Information Security Analyst managing critical governance, risk, and compliance topics. Leading incident responses and security policy development in a hybrid work model.
Responsibilities
• Will be a point of reference for critical governance, risk, and compliance topics, working across the Plan, Attack and Defend pillars;
• Will handle sensitive projects, critical data, and demanding audits.
**Strategic and analytical:**
• Conduct risk analyses for new projects and systems;
• Develop and review security policies and procedures;
• Coordinate responses to critical incidents (technical and strategic perspective);
• Apply threat intelligence and propose countermeasures;
• Participate in implementing security within DevSecOps pipelines.
**Operational:**
• Tune and improve tools such as SIEM, DLP, and XDR;
• Perform security testing and forensic analysis;
• Track critical vulnerabilities from identification to remediation;
• Serve as the technical point of contact during audits and internal threat investigations.
**Leadership and development:**
• Mentor junior professionals in technical and strategic competencies;
• Contribute to continuous improvement projects within the security area;
• Deliver training and security awareness initiatives;
• Represent the security team in forums, committees, and technical meetings.
Requirements
• Bachelor's degree in Technology fields such as Information Security, Computer Science, Information Systems, or related areas;
• 3–5 years of experience in Information Security;
• Strong communication and interpersonal skills, with the ability to integrate teams and present results;
• Technical writing skills for creating advanced documents and corporate policies;
• Autonomy to make technical decisions and lead projects;
• Analytical profile with mentoring ability, strategic collaboration, and business awareness;
• Focus on continuous improvement and innovation.
***Hard skills:***
• Experience in On-premises environments and in AWS, Azure, or GCP;
• Experience with Docker, Kubernetes, and securing CI/CD (GitLab, Jenkins, SonarQube);
• Scripting/automation experience with Python, PowerShell, or Bash;
• Security best practices for REST/GraphQL APIs and Infrastructure as Code.
***Monitoring and Incident Response***
• Use of SIEM tools (e.g., Splunk, QRadar), SOAR (e.g., Cortex, Splunk SOAR), and XDR (e.g., CrowdStrike, Microsoft Defender);
• Experience with forensic analysis tools (e.g., FTK, Volatility) and vulnerability management (e.g., Nessus, Qualys);
• Familiarity with DLP, UEBA, NGFW firewalls, email security, CASB, and SSPM solutions.
***Threats and Testing***
• Knowledge of Threat Intelligence (e.g., MITRE ATT&CK, Mandiant);
• Execution or support of penetration tests (pentests) and Red Team simulations;
• Basic knowledge of reverse engineering and malware analysis (differential).
Professional N2 in Information Security executing projects and providing technical support at NetSecurity. Collaborating with São Paulo technical team to enhance cybersecurity processes.
Cyber Security Analyst at Equitable Bank responsible for cyber risk governance. Working in a hybrid environment in Toronto focusing on compliance and risk management.
Cybersecurity Analyst role at Sip providing secure development support for financial services. Involvement in offensive security activities and design software solutions.
Experienced Information Security Analyst investigating incidents and mentoring junior analysts in a collaborative environment. Position with a mission - centered organization to support information security operations.
Network Security Analyst leading response efforts during major security incidents while ensuring robust security operations at Comcast. Engaging in investigations and providing strategic recommendations for improvements.
Cyber Security Co - op at RBC analyzing data to detect threats and improve security measures. Collaborating in a dynamic team environment to build solutions for potential cyber threats.
Security Analyst at Digio responsible for Security by Design, identifying and managing risks in projects. Focus on secure architecture, threat modeling, and risk evaluation.
Information Security Analyst developing and managing security awareness training programs for global function. Reducing human - based risks through education and compliance adherence.
Join is seeking a Senior Cybersecurity Analyst for a hybrid quality - focused squad. Responsible for incident response and digital forensics in cybersecurity.