···
Log in / Register
SOC Analyst 1 - Detection Engineering & Automation
Indeed
Full-time
Onsite
No experience limit
No degree limit
Praça do Patriarca, 62 - Centro Histórico de São Paulo, São Paulo - SP, 01002-010, Brazil
Favourites
Share
Some content was automatically translatedView Original
Description

Job Summary: We are seeking a SOC Analyst 1 to work in Detection Engineering & Automation, conducting research, developing, and evaluating detections, with a focus on SOAR automations. Key Highlights: 1. Focus on research, development, and evaluation of security detections. 2. Development of SOAR automations for SIEM alert response. 3. Work with security frameworks (CKC, MITRE ATT&CK). We seek a professional to work in **Detection Engineering & Automation** as a **SOC ANALYST 1**, responsible for researching, developing, testing, and evaluating detection performance. The ideal candidate must understand SOC concepts, Information Security frameworks, and/or have participated in incident response processes. This position focuses on developing SOAR automations to automatically respond to alerts generated by the SIEM. ### **Responsibilities and Duties:** * Conduct research based on analysis of cyber threat reports; * Create and maintain detection use cases; * Analyze events/logs to identify anomalous behaviors; * Develop detection rules based on research and analysis of SIEM (Security Information and Event Management) technologies; * Create automations via playbooks for automated responses using SOAR (Security Orchestration, Automation, and Response). ### **Requirements and Qualifications:** * Education: Currently pursuing a degree in Information Security, Computer Science, Technology, or related fields. **Soft Skills** * Proactivity: identifying improvements and proposing solutions; * Self-directed learning: eagerness to continuously learn new things; * Engagement and commitment to work quality; * Discipline and effective time management; * Teamwork; * Strong communication skills. **Hard Skills** * Knowledge of Windows and Linux operating systems; * Knowledge of cloud environments (AWS, GCP, Azure, etc.); * Knowledge of processes related to cyber threat monitoring; * Familiarity with CKC (Cyber Kill Chain) and MITRE ATT&CK frameworks; * Familiarity with major SIEM (Security Information and Event Management) platforms; **Preferred Qualifications** * Experience developing automation scripts — Python; * Knowledge of YAML language; * Familiarity with SIGMA format.

Source:  indeed View original post
João Silva
Indeed · HR

Company

Indeed
João Silva
Indeed · HR
Similar jobs

Cookie
Cookie Settings
Our Apps
Download
Download on the
APP Store
Download
Get it on
Google Play
© 2025 Servanan International Pte. Ltd.