Description
Job Summary:
An Information Security professional for monitoring and responding to incidents, vulnerability management, and administration of security controls, on a temporary contract basis.
Key Highlights:
1. Monitoring and responding to security incidents.
2. Vulnerability management and administration of security controls.
3. Opportunity to support information security compliance and auditing.
Temporary contract to cover vacation periods.
**Responsibilities:**
* Monitoring and responding to incidents
* Monitor alerts generated by security tools (SIEM, IDS/IPS, antivirus), log incidents in the ticketing system, escalate incidents per defined procedures, and assist in initial investigation of suspicious events.
* Vulnerability management
* Perform periodic vulnerability scans across organizational assets, consolidate results into standardized reports, and track patch and remediation cycles with IT teams.
Security control administration
* Support configuration and maintenance of security tools (firewall, proxy, antivirus, multi-factor authentication), manage access requests per current policy, and verify configuration compliance against defined standards.
* Compliance and audit support
* Assist in collecting evidence for internal and external audits, verify process adherence to security policies, and contribute to updating normative documents (policies, procedures, and work instructions).
* Awareness and training
* Support development and dissemination of information security awareness materials for employees, record training participation, and monitor engagement metrics.
**Technical Skills**
* SIEM tool operation (e.g., Splunk, Microsoft Sentinel, Wazuh) for log analysis and event correlation
* Basic networking knowledge (TCP/IP, DNS, HTTP/S, VPN, firewall) for traffic interpretation and anomaly identification
* Performing vulnerability scans using vulnerability analysis tools (e.g., Nessus, OpenVAS)
Familiarity with Windows and Linux operating systems, including log reading and interpretation of security configurations
* Ability to analyze Indicators of Compromise (IoCs) and support basic forensic investigation
Familiarity with reference frameworks and standards: ISO 27001, NIST CSF, LGPD, CIS Controls
**Behavioral Skills**
* Attention to detail and analytical ability to identify anomalous patterns in large volumes of data
* Clear communication to document incidents and objectively report risk situations
* Organization and time management to handle multiple tickets and deadlines simultaneously
* Ethical conduct and commitment to confidentiality of handled information
* Willingness for continuous learning in a rapidly evolving field
**Competencies**
* Completed bachelor’s degree in Computer Science, Information Security, or related fields
* Problem analysis and resolution
* Ability to investigate security events and incidents, distinguish false positives from real threats, and propose containment actions based on established procedures—even with partial information.
* Process and compliance orientation
* Understanding and application of organizational security policies, standards, and procedures, ensuring executed activities align with internal controls and applicable regulatory requirements.
* Cross-team collaboration
* Ability to collaborate with IT, Legal, Privacy, and business teams, communicating risks in accessible terms and contributing to solutions that balance security and operations.
* Information and documentation management
* Ability to accurately record evidence, incident reports, scan results, and corrective action histories, ensuring traceability and reliability of information.
* Situational awareness in security
* Monitoring of the threat landscape (basic threat intelligence), including newly disclosed vulnerabilities (CVEs), vendor security bulletins, and attack trends relevant to the organization’s industry.
**Job Details:**
* Market-competitive salary
* On-site working hours
* Temporary contract
* Meal allowance
* Transportation allowance