Description
Hybrid model (2 days per week onsite in Campinas/SP)
Advanced English for conversation
**Requirements:**
Experience with security monitoring and detection tools, such as SIEM, EDR, or XDR
Experience analyzing logs, security alerts, and investigating suspicious events
Experience with scripting or automation, such as Python, Shell, JavaScript, and related technologies
Ability to investigate security incidents, identify evidence, and support decision-making during incident response
Proven experience creating automations via scripts or tools like N8N;
Understanding of cybersecurity attack TTPs, especially in cloud environments;
Proven experience conducting incident response activities within a SOC/CSIRT environment;
Deep understanding of SOC/CSIRT KPIs, operational routines, and strategies;
**Preferred Qualifications:**
Experience with cloud environments (especially Azure) and their primary security risks
Familiarity with security frameworks and best practices, such as MITRE ATT\&CK, NIST, or ISO 27001