Remote Jobs RockRemote Jobs Rock

Especialista de CSIRT

📅 Jun 29
Segurança Da InformaçãoResposta A IncidentesAnálise ForenseSIEM

📜 Description

  • Investigar incidentes envolvendo malware, movimentos laterais, abuso de credenciais e ameaças sofisticadas.
  • Executar análises forenses (live e offline) em endpoints, servidores, redes e ambientes cloud.
  • Realizar threat hunting baseado em hipóteses, mapeado em MITRE ATT&CK.
  • Coordenar ações técnicas durante incidentes críticos e liderança de war rooms.
  • Realizar contenção, erradicação e recuperação de ambientes afetados.
  • Produzir relatórios técnicos, RCA e lições aprendidas.

🛠️ Requirements

  • Ensino Superior completo em Segurança da Informação, Defesa Cibernética, Redes de Computadores, Análise de Sistemas, Ciência da Computação ou áreas correlatas.
  • Experiência comprovada em Resposta a Incidentes e análise forense.
  • Domínio de SIEM, EDR/XDR e análise de logs.
  • Conhecimento de redes, protocolos e TTPs de atacantes.
  • Experiência com MITRE ATT&CK e threat hunting.
  • Inglês Intermediário.
Full job description

Você será responsável por conduzir investigações avançadas de segurança, realizar resposta a incidentes, executar análises forenses e conduzir atividades de threat hunting. Atuar na gestão e resolução de incidentes complexos, oferecendo suporte técnico qualificado a clientes em situações críticas e garantindo a efetividade das ações de contenção, erradicação e recuperação. Contribuir para a evolução contínua das capacidades de detecção e resposta do SOC, incluindo aprimoramento de processos, identificação de lacunas, implementação de melhorias técnicas e participação ativa na análise de ameaças emergentes.

Responsibilities

Suas principais atividades:


  • Investigar incidentes envolvendo malware, movimentos laterais, abuso de credenciais e ameaças sofisticadas;
  • Executar análises forenses (live e offline) em endpoints, servidores, redes e ambientes cloud;
  • Realizar threat hunting baseado em hipóteses, mapeado em MITRE ATT&CK;
  • Coordenar ações técnicas durante incidentes críticos e liderança de war rooms;
  • Realizar contenção, erradicação e recuperação de ambientes afetados;
  • Produzir relatórios técnicos, RCA e lições aprendidas;
  • Desenvolver e melhorar casos de uso, regras de detecção e automações no SOC;
  • Desenvolver e revisar playbooks de resposta a incidentes.

Requirements

Esperamos que você tenha:


  • Ensino Superior completo em Segurança da Informação, Defesa Cibernética, Redes de Computadores, Análise de Sistemas, Ciência da Computação ou áreas correlatas;
  • Experiência comprovada em Resposta a Incidentes e análise forense;
  • Domínio de SIEM, EDR/XDR e análise de logs;
  • Conhecimento de redes, protocolos e TTPs de atacantes;
  • Experiência com MITRE ATT&CK e threat hunting;
  • Inglês Intermediário.


Será um diferencial se você também tiver:


  • Certificações GCIH, GCFA, GCIA, GNFA, CHFI ou similares.
  • Experiência com automação (Python, PowerShell) e plataformas SOAR.
  • Conhecimento de ambientes Azure, AWS ou GCP.
  • Vivência em MSSP ou ambientes críticos (financeiro, indústria, saúde).
Notion

Security Engineer, Detection and Response

🕒 4 days ago
Notion👥 10,000+ employees🏢 Software Development🤝 B2B

As a Detection Engineer, you'll build and operate systems to detect and respond to attacks in Notion's cloud-native environment, ensuring high-signal detections and effective incident response.

Detection EngineeringSecurity OperationsIncident ResponseThreat Hunting
WRITER

Security engineer, detection and response (UK)

🕒 10 days ago
WRITER👥 501 - 1000 employees🏢 Computer Software

As a staff detection and response engineer, you'll build sophisticated detection systems to protect AI infrastructure from evolving threats while automating response capabilities.

Security OperationsDetection EngineeringIncident ResponseAI/ML Infrastructure Security
WRITER

Security engineer, detection and response

🕒 10 days ago
WRITER👥 501 - 1000 employees🏢 Computer Software

As a staff detection and response engineer, you'll protect AI infrastructure by building detection systems, automating responses, and coordinating incident responses to sophisticated threats.

Security OperationsDetection EngineeringIncident ResponsePython

Trusted by Remote Workers