Security Incident Response Specialist

🕒 June 17

🇧🇷 Brazil – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🛡️ Security Operations

👻 Ghost score 24%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Cooperativa Central Ailos

Cooperativa Central Ailos

1001 - 5000 employees

Founded 2002

🛡️ Insurance

💼 Consulting

📦 Logistics

Insurance • Consulting • Logistics

Cooperativa Central Ailos is a cooperative organization that focuses on providing accessible financial services to its members, ensuring inclusivity and support for various communities. The organization emphasizes user-friendly interfaces and high contrast accessibility features, catering to a diverse clientele.

📋 Description

• Take technical command of critical (P1) incidents, defining response strategy, prioritization, and business trade-offs. • Coordinate complex, multivector investigations covering endpoints, identity, email, cloud, network, and applications. • Perform or direct advanced forensic analyses, ensuring chain of custody and proper engagement with legal and privacy teams. • Design, evolve, and maintain the Incident Response capability, including processes, tools, integrations, metrics, and a readiness roadmap. • Mentor junior and mid-level professionals, lead tabletop exercises and crisis simulations, and represent the function to executives, auditors, and regulators. • Manage relationships with vendors and strategic partners (DFIR, CSIRT, Threat Intelligence), conducting POCs and technical evaluations as needed. • Define and maintain detection standards and conventions, including naming, severity, lookback windows, and cost/performance thresholds. • Plan and execute the detection roadmap aligned to key risks, threats, and organizational objectives (e.g., coverage of top TTPs). • Establish quality metrics and technical gates, such as minimum accuracy, mandatory testing, peer review, and promotion criteria for production. • Lead purple teaming initiatives, continuous validation of controls, and detection of emerging techniques; guide hypothesis-driven threat hunting. • Serve as the technical reference for detection code reviews, mentor the team, and represent the topic in technical committees and executive forums. • Evaluate tools, frameworks, and architectures for SIEM/XDR/NDR, conducting POCs and adopting detection-as-code at scale. • Define content standards, detection architecture, and coverage strategy based on MITRE ATT&CK. • Ensure operational quality through SLOs, effectiveness metrics, and advanced detection testing.

🎯 Requirements

• Proven experience in cyber Incident Response within complex corporate environments. • Strong background in Detection Engineering, SIEM/XDR/NDR, and practical use of the MITRE ATT&CK framework. • Advanced knowledge of investigations involving endpoints, identity, cloud, email, network, and applications. • Experience with forensic analysis, chain of custody, and interaction with legal and privacy teams. • Proven technical leadership, mentoring, and cross-functional influence. • Excellent technical communication skills, with the ability to operate during crises, audits, and committee meetings. • Preferred: Experience with detection-as-code (e.g., Sigma, KQL, SPL, Terraform, CI/CD pipelines). • Prior experience with purple teaming, structured threat hunting, and adversary simulations. • Familiarity with frameworks such as NIST CSF, NIST 800-61, ISO 27001/27002. • Experience working with DFIR, Threat Intelligence, and MSSP vendors. • Relevant certifications (e.g., GCED, GCIA, GCIH, GNFA, CISSP, or similar).

🏖️ Benefits

• Health insurance – valuable coverage when you need it. • Dental insurance – because we care about smiles. • Renascer Program – employee support and well‑being initiative. • Meaningful Dates – we celebrate important moments. • Education investment – we support your learning journey. • Results participation – we build together and share in the outcomes. • Individual Development Plan – we value your career ownership. • Private pension plan – supporting long‑term future planning. • Life insurance – an important benefit. • Time Together – recognition for team engagement and in‑person participation. • Meal and/or grocery allowance. • Transportation allowance – no deductions. • Childcare / babysitting assistance – because your child deserves a safe, welcoming place.

Apply Now