X-Force Incident Response Consultant

IBM

São Paulo

Presencial

BRL 167 400 - 279 000

Tempo integral

14 dias+
Gerador de candidaturas

Recebe uma resposta deste empregador — um currículo e uma carta de apresentação adaptados exatamente ao que estão a contratar.

Ultrapassa os filtros ATS

Resumo da oferta

A global technology firm seeks an experienced Security Consultant in São Paulo, Brazil. This role involves responding to cybersecurity incidents and advising clients on strengthening their security posture. Candidates must have strong incident response skills, familiarity with EDR and forensic tools, and proficiency in English or Spanish. A Bachelor’s degree in Technology or a related field is required. This full-time position offers a dynamic environment addressing critical cybersecurity challenges.

Qualificações

  • Significant hands-on experience with incident response and computer forensics.
  • Experience leading incident response teams and managing tasks.
  • Ability to communicate fluently in English and/or Spanish.

Responsabilidades

  • Respond to high-profile cybersecurity incidents.
  • Analyze business requirements for security solutions.
  • Collaborate with internal teams for integrated solutions.

Conhecimentos

Incident response
Communication skills in English
Cybersecurity policy
Threat hunting
Forensic analysis
EDR tools familiarity
Log analysis
Scripting (Python, PowerShell)

Formação académica

Bachelor's degree in Technology or related field

Ferramentas

EnCase
FTK
X-Ways
SleuthKit
Splunk
ELK

Descrição da oferta de emprego

Introduction

Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant, you will be a key advisor for IBM’s clients, analyzing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling and securing the client’s organization with the cognitive solutions that are making IBM the fastest growing enterprise security business in the world.

Your Role And Responsibilities

As a senior consultant for the IBM Security X-Force Incident Response (X-Force IR) team, you will be part of a team of consultants who are responding to high‑profile cybersecurity incidents within our clients’ enterprise networks. You will work with our clients to prepare for and respond to cybersecurity incidents. You will serve as a trusted advisor to our clients, helping to shape their cybersecurity program. You will collaborate with internal IBM stakeholders to provide integrated solutions to our clients’ most challenging problems.

In this role you will have demonstrated skills in various elements of Incident Response, conducting computer intrusion investigations, and have a strong foundation in cyber security policy, operations and best practices, ideally in large enterprise environments. You will have proficiency with leading EDR tools as well as familiarity with forensic analysis tools and live‑response analysis. Familiarity with Windows and Linux enterprise environments and systems such as Active Directory, M365, firewalls, IPS/IDS, SIEMs, etc. is required. Excellent written and verbal communication skills are required. When not responding to breaches, you will conduct enterprise threat hunting, help clients develop incident response plans, facilitate tabletop exercises as well as provide other strategic security services related to incident response.

Required Technical And Professional Expertise
  • Significant hands‑on experience with hardware/software tools used in incident response, computer forensics, network security assessments, and/or application security.
  • Experience with assessing and developing enterprise‑wide policies and procedures for IT risk mitigation and incident response.
  • Experience leading incident response teams and managing tasks across all phases of an engagement.
  • Capable of working independently as well as providing leadership on internal projects and client engagements.
  • Communication skills: able to communicate fluently in English or/and Spanish.
  • Bachelor’s degree completed in Technology or related fields.
Forensic Analysis & Incident Response Skills
  • Ability to forensically analyze both Windows & Unix systems for evidence of compromise.
  • Proficiency with industry standard forensic tools such as EnCase, FTK, X‑Ways, SleuthKit.
  • Experience performing log analysis locally and via SIEM/log aggregation tool.
  • Experience hunting threat actors in large enterprise networks and cloud environments.
  • Experience with using and configuring Endpoint Detection & Response (EDR) tools.
  • Demonstrate an understanding of the behavior, security risks and controls of common network protocols.
  • Demonstrate an understanding of common applications used in Windows and Linux enterprise environment.
  • Familiarity with Active Directory, Exchange and Office365 applications and logs.
  • Familiarity with cloud computing platforms like IBM Cloud, AWS, GCP or Azure.
  • Proficient in writing cohesive reports for a technical and non‑technical audience.
Strategic Assessment Expertise
  • Examine and analyze available client internal policies, processes, and procedures to determine patterns and gaps at both a strategic and tactical level. Recommend appropriate course of action to support maturing the client’s incident response program and cyber security posture.
  • A strong familiarity with various security frameworks and standards such as ISO 27001/2, PCI DSS, NIST 800‑53, 800‑171, and applicable data privacy laws and regulations.
  • Demonstrated experience with planning, scoping, and delivering technical and/or executive‑level tabletop exercises, with a focus on either tactical or strategic incident response processes.
  • Ability to incorporate current trends and develop custom scenarios applicable to a client.
  • Low‑level operating system knowledge, including automation and performing administrative tasks.
  • Scripting or programming experience, preferably in a language commonly used for DFIR such as Python or PowerShell.
  • Ability to work with data at scale such as using Splunk / ELK.
  • Expertise working with shell programs such as grep, sed and awk to process data quickly.
  • Working experience with virtualization and cloud technology platforms like IBM Cloud, AWS, GCP & Azure.
Preferred Technical And Professional Experience
  • Diverse understanding of cyber security related vulnerabilities, common attack vectors, and mitigations.
  • Capable of developing strategic level incident response plans as well as tactical‑focused playbooks.
  • Ability to manage tasks and coordinate work streams during incident response investigations.
Seniority level
  • Mid‑Senior level
Employment type
  • Full‑time
Job function
  • Consulting, Information Technology, and Sales
Industries
  • IT Services and IT Consulting
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Information Security Analyst
Information Security Analyst

Jobtailor • Maringá

Presencial
BRL 150 000 - 230 000
Senior Security and Operations Analyst
Senior Security and Operations Analyst

Jobtailor • São Paulo

Presencial
BRL 90 000 - 150 000
Principal Consultant, DFIR- Reactive Services (Unit 42)
Principal Consultant, DFIR- Reactive Services (Unit 42)

Palo Alto Networks • São Paulo

Presencial
BRL 350 000 - 550 000
Remote work option
Travel opportunities (≈20%)
Mentorship culture
Principal Consultant, DFIR- Reactive Services (Unit 42)
Principal Consultant, DFIR- Reactive Services (Unit 42)

Jobs Paloaltonetworks • São Paulo

Presencial
BRL 260 000 - 520 000
Consultant, DFIR, Reactive Services (Unit 42) – LATAM
Consultant, DFIR, Reactive Services (Unit 42) – LATAM

Palo Alto Networks, Inc. • São Paulo

Presencial
BRL 80 000 - 120 000
Incident Response Analyst
Incident Response Analyst

TrendAI • São Paulo

Presencial
BRL 90 000 - 150 000
Incident Response Analyst
Incident Response Analyst

Trend Micro • São Paulo

Presencial
BRL 90 000 - 130 000
SOC Technical Supervisor, Incident Analysis
SOC Technical Supervisor, Incident Analysis

Jobtailor • São Paulo

Presencial
BRL 180 000 - 320 000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Jobtailor • São Paulo

Presencial
BRL 120 000 - 180 000
Information Security Consultant – Mid-Level
Information Security Consultant – Mid-Level

Jobtailor • São Paulo

Presencial
BRL 100 000 - 167 000