···
Log in / Register

Cybersecurity Analyst I

Indeed
Full-time
Onsite
No experience limit
No degree limit
100 - 4 1201 - Plano Piloto, Brasília - DF, 70714-900, Brazil
Favourites
Share
Some content was automatically translatedView Original

Description

Job Summary: We are seeking a Defensive Security Engineer with an investigative and analytical profile to develop and enhance threat detection mechanisms. Key Highlights: 1. Focus on detection engineering and evolution of security mechanisms. 2. Improving security coverage and reducing false positives. 3. Collaborating with MDR, Threat Hunting, and Incident Response teams. **Description and Responsibilities:** **Schedule:** Monday to Thursday, 9 AM to 7 PM with a 1-hour lunch break; Fridays, 9 AM to 7 PM with a 2-hour lunch break **Level:** Operational **Employment Type:** Full-time – CLT The Security Center has a defensive security team focused on creating and evolving detection mechanisms to identify malicious behaviors and signs of compromise in corporate and customer environments. We seek a Defensive Security Engineer with an investigative mindset and strong analytical ability who can translate threat intelligence into efficient, scalable, and risk-oriented detections. This role goes beyond rule creation, encompassing Detection Engineering evolution, security coverage improvement, false positive reduction, and support for more complex investigations alongside the SOC. Experience with Microsoft Sentinel, KQL usage, alert creation, and incident response will be considered a plus.?? **Main Responsibilities:** * Develop, implement, and evolve security detections focused on malicious behaviors, credential abuse, lateral movement, suspicious execution, persistence, and data exfiltration * Translate threat techniques, tactics, and procedures (TTPs) into actionable rules, analytical logic, correlations, and use cases * Design and maintain detection rules for SIEM, EDR, XDR, NDR, and other telemetry and monitoring platforms * Perform event engineering, normalization, and enrichment to broaden context and improve analytical effectiveness * Collaborate with Hunting and CTI teams to create threat-context-driven use cases * Continuously refine detections based on false positives, coverage gaps, environment changes, and threat evolution * Support complex investigations and post-incident analysis, focusing on coverage improvement and development of new defensive capabilities * Validate detection effectiveness through simulations, controlled testing, and behavior reproduction * Map defensive coverage against frameworks such as MITRE ATT\&CK and identify priority visibility and detection gaps * Support definition and evolution of standards, methodologies, playbooks, and quality criteria * Produce technical documentation * Develop scripts, automations, and utilities to support engineering activities * Collaborate with MDR, Threat Hunting, CTI, Offensive Security, and Incident Response teams to build more effective defenses. **Requirements:** * Experience in defensive security, detection, and incident response * Hands-on experience developing and evolving detections with emphasis on quality and noise reduction * Knowledge of security telemetry (endpoints, identities, network, applications, and cloud) * Ability to perform log- and behavior-based analysis and investigation * Familiarity with corporate environments (Active Directory, Windows, and networks) * Experience with platforms such as SIEM, EDR, XDR, or similar * Solid understanding of networking, protocols, and inter-system communication * Strong communication skills for interacting with both technical and non-technical audiences * Flexibility in work approach * Intermediate English proficiency **Technical Skills:** * Security and monitoring platforms (SIEM, EDR, XDR, NDR, and observability solutions) * Building queries, correlations, and rules across various analytical languages and engines * Log engineering: normalization, parsing, and event enrichment * Integrating multiple data sources to generate defensive context * Analysis of security events (authentication, process execution, privileges, network activity, and access to sensitive resources) * Scripting and automation development (Python, PowerShell, Bash, or similar) * Detection validation and optimization, including efficacy testing, tuning, and false positive reduction. **Preferred Qualifications:** * Certifications: CND, ECIH, CHFI, CSA, or equivalents * Experience with Detection-as-Code (DAC) * Experience with threat hunting, incident response, or purple teaming * Experience in offensive security or collaboration with offensive security teams * Work in complex corporate environments, cloud, microservices, and hybrid architectures * Practical knowledge of simulating malicious behaviors for detection validation. ?? Apply now and join our team! ??? **Benefits:** Birthday day off, Mobility (fuel and ride-hailing apps), Health insurance, Dental insurance, Total Pass, Meal allowance, Transportation allowance, Vittude (mental health)

Source:  indeed View original post
João Silva
Indeed · HR

Company

Indeed
Cookie
Cookie Settings
Our Apps
Download
Download on the
APP Store
Download
Get it on
Google Play
© 2025 Servanan International Pte. Ltd.