Insider Risk Security Engineer

CloudWalk, Inc.

São Paulo

Presencial

BRL 180 000 - 260 000

Tempo integral

Há 8 dias
Gerador de candidaturas

Transforma esta função numa entrevista — um currículo e uma carta de apresentação criados à volta do que este empregador procura.

Ultrapassa os filtros ATS

Resumo da oferta

CloudWalk, Inc. is seeking a security-minded engineer to build and tune detections across Chronicle, Wiz, and SentinelOne, and to own the insider-risk investigation lifecycle from detection to remediation.

You will analyze logs, reconstruct user timelines, and reduce alert noise while crafting automated triage workflows in TypeScript. The role emphasizes building LLM-powered agents to accelerate investigations, integrating insider-risk tools with SIEM and SOAR, and collaborating with Legal and

Qualificações

  • Experience designing, implementing, and tuning detection rules across security tools.
  • Ability to investigate insider-risk alerts and reconstruct user timelines across systems.
  • Experience reducing alert noise and false positives.
  • Ability to automate repetitive triage tasks with code.
  • Experience building AI-powered investigation workflows.

Responsabilidades

  • Design, implement, and fine-tune detection rules across Chronicle (YARA-L), Wiz, and SentinelOne, plus DLP/UEBA surfaces.
  • Act as the primary investigator for insider risk alerts; analyze logs and reconstruct timelines to explain what happened and what to do.
  • Continuously tune alerts to reduce false positives and maintain signal quality.
  • Write TypeScript code to automate repetitive triage tasks and integrate tools with SIEM/SOAR.
  • Build and tune LLM-powered agents to automate investigations and enrich context across platforms.
  • Partner with Legal, People, and other Security teams to conduct forensic investigations and remediation.
  • Proactively hunt for undetected anomalous behavior and risky data handling across endpoints and cloud.

Conhecimentos

TypeScript
Security analytics
LLM/AI tooling
Incident response

Ferramentas

Chronicle (YARA-L)
Wiz
SentinelOne
SIEM
SOAR

Descrição da oferta de emprego

About This Role
  • Build & Tune Detections: Design, implement, and fine-tune rules across Chronicle (YARA-L), Wiz, and SentinelOne, plus our DLP and UEBA surfaces. Move beyond out-of-the-box alerts, actively cut false positives, and own the detection lifecycle from rule creation to retirement.
  • Investigate & Triage: Act as the primary technical investigator for insider risk alerts. Analyze logs, reconstruct user timelines across our entire stack, and determine what happened, why, and what to do about it including intent behind data movement.
  • Reduce the Noise: Continuously tune alerts and detection logic to drive down false positives and keep the signal high.
  • Automate Workflows: Write code (TypeScript) to automate repetitive triage tasks and integrate our insider risk tools with our SIEM and SOAR platforms. If you repeat a triage step twice, automate it.
  • Weaponize AI for Investigations: Build and tune LLM-powered agents that triage alerts, enrich them with cross-platform context, and reconstruct investigation timelines automatically. Turn repetitive forensic work into autonomous workflows.
  • Cross-Functional Operations: Partner directly with Legal, People, and other Security teams to safely and discreetly conduct forensic investigations and coordinate remediation efforts.
  • Threat Hunting: Proactively hunt for undetected anomalous behavior, unauthorized shadow IT usage, or risky data handling practices across endpoints and cloud environments.
  • Build & Tune Detections: Design, implement, and fine-tune rules across Chronicle (YARA-L), Wiz, and SentinelOne, plus our DLP and UEBA surfaces. Move beyond out-of-the-box alerts, actively cut false positives, and own the detection lifecycle from rule creation to retirement.
  • Investigate & Triage: Act as the primary technical investigator for insider risk alerts. Analyze logs, reconstruct user timelines across our entire stack, and determine what happened, why, and what to do about it including intent behind data movement.
  • Reduce the Noise: Continuously tune alerts and detection logic to drive down false positives and keep the signal high.
  • Automate Workflows: Write code (TypeScript) to automate repetitive triage tasks and integrate our insider risk tools with our SIEM and SOAR platforms. If you repeat a triage step twice, automate it.
  • Weaponize AI for Investigations: Build and tune LLM-powered agents that triage alerts, enrich them with cross-platform context, and reconstruct investigation timelines automatically. Turn repetitive forensic work into autonomous workflows.
  • Cross-Functional Operations: Partner directly with Legal, People, and other Security teams to safely and discreetly conduct forensic investigations and coordinate remediation efforts.
  • Threat Hunting: Proactively hunt for undetected anomalous behavior, unauthorized shadow IT usage, or risky data handling practices across endpoints and cloud environments.
The Future We See

At CloudWalk, we envision a future where AI empowers every field to reach new heights:

  • People teams leveraging AI to transform talent acquisition and employee development.
  • Marketing professionals creating data-driven, AI-powered campaign strategies.
  • Customer Success teams enhancing client experiences with intelligent solutions.
  • Risk analysts combining human expertise with AI to navigate complexities.
  • Designers collaborating with AI to push creative boundaries.

Join us at CloudWalk, where we're not just engineering solutions; we're building a smarter, AI-driven future for payments together.

By applying for this position, your data will be processed as per CloudWalk's Privacy Policy.

Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Security Engineer
Security Engineer

CloudWalk, Inc. • São Paulo

Presencial
BRL 120 000 - 180 000
Offensive Security Engineer
Offensive Security Engineer

CloudWalk, Inc. • São Paulo

Presencial
BRL 180 000 - 300 000
AML-CTF Analyst — U.S. Operations
AML-CTF Analyst — U.S. Operations

CloudWalk, Inc. • São Paulo

Presencial
BRL 180 000 - 300 000
Senior Engineer - Platform/Devops
Senior Engineer - Platform/Devops

CloudWalk, Inc. • São Paulo

Presencial
BRL 180 000 - 260 000
Security Engineer - Incident Response
Security Engineer - Incident Response

CloudWalk, Inc. • São Paulo

Híbrido
BRL 150 000 - 190 000
Privacy Analyst
Privacy Analyst

CloudWalk, Inc. • São Paulo

Híbrido
BRL 90 000 - 130 000
Head of Communications
Head of Communications

CloudWalk, Inc. • São Paulo

Presencial
BRL 280 000 - 560 000
Staff Engineer – Issuing
Staff Engineer – Issuing

CloudWalk, Inc. • São Paulo

Presencial
BRL 180 000 - 260 000
Backend Engineer Authentication
Backend Engineer Authentication

CloudWalk, Inc. • São Paulo

Presencial
BRL 250 000 - 400 000
Treasury Analyst - ALM, Funding and Modeling
Treasury Analyst - ALM, Funding and Modeling

CloudWalk, Inc. • São Paulo

Presencial
BRL 180 000 - 280 000