Snr. Information Security Analyst (Position located in Brazil)
Please submit your resume in English.
To learn more about our team and office culture in São Paulo, Brazil, visit the following links.
Careers Page: https://www.knowbe4.com/careers/locations/sao-paulo
Glassdoor: https://www.glassdoor.com/Location/KnowBe4-S%C3%A3o-Paulo-Location-EI_IE969384.0,7_IL[…]M_-C1lsxoZq7Cx8IriVE8MkrzuTmnJzqego77RAWZz9sqGt_55BflwYKpQeg
LinkedIn: https://www.linkedin.com/company/knowbe4/life/brazil/
The Snr. Information Security Analyst serves as a technical lead for the organization’s threat detection and response operations. This role is responsible for ensuring the confidentiality, integrity, and availability of enterprise data by leading security reviews, risk assessments, and incident response efforts. Beyond technical execution, the Senior Analyst drives operational excellence by architecting automated workflows and providing advanced mentorship to the SOC team. This position bridges the gap between high-level security strategy and hands-on threat hunting to maintain a resilient security posture.
Responsibilities:
Conduct Security, vulnerability, and risk assessments across services, cloud and applications, using both automated tools and manual testing procedures.
Operational Leadership. Direct the SOC team in identifying, investigating, and triaging security alerts; act as the lead investigator for complex or high-stakes security incidents
Advanced Threat Hunting. Proactively hunt for threats across cloud, hybrid, and on-prem environments using behavior-based analysis and threat intelligence feeds.
Cloud Security Governance. Lead regular security audits of AWS/Azure/SaaS environments, developing and enforcing hardening standards to mitigate cloud-specific risks
Conduct regular security reviews and risk assessments for cloud environments to identify vulnerabilities and threats. Develop strategies to mitigate risks and enhance the overall security posture of cloud services.
Monitor environments for security incidents and anomalies. Lead the response to security breaches or attacks, coordinating efforts to contain and resolve incidents while minimizing impact.
Collaborate with various business units, ensuring adherence to security policies and procedures.
Advanced Scripting. Expertise in Python or Bash for parsing complex logs, automating data collection during forensics, and integrating disparate security APIs.
SOC Mentorship. Serve as a subject matter expert (SME) for junior analysts, developing training materials and conducting tabletop exercises to improve team readiness.
Requirements:
Bachelor’s degree in information security, information systems, or similar preferred
Relevant industry certification in information security, management information systems security or similar preferred
Minimum 2+ years experience in information security and Technology or related role
AWS Cloud Security: Proficient in Amazon Web Services (AWS) cloud environments, including managing security groups, IAM roles, and other security relevant aspects of AWS. Skilled in implementing best practices for AWS security, automating deployments, and optimizing cloud resources for security and efficiency.
Elastic Search SIEM Expertise: Demonstrates in-depth knowledge and hands-on experience with Elastic Search as a Security Information and Event Management (SIEM) tool within a SOC environment. Skilled in configuring and customizing Elastic Search for optimal log collection, analysis, and real-time monitoring of security events.
Advanced Threat Investigation Skills: Proficient in conducting in-depth investigations of cyber threats within cloud environments. Skilled in analyzing security logs, network traffic, and system behaviors to identify and understand the nature of potential security incidents. Capable of using various forensic tools and techniques to trace the source of threats and recommend mitigation strategies.
SOC Alert Expertise: Experienced in optimizing SOC alerts for cloud-based infrastructures. Skilled in configuring and fine-tuning alerting systems to minimize false positives while ensuring critical threats are identified and escalated promptly. Understands the nuances of different cloud environments and tailors alerting mechanisms accordingly.