JSOC - Cybersecurity Specialist - Incident Response

Questrade Financial Group

Brasil

Híbrido

BRL 120 000 - 240 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Health & wellbeing resources
Paid vacation and sick days
Competitive compensation
Career growth opportunities
Community involvement
Diversity & inclusive environment

Resumo da oferta

Questrade Financial Group in Brazil is seeking a skilled SOC Specialist to defend our infrastructure and data. You will lead incident response, threat hunting, and detection rule tuning in a fast-paced security operations center environment.

You will collaborate with cyber, IT, and vendor teams, leverage CrowdStrike Falcon and Elastic Security, and contribute to playbooks, tabletop exercises and post‑incident reviews, while staying current with industry frameworks and threats.

Qualificações

  • 3+ years of cybersecurity incident response and threat hunting in a SOC environment.
  • Experience in creating and tuning detection rules.
  • Experience integrating security tools via APIs and familiarity with SOAR concepts.
  • Experience with investigations using CrowdStrike Falcon and Elastic Security.
  • Forensic triage across Mac, Linux, and Windows; familiarity with multiple operating systems.
  • Contributing to SOC processes, playbooks, SIEM rules, and incident reports.
  • Knowledge of NIST Cybersecurity Framework and MITRE ATT&CK.

Responsabilidades

  • Collaborate with team members on investigations and share technical knowledge.
  • Monitor, analyze and report possible cybersecurity attacks.
  • Investigate and analyze threat indicators.
  • Gather indicators of compromise for threat hunting activities.
  • Leverage security tools to identify malicious activities.
  • Analyze malicious activity to determine TTPs.
  • Correlate data to determine incident impact.
  • Execute containment and eradication following playbooks.
  • Participate in on-call rotations and IR simulations.
  • Coordinate incident response with internal teams and third parties.
  • Document timelines, evidence and actions for post‑incident review.
  • Produce lessons‑learned reports and improve playbooks.
  • Maintain up-to-date understanding of threats and security frameworks.
  • Communicate findings to stakeholders and track SOC metrics.

Conhecimentos

Incident Response
Threat Hunting
EDR Tools
SIEM
CrowdStrike
Elastic Security
Python
JavaScript
SOAR
NIST
MITRE ATT&CK

Ferramentas

CrowdStrike Falcon
Elastic Security

Descrição da oferta de emprego

Questrade Financial Group (QFG), through its companies - Questrade, Inc., Questrade Wealth Management Inc., Community Trust Company, Zolo, and Flexiti Financial Inc., provides securities and foreign currency investment, professionally managed investment portfolios, mortgages, real estate services, financial services and more. Questrade uses cutting-edge technologies to develop innovative products that give customers better, more affordable ways to take control of their money.

We are everything a traditional financial institution is not. At QFG, you will be constantly moving forward, bringing the future of fintech into existence. You will be a part of a collaborative team that cares deeply about our mission and each other. Your team members will help you conquer challenges, push boundaries and discover what you are truly capable of.

At QFG, we have a culture of innovation where technology serves people—both our team and our customers. We see AI as a collaborative and transformative enabler, and we are seeking forward-thinking individuals who can effectively integrate it into their daily work. The ideal candidate will be a catalyst for change, helping us use AI to create a more efficient and rewarding employee experience while also developing cutting‑edge solutions that delight and serve our customers. Join us in shaping a future where AI empowers our team to do their best work and helps us deliver unparalleled customer experiences.

This is a place where you can explore, discover and learn with continuous growth. As a diverse and inclusive place to work, with a hybrid working environment you can unleash your creativity and curiosity with no limits. If you share the same sense of infinite possibility, come shape your future at QFG.

What’s in it for you as an employee of QFG?
  • Health & wellbeing resources and programs
  • Paid vacation, personal, and sick days for work‑life balance
  • Competitive compensation and benefits packages
  • Career growth and development opportunities
  • Opportunities to contribute to community causes
  • Work with diverse team members in an inclusive and collaborative environment
We’re looking for our next SOC Specialist. Could It Be You?

Your contribution delivering sustainable and measurable results in the following areas will be very important:

Identifying and responding to cyber threats - safeguarding our company's infrastructure and data. You will be primarily involved in supporting the alert development cycle, triaging and investigating alerts, managing the full incident response lifecycle (investigation, containment, eradication, and recovery) and collecting and tracking metrics for reporting. You will be working alongside internal customers and our vendor support teams to ensure we are utilizing our security tools in accordance with corporate policies and growing business needs. You will work closely with Cybersecurity and IT teams to align priorities and execute plans for new initiatives, as well as contribute to process improvements and build documentation for new tools.

Need more details? Keep reading…

You will:
  • Collaborate with team members on investigations and share technical knowledge.
  • Monitor, analyze and report possible cybersecurity attacks.
  • Investigate and perform analysis of threat indicators.
  • Gather Indicators of compromise and any relevant data to use with threat hunting activities.
  • Leverage security tools (Elastic, CrowdStrike and more) for analysis to identify malicious activities.
  • Analyze identified malicious activity to determine Tactics, Techniques and Procedures.
  • Conduct research, analysis and correlate gathered data from various resources to determine the impact of the incident.
  • Execute containment and eradication actions following established playbooks.
  • Participate in on‑call and hands‑on scheduled shift rotations, including outside of business hours.
  • Support coordination of Security Incident Response and investigation with other internal teams and 3rd party providers.
  • Document incident timelines, evidence, and actions taken for post‑incident review.
  • Perform post‑incident reviews and produce lessons‑learned reports.
  • Contribute to maintaining and improving incident response playbooks and runbooks.
  • Participate in tabletop exercises and IR simulations.
  • Provide proactive security investigation and searches on corporate environments to detect malicious activities.
  • Maintain up‑to‑date understanding of security threats, countermeasures, security tools, cloud security and SaaS technologies.
  • Maintain technical proficiency through training, keeping up with industry best practices, and security frameworks.
  • Communicate investigation findings to technical stakeholders and contribute to reporting.
  • Contribute to tracking SOC operational metrics (MTTD, MTTR, alert fidelity).
So are YOU our next SOC Specialist? You are if you have…
  • 3+ years of relevant experience in performing Cybersecurity Incident Response and Threat Hunting activities in a complex incident management or Security Operations Center environment.
  • Experience in the creation and fine‑tuning of detection rules.
  • Familiarity with integrating security tools via APIs for automation, and familiarity with Security Orchestration, Automation, and Response (SOAR) concepts.
  • Experience with investigations and incident response using EDR tools such as CrowdStrike Falcon and SIEM tools such as Elastic Security (KQL, ESQL, Timeline analysis).
  • Experience with forensic triage (disk, memory, network) and multiple operating systems (Mac, Linux, Windows).
  • Experience with contributing to SOC processes, playbooks, SIEM correlation rules, and incident reports.
  • Experience in incident management and communication under pressure.
  • Familiarity with programming languages such as Python, JavaScript and others.
  • Knowledge of NIST Cybersecurity Framework, MITRE ATT&CK.
  • Knowledge of security products and device monitoring tools including Firewalls, IDS/IPS, Phishing and e‑mail security, content filtering, DDoS, WAF, and more.
Brownie points if you have…

GSEC, Security+, CySA+, CEH, CHFI or similar relevant certifications.

At Questrade Financial Group of Companies, with multiple office locations around the world, we are committed to fostering a diverse, inclusive and accessible work environment. This is an environment where individuals are treated with dignity and respect. Here, the unique skills and experience you bring will be valued. You will be supported and motivated, so that you can harness your unlimited potential. Our team reflects the diversity of the communities we serve and operate in. Having a collaborative and diverse team helps us push boundaries to bring the future of fintech into existence—not only for the benefit of our customers, but for those who build their career with us.

Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment/selection process, please let us know and we will work with you to meet your needs.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Cyber Security Analyst
Cyber Security Analyst

Orange Business • São Paulo

Presencial
Medical plan
Dental plan
Life insurance
+6
Specialist, NG Identity Security (Remote, BRA)
Specialist, NG Identity Security (Remote, BRA)

CrowdStrike • São Paulo

Presencial
BRL 180 000 - 300 000
Market-leading compensation
Wellness programs
Vacation and holidays
+3
Cyber Security Analyst
Cyber Security Analyst

Orange Business • Nova Petrópolis

Presencial
BRL 60 000 - 80 000
Medical plan
Dental plan
Life insurance
+4
Cyber Security Specialist
Cyber Security Specialist

Jobtailor • Belo Horizonte

Presencial
BRL 110 000 - 170 000
Senior Security Engineer, Enterprise Security
Senior Security Engineer, Enterprise Security

United States Digital Space LLC • São Paulo

Híbrido
BRL 180 000 - 300 000
Competitive compensation incl. equity
Retirement and ESPP
Flexible paid time off
+6
Technical Support Engineer - Cloud (Remote, BRA)
Technical Support Engineer - Cloud (Remote, BRA)

CrowdStrike • São Paulo

Presencial
BRL 120 000 - 180 000
Market leading compensation
Wellness programs
Generous vacation
+5
Customer Success Manager Brazil
Customer Success Manager Brazil

Embedded Shishya • São Paulo

Presencial
BRL 120 000 - 180 000
Security Engineer - Incident Response
Security Engineer - Incident Response

CloudWalk, Inc. • São Paulo

Presencial
BRL 180 000 - 240 000
Security Triage & Remediation Lead, Brazil
Security Triage & Remediation Lead, Brazil

CI&T • Brasil

Presencial
BRL 180 000 - 300 000
Health and dental insurance
Meal allowance
Extended paternity leave
+9
[Job - 31023] Security Triage & Remediation Lead, Brazil
[Job - 31023] Security Triage & Remediation Lead, Brazil

CI&T • Brasil

Presencial
BRL 260 000 - 520 000
Health and dental insurance
Meal allowance
Childcare assistance
+2