine-tune rules across Chronicle (YARA-L), Wiz, and SentinelOne, plus our DLP and UEBA surfaces. Move beyond out-of-the-box alerts, actively cut false positives, and own the detection lifecycle from rule creation to retirement.
  • Investigate & Triage: Act as the primary technical investigator for insider risk alerts. Analyze logs, reconstruct user timelines across our entire stack, and determine what happened, why, and what to do about it - including intent behind data movement.
  • Reduce the Noise: Continuously tune alerts and detection logic to drive down false positives and keep the signal high.
  • Automate Workflows: Write code (TypeScript) to automate repetitive triage tasks and integrate our insider risk tools with our SIEM and SOAR platforms. If you repeat a triage step twice, automate it.
  • Weaponize AI for Investigations: Build and tune LLM-powered agents that triage alerts, enrich them with cross-platform context, and reconstruct investigation timelines automatically. Turn repetitive forensic work into autonomous workflows.
  • Cross-functional Operations: Partner directly with Legal, People, and other Security teams to safely and discreetly conduct forensic investigations and coordinate remediation efforts.
  • Threat Hunting: Proactively hunt for undetected anomalous behavior, unauthorized shadow IT usage, or risky data handling practices across endpoints and cloud environments.
What You Need to Succeed
  • Hands-on Experience in a Security Operations Center (SOC), Cyber Threat Intelligence, Incident Response, Security Engineering, or dedicated Insider Threat role.
  • Investigative & Analytical Mindset: You know how to differentiate between a malicious data exfiltration event and an engineer who just doesn't understand the company's cloud storage policy.
  • Technical Chops: Deep, practical experience querying raw logs, writing detection rules, and understanding the data pipeline behind them - you don't just read dashboards, you go to the source.
  • Stack Familiarity (or ability to ramp fast): Google Workspace (Admin SDK, Reports API), Chronicle / Google SecOps (UDM Search, YARA-L), Wiz, SentinelOne (Deep Visibility), Jumpcloud, Tailscale, GCP Audit Logs and IAM. DLP/UEBA tools (e.g., Microsoft Purview, Proofpoint, Forcepoint, Varonis, Exabeam) and SIEM platforms (e.g., Splunk, Sentinel, CrowdStrike LogScale).
  • Scripting Skills: Proficiency in TypeScript (Python/bash a plus). You write tools and services others can rely on, not just one-off scripts.
  • Discretion & Ethics: Unwavering integrity and the ability to handle highly sensitive, confidential personnel investigations with strict adherence to privacy laws and company guidelines.
  • Communication: The ability to translate complex technical forensic findings into clear, non-technical summaries for People and Legal teams.
Nice to Have
  • Experience with insider threat detection, User and Entity Behavior Analytics, or building insider risk workflows.
  • Familiarity with fintech / payment industry security (PCI DSS, card data, Pix, acquiring flows).
  • Experience with LLM-powered security agents or AI-driven detection / triage automation.
  • Kubernetes / Istio service mesh context.
The Future We See:

At CloudWalk, we envision a future where AI empowers every field to reach new heights:

  • People teams leveraging AI to transform talent acquisition and employee development.
  • Marketing professionals creating data-driven, AI-powered campaign strategies.
  • Customer Success teams enhancing client experiences with intelligent solutions.
  • Risk analysts combining human expertise with AI to navigate complexities.
  • Designers collaborating with AI to push creative boundaries.

Join us at CloudWalk, where we're not just engineering solutions; we're building a smarter, AI-driven future for payments- together.

By applying for this position, your data will be processed as per CloudWalk's Privacy Policy.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Security Engineer - Incident Response
Security Engineer - Incident Response

CloudWalk, Inc. • São Paulo

Presencial
BRL 180 000 - 240 000
Security Engineer
Security Engineer

CloudWalk, Inc. • São Paulo

Presencial
BRL 120 000 - 210 000
Data Analyst
Data Analyst

Cloudwalk • São Paulo

Presencial
BRL 75 000 - 95 000
AML-CTF Analyst — U.S. Operations
AML-CTF Analyst — U.S. Operations

CloudWalk, Inc. • São Paulo

Presencial
BRL 458 481 - 662 251
Backoffice Analyst
Backoffice Analyst

CloudWalk, Inc. • São Paulo

Presencial
BRL 60 000 - 90 000
AI-Native Growth & Builder
AI-Native Growth & Builder

CloudWalk, Inc. • São Paulo

Presencial
BRL 250 000 - 480 000
Cyber Security Analyst - Americas
Cyber Security Analyst - Americas

Intuition Machines • Brasil

Teletrabalho
Fully remote position
Flexible working hours
Modern development workflows
Senior Engineer - Platform/Devops
Senior Engineer - Platform/Devops

CloudWalk • São Paulo

Presencial
FinCrime Investigator - AML Investigations (Exclusive for PwD)
FinCrime Investigator - AML Investigations (Exclusive for PwD)

Wise • São Paulo

Presencial
BRL 120 000 - 180 000
AI Cybersecurity Analyst — Junior
AI Cybersecurity Analyst — Junior

Flintworks • Brasil

Presencial
BRL 147 000 - 246 000
Competitive compensation package
Certification sponsorship (CompTIA, AWS, Cisco)