···
Log in / Register
Information Security Specialist I (SOC)
Negotiable Salary
Indeed
Full-time
Onsite
No experience limit
No degree limit
Praça do Patriarca, 62 - Centro Histórico de São Paulo, São Paulo - SP, 01002-010, Brazil
Favourites
Share
Some content was automatically translatedView Original
Description

Description: * Bachelor's degree in Information Security, Information Systems, Computer Science, or related fields. * Experience in security monitoring and incident response (SOC / CSIRT / Blue Team). * Proficiency in SIEMs (Google SecOps, Splunk, QRadar, Elastic, Chronicle). * Expertise in log analysis, networking, and protocols (Firewall, Proxy, DNS, Syslog, Endpoint, Cloud). * Knowledge of EDR/XDR, DLP, WAF, IDS/IPS, and CSPM (GuardDuty, Defender, Trend Vision One). * Ability to technically lead investigations and prioritize incidents based on impact and risk. * Experience with task automation (Python, APIs, SOAR). * Skill in documenting evidence, guiding analysts, and reporting to executives. * Familiarity with security frameworks (MITRE ATT&CK, NIST, ISO 27035). * Availability for 24x7 operations, including on-site shifts from 9:00 AM to 6:00 PM in the Faria Lima region. * Provide technical leadership to the SOC analyst team (L1/L2), serving as the focal point for complex investigations and incident response. * Support the development of work schedules, time-off planning, and technical training for the team. * Ensure the effectiveness of continuous monitoring, tuning, and evolution of detection rules in the SIEM (Google SecOps, Splunk, QRadar, Elastic, etc.). * Execute and supervise triage, correlation, and handling of security incidents across multiple platforms (on-premises, cloud, and SaaS). * Conduct reviews of critical alerts, coordinating escalation with the CSIRT and other cybersecurity defense teams. * Drive continuous improvement of processes, automations (Python/SOAR), and integration of defensive tools. * Support the design and execution of SOC playbooks, runbooks, and standard operating procedures. * Prepare technical and executive incident reports, including recommendations and performance indicators (KPIs and KRIs). * Serve as a technical reference and mentor for the team, promoting continuous skill development and best practices in investigation. * Collaborate with Vulnerability Management, Threat Intelligence, and Cloud Security teams to strengthen the overall defense ecosystem. 2512150202201865539

Source:  indeed View original post
João Silva
Indeed · HR

Company

Indeed
Cookie
Cookie Settings
Our Apps
Download
Download on the
APP Store
Download
Get it on
Google Play
© 2025 Servanan International Pte. Ltd.