Jobgether
Senior Security Engineer - CSIRT
engineeringfull-timeBrazil
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more
About the role
Accountabilities:
- Act as the primary technical point of contact for Level 2 and Level 3 security incidents, leading response efforts across complex and high-criticality environments.
- Coordinate incident response activities with MSSPs and 24/7 SOC teams, ensuring operational quality, alignment, and continuous improvement.
- Collaborate rapidly with multicultural teams and multiple business functions, including Legal, Data Protection, Communications, and cybersecurity teams, throughout security incidents.
- Develop, maintain, and continuously improve Incident Response playbooks, procedures, and workflows, incorporating automation wherever possible.
- Lead Digital Forensics and Incident Response activities, including investigation of root causes, assessment of compromise scope, evidence analysis, and post-incident reviews.
- Drive post-mortem processes by facilitating technical discussions, documenting findings, and translating incidents into actionable improvements.
- Apply advanced threat detection expertise to create, tune, and enhance detection rules across SIEM and EDR platforms.
- Manage the full Cyber Threat Intelligence lifecycle, transforming threat data into actionable intelligence that strengthens SOC operations and defensive capabilities.
- Partner with Tier 1 and Tier 2 vendors to optimize operational routines, improve service delivery, and maximize the value of security contracts.
- At least 5 years of professional experience focused on Incident Response, Digital Forensics, or Threat Hunting.
- Strong hands-on expertise in Digital Forensics and Incident Response, including the preservation, collection, acquisition, and analysis of digital evidence.
- Experience investigating systems and networks across Windows, Linux, and macOS environments.
- Proficiency with memory forensics and host-based forensic tools.
- Ability to conduct basic static and dynamic malware analysis to identify Indicators of Compromise (IoCs) and understand malicious capabilities.
- Proven experience leading incident response activities in cloud environments, particularly AWS and GCP.
- Practical experience with Security Orchestration, Automation and Response (SOAR), including developing automated workflows that improve incident response efficiency.
- Strong risk assessment and prioritization skills, with the ability to allocate resources and make effective decisions during high-pressure situations.
- Excellent communication and leadership abilities, including the capacity to clearly explain technical findings to both technical specialists and executive stakeholders.
- Competitive salary.
- Profit-sharing opportunities.
- Meal allowance.
- Health insurance.
- Dental plan.
- Life insurance.
- Childcare subsidy and atypical parenthood subsidy.
- Wellhub membership.
- Home office allowance.
- Employee assistance program covering mental health, social, legal, and financial support.
- Extended parental leave.
- Day off for your birthday, Mother’s Day, and Father’s Day.
- Benefits Club with discounts on everyday services.
- Discounts at educational institutions.
- Reading kit for children through PlayKids.
- Remote-first work model, with the option to work from anywhere in Brazil.
- Access to São Paulo offices or partner coworking spaces up to twice per week.
Requirements:
Benefits:
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply