Hybrid Information Security Analyst – Mid-level

Posted last month

Apply now

About the role

  • Analista Pleno de Blue Team at Mais.Mobi focusing on cyber security, incident response, and vulnerability management. Working in a hybrid role in Rio de Janeiro.

Responsibilities

  • Detect and support remediation of environment vulnerabilities, maintain cybersecurity tools, and perform incident response;
  • Create, optimize and maintain detection rules (correlation rules) in the SIEM to identify malicious or anomalous activity;
  • Manage the vulnerability lifecycle, from identification to remediation in collaboration with other teams;
  • Support implementation of security best practices across cloud environments, servers, workstations and networks, following security frameworks;
  • Participate in security incident response, investigating alerts generated by the SIEM or other security tools;
  • Provision and deprovision assets and resources in defensive security tools;
  • Support analysis of security failures and propose mitigation solutions;
  • Ensure proper collection of asset logs, working to meet security requirements and monitoring rules;
  • Document procedures, incident analyses and security configurations;
  • Prepare technical and executive reports, including evidence, impact assessments and mitigation recommendations;
  • Automate processes and develop scripts to support defensive operations;
  • Collaborate with Red Team, SOC, Architecture and DevSecOps teams to validate and remediate vulnerabilities;
  • Develop Blue Team playbooks, methodologies and internal standards;
  • Monitor threat trends, exploits and new attack techniques and update security tools with obtained intelligence.

Requirements

  • Bachelor's degree in Information Security, Information Systems, Computer Science, Software Engineering or related fields;
  • Experience in Blue Team roles or equivalent functions;
  • Experience with core tools: SIEM, EDR or XDR, Vulnerability Management and WAF;
  • Advanced knowledge of Windows and Linux environments, permissions, services and common attack vectors;
  • Advanced knowledge of firewalls, proxies, VPNs, cloud and networking;
  • Familiarity with methodologies: MITRE ATT&CK, PTES, NIST SP;
  • Familiarity with security projects, processes and policies;
  • Understanding of secure development and DevSecOps pipelines (CI/CD, Git, integration of automated scanners);
  • Experience producing reports, cybersec books and technical presentations;
  • Experience in environment hardening, incident response and creation of playbooks;
  • Ability to produce clear, concise, impact-oriented documentation;
  • Certifications: ISO/IEC 27001 and CompTIA Security+.
  • Preferred certifications: EHF (Ethical Hacking Foundation), OCI Security Professional, AWS Certified Security – Specialty, GCIA (GIAC Certified Intrusion Analyst), GCDA (GIAC Certified Detection Analyst), CCD (Certified CyberDefender) - CyberDefenders, CDN (Certified Network Security), CEH (Certified Ethical Hacker);
  • Experience with specific security tools such as Kaspersky, Umbrella, Cloudflare;
  • Knowledge of programming/scripting languages (e.g., Python, Shell Script, PowerShell) for security task automation;
  • Knowledge of the Brazilian General Data Protection Law (LGPD);
  • Postgraduate degree in Information Security;
  • English at intermediate/advanced level.

Benefits

  • Transportation allowance + Meal voucher + Food allowance + Health and dental insurance + Reimbursement for online courses + Life insurance + Emotional wellbeing program, etc.

Job title

Information Security Analyst – Mid-level

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job