SOC Technical Supervisor, Incident Analysis

Jobtailor

São Paulo

Presencial

BRL 180 000 - 320 000

Tempo integral

Há 7 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Uma candidatura feita para esta oferta — um currículo e uma carta de apresentação personalizados que vão ao encontro do anúncio.

Ultrapassa os filtros ATS

Resumo da oferta

Jobtailor in São Paulo, Brazil seeks a dynamic SOC Lead to direct operations and guide analysts through complex investigations. You will oversee triage, classification, and escalation of security incidents, while ensuring adherence to playbooks and incident response processes.

The role requires strong leadership, decisive decision-making, and solid knowledge of SIEM, EDR/XDR, AD, and cloud security. You will coordinate with multiple cybersecurity teams to maintain SOC maturity and service

Qualificações

  • Experience in leading SOC operations and incident response.
  • Ability to make decisions in high-pressure environments.
  • Strong communication and organizational skills.
  • Familiarity with SIEM, EDR/XDR, and common security tooling.
  • Knowledge of playbooks, procedures, and incident response processes.

Responsabilidades

  • Lead the Security Operations Center (SOC) from a technical and operational perspective.
  • Supervise analysts’ activities during the shift.
  • Triage, investigate, classify, prioritize, and escalate alerts and incidents.
  • Serve as technical reference for N1/N2 analysts and support complex investigations.
  • Monitor queues, priorities, severities, and SLAs.
  • Collaborate with Engineering, Threat Hunting, Threat Intelligence, DFIR, and other teams.
  • Maintain documentation of analyses, evidence, actions, and recommendations.
  • Support incident communication with clients and internal teams.
  • Contribute to continuous improvement, automation, and SOC maturity.

Conhecimentos

Leadership
Decision-making
Communication
Prioritization
Cybersecurity knowledge
Monitoring & detection
SIEM
EDR/XDR
Active Directory
Firewalls
Proxy
VPN
Microsoft 365
Entra ID
Cloud security

Ferramentas

SIEM
EDR/XDR
Active Directory
Firewalls
Proxy
VPN
Microsoft 365
Entra ID
Cloud security

Descrição da oferta de emprego

  • Lead the Security Operations Center (SOC) from a technical and operational perspective
  • Supervise analysts’ operational and technical activities during the shift
  • Ensure the triage, investigation, classification, prioritization, and escalation of alerts and incidents
  • Serve as a technical reference for N1 and N2 analysts and support complex investigations
  • Monitor queues, priorities, severities, and SLAs
  • Support investigations involving SIEM, EDR/XDR, Active Directory, Firewalls, Proxy, VPN, Microsoft 365, Entra ID, Cloud, and security solutions
  • Correlate events to identify compromises, lateral movement, persistence, privilege escalation, and suspicious behavior
  • Support security incidents and cyber crises, carrying out escalations as needed
  • Ensure adherence to playbooks, procedures, and incident response processes
  • Assess the technical quality of analyses and identify opportunities for improvement and false positives
  • Collaborate with Engineering, Threat Hunting, Threat Intelligence, DFIR, and other Cybersecurity teams
  • Monitor SOC metrics, including SLA, MTTA, MTTD, MTTR, alert volume, backlog, and the quality of case handling
  • Provide technical oversight and feedback to analysts
  • Support activity distribution according to criticality, priority, capacity, and technical expertise
  • Ensure documentation of analyses, evidence, actions, and recommendations
  • Support incident communication and escalation with clients and internal teams
  • Participate in operational, technical, and status meetings
  • Support RCA and post-incident analysis
  • Contribute to continuous improvement, automation, process optimization, and SOC maturity
  • Ensure operational continuity, recordkeeping, and handovers
  • Proactively identify operational risks that could compromise SOC services
Requirements
  • Technical, investigative, and leadership profile
  • Ability to make decisions in highly critical environments
  • Strong communication skills
  • Ability to prioritize
  • Sense of urgency
  • Organization and composure when handling critical incidents
  • Technical knowledge of Cybersecurity
  • Experience and/or knowledge of Monitoring, Detection, Investigation, and Incident Response
  • Knowledge of SIEM, EDR/XDR, Active Directory, Firewalls, Proxy, VPN, Microsoft 365, Entra ID, Cloud, and security solutions
  • Knowledge of security alert and incident triage, investigation, classification, prioritization, and escalation
  • Knowledge of SLAs, playbooks, operating procedures, and incident response processes
  • Knowledge of RCA (Root Cause Analysis) and post-incident analysis
Core Competencies

Demonstrates expertise in leading Security Operations Center (SOC) activities, including incident response, triage, and investigation, while ensuring adherence to operational procedures and continuous improvement. Proficient in utilizing security tools such as SIEM, EDR/XDR, and Active Directory to monitor and respond to cybersecurity threats effectively.

Highest-signal resume keywords
  • Security Operations Center Leadership
  • Incident Response Management
  • SIEM and EDR/XDR Expertise
  • Root Cause Analysis (RCA)
  • Cybersecurity Knowledge
Hard Skills
  • Incident Triage
  • Investigation and Classification
  • Prioritization of Alerts
  • Monitoring and Detection
  • Cybersecurity Technical Knowledge
Soft Skills
  • Strong Communication Skills
  • Decision-Making in Critical Environments
  • Organization and Composure
  • Sense of Urgency
  • Ability to Prioritize
Industry Keywords
  • Incident Response Processes
  • Playbooks
  • Operating Procedures
  • Security Alert Triage
  • Post-Incident Analysis
Tools & Technologies
  • SIEM
  • EDR/XDR
  • Active Directory
  • Firewalls
  • Proxy
  • VPN
  • Microsoft 365
  • Entra ID
  • Cloud Security Solutions
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Information Security Consultant – Mid-Level
Information Security Consultant – Mid-Level

Jobtailor • São Paulo

Presencial
BRL 100 000 - 167 000
Senior Security and Operations Analyst
Senior Security and Operations Analyst

Jobtailor • São Paulo

Presencial
BRL 90 000 - 150 000
Information Security Analyst
Information Security Analyst

Jobtailor • Maringá

Presencial
BRL 150 000 - 230 000
Cybersecurity Intern
Cybersecurity Intern

Jobtailor • São Paulo

Presencial
BRL 13 000 - 27 000
Infrastructure and Digital Security Manager
Infrastructure and Digital Security Manager

Jobtailor • São Paulo

Presencial
BRL 320 000 - 460 000
Analista de triagem e contenção de incidentes - Cooperado
Analista de triagem e contenção de incidentes - Cooperado

Solo Network • Brasil

Presencial
AF5E: Analista de Segurança da Informação Sênior
AF5E: Analista de Segurança da Informação Sênior

Mazzatech • São Paulo

Híbrido
BRL 180 000 - 300 000
Infrastructure Analyst, Senior
Infrastructure Analyst, Senior

Jobtailor • Barueri

Presencial
BRL 60 000 - 120 000
Analista de SOC - Tier II
Analista de SOC - Tier II

NetSecurity • São Paulo

Presencial
BRL 90 000 - 130 000
Security / SOC L2 Analyst
Security / SOC L2 Analyst

Accenture Brasil • São Paulo

Presencial
BRL 90 000 - 130 000
Treinamentos e certificações
Oportunidade de carreira (N2→N3)
Ambiente global de Cyber Security