Security Engineer - Incident Response

CloudWalk, Inc.

São Paulo

Presencial

BRL 180 000 - 240 000

Tempo integral

Há 9 dias

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

CloudWalk, a forward-thinking fintech security team, seeks a skilled security engineer to design and evolve our SIEM, telemetry pipelines, and detection capabilities. You will investigate incidents end-to-end, hunt proactively for gaps, and automate triage and response workflows to strengthen our defenses.

Ideal candidates will have hands-on experience with SIEMs, cloud security, and programming in Python/Go/TS, plus a penchant for turning attacker insights into robust detections.

Qualificações

  • > Strong understanding of detection engineering, incident response and attacker behavior.
  • - Experience investigating security events across multiple sources of telemetry.
  • - Experience with SIEMs, logging platforms or large-scale security data.
  • - Good understanding of cloud environments, IAM, Kubernetes and modern infrastructure.
  • - You code. Python, Go, Typescript or something similar.
  • - Ability to distinguish a real attack from noisy telemetry without losing your sanity.
  • - Clear communication during incidents, especially when information is incomplete and the stakes are high.

Responsabilidades

  • Build our security nervous system. Own and improve the SIEM, telemetry pipelines, enrichment and correlation across CloudWalk.
  • Create detections that matter. Turn attacker behavior, real incidents and Red Team findings into useful signals instead of alert spam.
  • Respond when things get weird. Investigate incidents from first signal to containment, recovery and lessons learned.
  • Hunt before alerts fire. Search proactively for suspicious behavior and visibility gaps.
  • Automate aggressively. Build tools and workflows for triage, enrichment, evidence collection and containment.
  • Work with attackers. The friendly kind. Partner closely with Offensive Security to turn attack paths into detections and controls.
  • Use AI as leverage. Build agents and automations for investigation, log analysis, alert enrichment and response.

Conhecimentos

Detection engineering
Incident response
Attacker behavior
SIEM / logging platforms
Cloud environments / IAM / Kubernetes
Programming (Python / Go / TS)
Incident communication

Ferramentas

Splunk
Elastic/OpenSearch
Datadog
Sigma/YARA/osquery

Descrição da oferta de emprego

We are not just another fintech unicorn. We are a pack of dreamers, builders, and tech enthusiasts shaping the future of payments.

Security here moves at the same speed as engineering.

This is not a traditional SOC role. You won't spend your day staring at dashboards and closing noisy alerts. You'll build the systems that tell us when something is wrong, investigate when it is, and make sure we come back stronger after every incident.

You'll own and evolve our SIEM, connect signals across cloud, endpoints, identities and applications, and help turn offensive security knowledge into real detection and response capabilities.

What You’ll Do
  • Build our security nervous system. Own and improve the SIEM, telemetry pipelines, enrichment and correlation across CloudWalk.
  • Create detections that matter. Turn attacker behavior, real incidents and Red Team findings into useful signals instead of alert spam.
  • Respond when things get weird. Investigate incidents from first signal to containment, recovery and lessons learned.
  • Hunt before alerts fire. Search proactively for suspicious behavior and visibility gaps.
  • Automate aggressively. Build tools and workflows for triage, enrichment, evidence collection and containment.
  • Work with attackers. The friendly kind. Partner closely with Offensive Security to turn attack paths into detections and controls.
  • Use AI as leverage. Build agents and automations for investigation, log analysis, alert enrichment and response.
What You Need to Succeed
  • Strong understanding of detection engineering, incident response and attacker behavior.
  • Experience investigating security events across multiple sources of telemetry.
  • Experience with SIEMs, logging platforms or large-scale security data.
  • Good understanding of cloud environments, IAM, Kubernetes and modern infrastructure.
  • Ability to investigate authentication, endpoint, network, application and cloud activity.
  • You code. Python, Go, Typescript or something similar. We want engineers, not dashboard operators.
  • Ability to distinguish a real attack from noisy telemetry without losing your sanity.
  • Clear communication during incidents, especially when information is incomplete and the stakes are high.
Nice to Have
  • Experience with BigQuery, Chronicle, Splunk, Elastic/OpenSearch, Datadog, Sentinel or similar platforms.
  • Detection-as-code, Sigma, YARA, osquery or Suricata.
  • EDR, threat hunting or digital forensics experience.
  • Experience automating incident response or building internal security tooling.
  • Offensive security knowledge, including C2, persistence, privilege escalation and lateral movement.
  • Experience with payment systems or PCI DSS.
  • Experience applying LLMs or AI agents to security operations.
  • Security research, open source contributions or CTF experience.
The Future We See:

At CloudWalk, we envision a future where AI empowers every field to reach new heights:

  • People teams leveraging AI to transform talent acquisition and employee development.
  • Marketing professionals creating data-driven, AI-powered campaign strategies.
  • Customer Success teams enhancing client experiences with intelligent solutions.
  • Risk analysts combining human expertise with AI to navigate complexities.
  • Designers collaborating with AI to push creative boundaries.

Join us at CloudWalk, where we're not just engineering solutions; we're building a smarter, AI-driven future for payments—together.

By applying for this position, your data will be processed as per CloudWalk's Privacy Policy that you can read here in Portuguese and here in English.

We use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, assessing responses, and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Security Engineer
Security Engineer

CloudWalk, Inc. • São Paulo

Presencial
BRL 120 000 - 210 000
Insider Risk Security Engineer
Insider Risk Security Engineer

CloudWalk, Inc. • São Paulo

Presencial
BRL 300 000 - 420 000
AML-CTF Analyst — U.S. Operations
AML-CTF Analyst — U.S. Operations

CloudWalk, Inc. • São Paulo

Presencial
BRL 458 481 - 662 251
AI GTM Engineer
AI GTM Engineer

CloudWalk, Inc. • São Paulo

Presencial
BRL 250 000 - 420 000
AI-Native Growth & Builder
AI-Native Growth & Builder

CloudWalk, Inc. • São Paulo

Presencial
BRL 250 000 - 480 000
Data Analyst
Data Analyst

Cloudwalk • São Paulo

Presencial
BRL 75 000 - 95 000
Public Policy & Government Affairs — Brasília Presence
Public Policy & Government Affairs — Brasília Presence

CloudWalk, Inc. • Brasília

Presencial
BRL 300 000 - 550 000
Cyber Security Engineer
Cyber Security Engineer

Mercado Livre Brasil • Osasco

Híbrido
BRL 180 000 - 240 000
Backoffice Analyst
Backoffice Analyst

CloudWalk, Inc. • São Paulo

Presencial
BRL 60 000 - 90 000
Brand Designer — Landing Pages
Brand Designer — Landing Pages

CloudWalk, Inc. • São Paulo

Presencial
BRL 60 000 - 100 000