Description
Job Summary:
We are seeking a Senior Cybersecurity Analyst to define, implement, and maintain information security solutions in hybrid and multicloud environments.
Key Highlights:
1. Participation in defining, implementing, and maintaining security solutions.
2. Technical leadership and cross-departmental collaboration.
3. Involvement in digital transformation initiatives.
**About the Role:**
We seek a Senior Cybersecurity Analyst to define, implement, and maintain information security solutions in hybrid and multicloud environments, ensuring protection against threats, business continuity, and compliance with standards and regulations.
* **Responsibilities:**
* Conduct risk assessments and implement security controls across infrastructure, applications, and cloud and on\-premise services;
* Define and enforce security policies aligned with frameworks (NIST, ISO 27001, COBIT) and regulatory requirements (LGPD, PCI\-DSS, SOX);
* Participate in security projects involving EDR, DLP, CASB, SIEM, firewalls, WAF, and endpoint and network protection solutions;
* Lead and support security incident investigations, including response, mitigation, and lessons learned;
* Develop and review incident response playbooks, standards, policies, and internal procedures;
* Serve as the technical subject-matter expert within the Security team, mentoring junior and mid-level analysts and collaborating with Infrastructure, Risk, Compliance, and Business units;
* Support internal and external audits by providing evidence, technical reports, and improvement recommendations;
* Participate in digital transformation initiatives, ensuring security requirements are applied from inception (security by design).
* **Requirements:**
* Proven experience (5\+ years) in Information Security, with hands-on expertise in securing networks, endpoints, applications, and cloud environments;
* Proficiency with SIEM tools (Splunk, QRadar, Elastic), EDR/XDR platforms (CrowdStrike, Trellix, SentinelOne), DLP, CASB, and next-generation firewalls;
* Knowledge of forensic analysis, incident response, and log investigation;
* Experience in cloud environments (Azure, AWS, GCP, OCI) with focus on security controls and compliance;
* Skills in automation and scripting (Python, PowerShell, Bash) for security and monitoring purposes;
* Familiarity with standards, frameworks, and legislation (ISO 27001, NIST CSF, LGPD, GDPR, PCI\-DSS, SOX);
* Ability to provide technical leadership, strategic vision, and effective communication.
* **Preferred Qualifications:**
* Relevant certifications: CISSP, CISM, CISA, CompTIA Security\+, Microsoft SC\-200/SC\-100, AWS Security Specialty, Palo Alto PCNSA/PCNSE, Fortinet NSE4\+;
* Experience in Zero Trust projects, SOC operations, Red Team/Blue Team exercises, or Security Automation (SOAR) implementation;
* Prior work experience in large enterprises or highly regulated industries (financial, telecom, healthcare, retail).
Minimum Education: Bachelor's Degree