Senior Information Security Analyst – SOC, Blue Team

Jobtailor

Brasil

Presencial

BRL 220 000 - 340 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Jobtailor in São Paulo (Pinheiros) seeks a Senior SOC Analyst to lead 24/7 monitoring and incident response within the CDOC. Hybrid work: on-site twice a week, with a focus on advancing security posture.

The role emphasizes complex incident handling, playbook automation, and CTI/IoC integration to improve detection and response across environments.

Qualificações

  • Bachelor's degree in a relevant field.
  • Hands-on SOC/CSIRT experience in large-scale environments.
  • Strong proficiency with SIEM/XSIAM and EDR/XDR tools.

Responsabilidades

  • Analyze and respond to security incidents/alerts (Level 3) and guide improvements.
  • Calibrate and evolve SIEM/XDR rules to reduce false positives.
  • Conduct proactive threat hunting to identify hidden threats.
  • Support N1/N2 teams in complex case development and resolution.
  • Develop and automate incident response playbooks using SOAR.
  • Apply IoCs and CTI reports to monitoring systems.

Conhecimentos

MITRE ATT&CK
Python
PowerShell
KQL
SQL
Analytical thinking
Technical leadership

Formação académica

Bachelor’s degree in Computer Science, Engineering, Information Security or related fields

Ferramentas

Palo Alto XSIAM
Cortex XDR
Cortex Cloud
Wireshark
SIEM / XDR
Firewalls
WAF
Proxies

Descrição da oferta de emprego

Senior SOC Analyst - Cyber Defense & Operations Center (CDOC)

Location: Pinheiros, São Paulo (hybrid model: on-site 2 times per week)

Hours: 8:00–18:00 Monday–Thursday, 8:00–17:00 Friday

We are looking for a Senior SOC Analyst to join our Cyber Defense and Operations Center (CDOC). This is a technical role in which you will provide technical leadership for 24/7 monitoring, response to complex incidents, and the advancement of our security posture.

Key Responsibilities
  • Advanced Detection and Response: Analyze and assist with response to security incidents/alerts (Level 3). Provide guidance to our contracted SOC partner on improvements and lessons learned. Ability to analyze across all environment tools (EDR, AV, antispam, password vault, DNS (e.g., Cisco Umbrella), DLP, WAF, IPS, etc.).
  • Detection Engineering: Support the creation, calibration and evolution of event correlation rules, alerts and use cases within our SIEM/XDR to reduce false positives and increase threat visibility.
  • Threat Hunting: Conduct continuous proactive searches across the environment to identify anomalous behaviors and hidden threats that bypassed traditional controls.
  • SOC Service Quality Assessment: Support and guide N1/N2 analyst teams in technical development and resolution of complex cases.
  • Playbooks and Automation (SOAR): Assist in developing, reviewing and automating incident response playbooks using SOAR tools to optimize mean time to respond (MTTR).
  • Threat Intelligence: Consume and apply indicators of compromise (IoCs) and Cyber Threat Intelligence (CTI) reports into monitoring systems.
Requirements
  • Bachelor’s degree in Computer Science, Engineering, Information Security or related fields.
  • Proven experience working in large-scale SOC/CSIRT environments.
  • Advanced proficiency with SIEM solutions (Palo Alto XSIAM).
  • Strong hands‑on experience with Palo Alto EDR/XDR solutions (e.g., Cortex XDR, Cortex Cloud).
  • Mastery of the MITRE ATT&CK framework and practical application for mapping adversary tactics and techniques.
  • Experience analyzing network traffic (Wireshark), operating system logs (Windows/Linux), firewalls, WAF and proxies.
  • Knowledge of query/scripting languages (e.g., Python, PowerShell, KQL or SQL) for automation and data analysis.
Desired/Preferred Qualifications (Differentials)
  • Knowledge of cloud security and monitoring (AWS, Azure or GCP).
  • Familiarity or experience with API security (e.g., tools such as Akamai API Security/Noname).
  • Recognized industry certifications such as CompTIA CySA+, CASP+, GIAC (GCIH, GCIA, GCDA), CEH, Microsoft SC-200, SC-300.
Diversity Statement

Diversity matters to us. We promote dignity and respect for everyone so people feel safe to be themselves. Our opportunities are open to all who value an environment free from prejudice, harassment and discrimination.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Analista de Segurança Pleno (SOC)
Analista de Segurança Pleno (SOC)

Ibrowse • São Paulo

Presencial
Analista de Segurança da Informação - SOC (Blue Team)
Analista de Segurança da Informação - SOC (Blue Team)

Secureway Tecnologia • Cerqueira César

Híbrido
BRL 90 000 - 150 000
Contrato PJ
Modalidade híbrida
Oportunidade de certificações
Analista de Segurança da Informação - SOC (Blue Team)
Analista de Segurança da Informação - SOC (Blue Team)

Secureway Tecnologia • São Paulo

Híbrido
BRL 78 000 - 123 000
Tech Lead – Cyber Security
Tech Lead – Cyber Security

Jobtailor • Belo Horizonte

Presencial
BRL 180 000 - 240 000
Cyber Security Engineer - São Paulo
Cyber Security Engineer - São Paulo

Yeah! Global • São Paulo

Presencial
Analista de Segurança da Informação Sênior
Analista de Segurança da Informação Sênior

Solor • Rio de Janeiro

Presencial
BRL 201 000 - 312 000
Vale Refeição/Alimentação
Plano de saúde
Plano odontológico
+2
Sr. Analyst, Cybersecurity Operations
Sr. Analyst, Cybersecurity Operations

AGCO Corporation • Jundiaí

Presencial
BRL 301 000 - 403 000
Medical and dental assistance
Private pension
Meal and food vouchers
+4
Director, Information Security
Director, Information Security

Jobgether • Brasil

Presencial
BRL 1 089 000 - 1 348 000
Competitive salary
Full-time leadership role
Enterprise-wide impact
+1
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Michael Page International do Brasil Recrutamento Especializado Ltda • Curitiba

Híbrido
BRL 120 000 - 160 000
Modelo de trabalho híbrido
Benefícios competitivos e estrutura de bônus
Desenvolvimento de carreira
Consultor de Segurança da Informação - Banco de Talentos (SOC)
Consultor de Segurança da Informação - Banco de Talentos (SOC)

OPLIUM • São Paulo

Presencial