Security Analyst - Blue Team / SecOps

full timeotherremote FROM 🇧🇷
Open to candidates in: Brazil
Jobgether
🏭 Not specified
📍 N/A
👤 Not specified

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Analyst - Blue Team / SecOps based in Brazil.

This role offers the opportunity to strengthen cybersecurity operations within a fast-growing technology environment, protecting digital products and customer data at scale.
The professional will be responsible for monitoring, investigating, and responding to security events while helping mature incident response processes.
You will work across cloud security, threat detection, forensic analysis, and operational security improvements.
The position combines technical investigation, proactive threat prevention, and collaboration with multiple teams to reduce risks effectively.
You will contribute to building security frameworks, automation practices, and response strategies that improve organizational resilience.
This is an opportunity for a security professional who enjoys solving complex challenges, acting with ownership, and continuously improving security operations.


Accountabilities:

The Security Analyst will support the protection of systems and infrastructure by monitoring threats, investigating incidents, and improving security processes. The role requires strong analytical thinking, operational discipline, and the ability to communicate effectively during security events.

  • Monitor security alerts, triage events, and conduct initial investigations of potential security incidents.
  • Perform initial forensic analysis, including evidence preservation, timeline creation, and identification of attack vectors.
  • Manage the post-incident lifecycle, including root cause analysis, lessons learned, and tracking corrective actions.
  • Monitor security operation metrics such as MTTD, MTTR, alert volume, and false-positive rates.
  • Build, maintain, and improve incident response plans, playbooks, and operational runbooks.
  • Configure and operate centralized logging solutions to support detection and investigation activities.
  • Support security audits by organizing evidence and contributing to the continuous improvement of security maturity.
  • Participate in phishing simulation programs and security awareness initiatives.
  • Identify opportunities to improve detection capabilities, response automation, and operational efficiency.
  • Requirements:

    The ideal candidate is a security professional with hands-on experience in blue team operations, incident response, cloud security, and threat analysis. The role requires technical expertise combined with strong communication and problem-solving abilities.

    • Practical experience with AWS security services, including CloudTrail, GuardDuty, CloudWatch, VPC Flow Logs, and AWS Config.
    • Experience applying incident response frameworks such as NIST Incident Response, SANS PICERL, or equivalent methodologies.
    • Ability to perform initial forensic analysis, including evidence collection, log analysis, and incident timeline reconstruction.
    • Experience creating practical playbooks and runbooks for security operations.
    • Familiarity with MITRE ATT&CK techniques and the ability to identify indicators of compromise through logs and alerts.
    • Ability to communicate incident status clearly to both technical and executive audiences.
    • Strong sense of urgency and efficiency when responding to security events.
    • Critical thinking, investigative mindset, and attention to detail.
    • Proactive approach to identifying threats and improving security posture.
    • Ability to collaborate effectively with multidisciplinary teams.
    • Strong operational discipline and commitment to documentation and process completion.
    • Nice-to-have qualifications:

      • Experience with SIEM platforms such as Splunk, Elastic SIEM, Microsoft Sentinel, or similar solutions.
      • Familiarity with SOAR platforms and incident response automation.
      • Knowledge of threat intelligence practices and IOC-based monitoring.
      • Experience working with external security partners.
      • Understanding of insider threat detection and abnormal user behavior analysis.
      • Experience with network traffic analysis and packet capture tools.
      • Relevant certifications such as:
        • AWS Certified Security - Specialty.
        • GCIH (GIAC Certified Incident Handler).
        • Blue Team Level 1 (BTL1).
        • CompTIA CySA+.
        • Benefits:

          • PJ contract model.
          • 30 days of paid rest after eligibility period.
          • Health insurance fully covered after six months for PJ professionals.
          • Dental insurance after six months.
          • Life insurance.
          • Complete equipment kit provided.
          • Home office allowance of R$180/month.
          • Birthday month day off.
          • Gym membership discounts.
          • Flexible dress code environment.
          • Extended maternity and paternity leave.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether?    Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.     #LI-CL1
Jobgether
🏭 Not specified
📍 N/A
👤 Not specified