Senior SOC Analyst - Cyber Defense & Operations Center (CDOC)
Location: Pinheiros, São Paulo (hybrid model: on-site 2 times per week)
Hours: 8:00–18:00 Monday–Thursday, 8:00–17:00 Friday
We are looking for a Senior SOC Analyst to join our Cyber Defense and Operations Center (CDOC). This is a technical role in which you will provide technical leadership for 24/7 monitoring, response to complex incidents, and the advancement of our security posture.
Key Responsibilities
- Advanced Detection and Response: Analyze and assist with response to security incidents/alerts (Level 3). Provide guidance to our contracted SOC partner on improvements and lessons learned. Ability to analyze across all environment tools (EDR, AV, antispam, password vault, DNS (e.g., Cisco Umbrella), DLP, WAF, IPS, etc.).
- Detection Engineering: Support the creation, calibration and evolution of event correlation rules, alerts and use cases within our SIEM/XDR to reduce false positives and increase threat visibility.
- Threat Hunting: Conduct continuous proactive searches across the environment to identify anomalous behaviors and hidden threats that bypassed traditional controls.
- SOC Service Quality Assessment: Support and guide N1/N2 analyst teams in technical development and resolution of complex cases.
- Playbooks and Automation (SOAR): Assist in developing, reviewing and automating incident response playbooks using SOAR tools to optimize mean time to respond (MTTR).
- Threat Intelligence: Consume and apply indicators of compromise (IoCs) and Cyber Threat Intelligence (CTI) reports into monitoring systems.
Requirements
- Bachelor’s degree in Computer Science, Engineering, Information Security or related fields.
- Proven experience working in large-scale SOC/CSIRT environments.
- Advanced proficiency with SIEM solutions (Palo Alto XSIAM).
- Strong hands‑on experience with Palo Alto EDR/XDR solutions (e.g., Cortex XDR, Cortex Cloud).
- Mastery of the MITRE ATT&CK framework and practical application for mapping adversary tactics and techniques.
- Experience analyzing network traffic (Wireshark), operating system logs (Windows/Linux), firewalls, WAF and proxies.
- Knowledge of query/scripting languages (e.g., Python, PowerShell, KQL or SQL) for automation and data analysis.
Desired/Preferred Qualifications (Differentials)
- Knowledge of cloud security and monitoring (AWS, Azure or GCP).
- Familiarity or experience with API security (e.g., tools such as Akamai API Security/Noname).
- Recognized industry certifications such as CompTIA CySA+, CASP+, GIAC (GCIH, GCIA, GCDA), CEH, Microsoft SC-200, SC-300.
Diversity Statement
Diversity matters to us. We promote dignity and respect for everyone so people feel safe to be themselves. Our opportunities are open to all who value an environment free from prejudice, harassment and discrimination.