Cybersecurity Specialist ensuring operational safety and responding to threats at RD Saúde's cyber environment. Focused on improving security processes and team collaboration.
Responsibilities
Anticipate internal and external attack scenarios.
Support the evolution of the environment's defensive technologies, being proactive and hands-on.
Investigate incident origins and follow up on resolution with internal teams.
Improve internal processes and communication with partner areas.
Support executive presentations.
Develop KPIs.
Provide close support to the team.
Maintain strong interaction and partnership with vendors (vendor management focused on delivery quality).
Proactive, challenging mindset with a sense of urgency and self-taught learning.
Continuously improve defensive and monitoring layers, supporting development, integrations, etc.
Recommend and apply best practices for data protection and threat reduction in a complex, high-criticality environment.
Ensure the proper operation and integration of the Blue Team and Cybersecurity Operations area (CSIRT - 24/7).
Guide the continuous improvement of security controls implemented in the environment, prioritizing optimization and continuous improvement.
Ensure the confidentiality, availability, integrity and resilience of the environments under your responsibility.
Ensure the Incident Response process is developed to meet all applicable regulatory requirements.
Manage vendors and partners, ensuring compliance with quality requirements and SLAs.
Develop advanced capabilities for detection and response to cyber incidents.
Consistently enhance the environment's monitoring, detection and response capabilities.
Technically develop the internal team, maintaining a sense of urgency and organization aligned with company expectations.
Manage and direct projects that improve the cyber maturity level of the environment, meeting defined scope and deadlines.
Ensure all Access Management processes follow market best practices, guaranteeing timely deliveries and SLAs.
Security Operations Center (SOC) operations: 24/7 incident management with direct interaction in SIEM solutions such as Splunk/Google SecOps, and collaboration with CSIRT teams for fast and effective incident response.
Responsible for formulating and implementing incident response plans and ensuring security throughout the lifecycle of the company's systems.
Antimalware and EDR/XDR management:
Implement and monitor advanced detection and response solutions for endpoints, focusing on EDR and XDR, including strong skills in extracting malicious features and familiarity with Yara rules and TTP analysis.
Cloud security: identify and implement best practices and standards in AWS and Azure cloud environments, using tools such as SecurityHub, GuardDuty, Cloud App Security and Advanced Threat Analytics for monitoring and risk mitigation.
Deep knowledge of security operations, perimeter defense, insider threats and risk management.
Develop and implement robust security architectures: design and integrate security solutions across the IT infrastructure, including networks, systems and cloud environments, ensuring proactive protection against cyber threats.
Requirements
Bachelor's degree (completed).
Knowledge/experience in cloud security management (AWS, Azure, OCI, GCP).
Broad knowledge of operating systems and containers.
PowerShell and Shell (Unix).
Ability to develop integrations.
Knowledge of Information Security Architecture.
Tools and frameworks: NGFW (Fortinet and Check Point), IDS/IPS, DLP, CASB, MDM, IAM, EDR, WAF, SIEM, CIS Controls, ISO 27001.
Database and server hardening.
Experience in cloud and hybrid environments.
Solid knowledge of network topologies, TCP/IP, firewalls and VPNs.
Solid knowledge of Active Directory environments and databases.
Security tools, standards and best practices.
Benefits
Performance-based Profit Sharing (PPR).
Health insurance.
Dental insurance.
On-site cafeteria.
Life insurance.
Transportation allowance.
Pharmacy benefit (Univers).
Partnerships with third-party companies (New Value).
Gym allowance (Wellhub).
Christmas hamper.
Career development track.
Extended maternity and paternity leave.
Job title
Cybersecurity Specialist – Blue Team, Cyber Operations
Event Security Associate supporting corporate events and high - visibility functions in the United States. Responsible for conducting risk assessments and translating findings into security plans.
IT Security Specialist performing operational tasks on firewalls and security systems in Doha. Maintaining IT security measures, user configurations, and assessing network vulnerabilities.
Cloud Cybersecurity Engineer supporting multi - cloud environments for critical USAF missions. Designing, deploying, and maintaining security for AWS, Azure, Google, and Oracle Clouds.
Information Systems Security Engineer (ISSE) driving cybersecurity initiatives in the Digital Modernization Sector. Supporting A&A efforts and ensuring security compliance with federal requirements.
Intern supporting occupational safety and health initiatives at ALTEN Mexico. Assisting in risk management and promoting safe work environments through regulatory compliance and innovation.
Senior SAP Security Specialist working with SAP Security solutions on customer projects. Responsible for workshops and leading consultancy in SAP Security environments.
Cybersecurity Engineer ensuring the security of IT & OT systems at ArianeGroup. Collaborating with internal teams and overseeing compliance and protection measures.
Professional focused on Cloud Security solutions and DevSecOps at innovative tech consulting firm Leega. Implementing security for AWS services and integrating security analysis tools.