Mid-Level Analyst – Offensive Security and Detection

Job not on LinkedIn

🔥 12 hours ago

🇧🇷 Brazil – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 25%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of ROIT

ROIT

51 - 200 employees

Founded 2016

💼 Consulting

⚖️ Legal

☁️ SaaS

Consulting • Legal • SaaS

ROIT is a Brazilian tax-technology company that provides an integrated ecosystem of SaaS solutions and AI-powered tools to help medium and large companies prepare for and manage the 2026 tax reform. Its offerings include an official tax-reform calculator that reprocesses SPED files and invoices, an Invoice-to-Pay automation suite (with ERP/SAP integrations), Tax Discovery for reclaiming taxes, regulatory consulting and education programs, and ongoing support for compliance and scenario planning.

📋 Description

• Conduct adversary simulations and offensive security exercises using MITRE ATT&CK as a reference • Plan and execute controlled attack scenarios, considering techniques, tactics, and attack paths relevant to the environment • Validate the effectiveness of existing prevention, protection, and monitoring controls • Identify security gaps based on the results of offensive exercises • Perform detection engineering by translating exercised techniques into use cases, rules, alerts, and monitoring mechanisms • Validate whether the techniques used during exercises are effectively detected and generate evidence of control coverage • Work closely with Cyber Defense, Application Security, and other technical teams to enhance security controls • Prioritize remediation recommendations based on demonstrated attack paths and identified risk • Document scenarios, techniques used, test results, identified gaps, and recommendations • Provide occasional support for security incident investigations • Support the automation of security routines, tests, validations, and processes related to detection and response • Contribute to the continuous advancement of ROIT’s Cybersecurity maturity

🎯 Requirements

• Practical experience in offensive security, Purple Team, or Red Team operations • Applied knowledge of the MITRE ATT&CK framework • Experience simulating adversary techniques and behaviors • Knowledge of detection engineering, including the creation of rules, use cases, and alerts • Ability to assess whether an attack technique is effectively detected by existing controls • Knowledge of SOC, SIEM, EDR/XDR, and security monitoring concepts • Ability to interpret technical evidence and turn it into improvement recommendations • Knowledge of operating systems, networks, applications, and security fundamentals • Familiarity with automation and scripting for security routines • Strong documentation and technical communication skills • Analytical, investigative, and evidence-driven mindset • Experience working in Purple Team environments • Experience developing and tuning detection rules • Knowledge of SIEM, EDR/XDR, and security platforms • Experience with automation using Python, PowerShell, Bash, or similar technologies • Knowledge of Cybersecurity frameworks and best practices • Experience with incident investigation and response • Certifications related to offensive security, defense, or detection

Apply Now

Similar Jobs

🔥 15 hours ago

Montreal Oficial

1001 - 5000

🔒 Cybersecurity

☁️ SaaS

Arquiteto de Segurança em TI definindo arquiteturas para redes, telecomunicações, ambientes híbridos e multicloud na Montreal. Avaliação técnica de soluções e elaboração de pareceres especializados.

🗣️🇧🇷🇵🇹 Portuguese Required

🔥 15 hours ago

Montreal Oficial

1001 - 5000

🔒 Cybersecurity

☁️ SaaS

Arquiteto de Segurança em TI na Montreal, empresa brasileira de tecnologia. Definindo arquiteturas, criptografia e estratégias DevSecOps para aplicações móveis.

🗣️🇧🇷🇵🇹 Portuguese Required

🕒 Yesterday

Monkey

51 - 200

💳 Fintech

☁️ SaaS

🤝 B2B

Cloud Security Engineer fortalecendo ambientes AWS da Monkey, fintech que simplifica transações financeiras entre empresas e fornecedores. Implementação de controles, investigação de vulnerabilidades e conformidade.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Cloud

Kubernetes

🕒 Yesterday

Alcoa

10,000+ employees

🏭 Manufacturing

Cybersecurity Specialist advising Alcoa’s global teams on IT and OT security. Assessing cyber risks, strengthening governance, and supporting resilient technology operations across Brazil.

Cloud

Cyber Security

IoT

🕒 Yesterday

Truelogic Software

501 - 1000

☁️ SaaS

🤝 B2B

🏢 Enterprise

AI security engineer red-teaming AI products and infrastructure for Truelogic, a nearshore technology staffing provider. Identifying AI-specific vulnerabilities and partnering with engineers on remediation.

Cloud