Hybrid Cybersecurity Specialist – Blue Team, Cyber Operations

Posted 2 months ago

Apply now

About the role

  • Cybersecurity Specialist ensuring operational safety and responding to threats at RD Saúde's cyber environment. Focused on improving security processes and team collaboration.

Responsibilities

  • Anticipate internal and external attack scenarios.
  • Support the evolution of the environment's defensive technologies, being proactive and hands-on.
  • Investigate incident origins and follow up on resolution with internal teams.
  • Improve internal processes and communication with partner areas.
  • Support executive presentations.
  • Develop KPIs.
  • Provide close support to the team.
  • Maintain strong interaction and partnership with vendors (vendor management focused on delivery quality).
  • Proactive, challenging mindset with a sense of urgency and self-taught learning.
  • Continuously improve defensive and monitoring layers, supporting development, integrations, etc.
  • Recommend and apply best practices for data protection and threat reduction in a complex, high-criticality environment.
  • Ensure the proper operation and integration of the Blue Team and Cybersecurity Operations area (CSIRT - 24/7).
  • Guide the continuous improvement of security controls implemented in the environment, prioritizing optimization and continuous improvement.
  • Ensure the confidentiality, availability, integrity and resilience of the environments under your responsibility.
  • Ensure the Incident Response process is developed to meet all applicable regulatory requirements.
  • Manage vendors and partners, ensuring compliance with quality requirements and SLAs.
  • Develop advanced capabilities for detection and response to cyber incidents.
  • Consistently enhance the environment's monitoring, detection and response capabilities.
  • Technically develop the internal team, maintaining a sense of urgency and organization aligned with company expectations.
  • Manage and direct projects that improve the cyber maturity level of the environment, meeting defined scope and deadlines.
  • Ensure all Access Management processes follow market best practices, guaranteeing timely deliveries and SLAs.
  • Security Operations Center (SOC) operations: 24/7 incident management with direct interaction in SIEM solutions such as Splunk/Google SecOps, and collaboration with CSIRT teams for fast and effective incident response.
  • Responsible for formulating and implementing incident response plans and ensuring security throughout the lifecycle of the company's systems.
  • Antimalware and EDR/XDR management:
  • Implement and monitor advanced detection and response solutions for endpoints, focusing on EDR and XDR, including strong skills in extracting malicious features and familiarity with Yara rules and TTP analysis.
  • Cloud security: identify and implement best practices and standards in AWS and Azure cloud environments, using tools such as SecurityHub, GuardDuty, Cloud App Security and Advanced Threat Analytics for monitoring and risk mitigation.
  • Deep knowledge of security operations, perimeter defense, insider threats and risk management.
  • Develop and implement robust security architectures: design and integrate security solutions across the IT infrastructure, including networks, systems and cloud environments, ensuring proactive protection against cyber threats.

Requirements

  • Bachelor's degree (completed).
  • Knowledge/experience in cloud security management (AWS, Azure, OCI, GCP).
  • Broad knowledge of operating systems and containers.
  • PowerShell and Shell (Unix).
  • Ability to develop integrations.
  • Knowledge of Information Security Architecture.
  • Tools and frameworks: NGFW (Fortinet and Check Point), IDS/IPS, DLP, CASB, MDM, IAM, EDR, WAF, SIEM, CIS Controls, ISO 27001.
  • Database and server hardening.
  • Experience in cloud and hybrid environments.
  • Solid knowledge of network topologies, TCP/IP, firewalls and VPNs.
  • Solid knowledge of Active Directory environments and databases.
  • Security tools, standards and best practices.

Benefits

  • Performance-based Profit Sharing (PPR).
  • Health insurance.
  • Dental insurance.
  • On-site cafeteria.
  • Life insurance.
  • Transportation allowance.
  • Pharmacy benefit (Univers).
  • Partnerships with third-party companies (New Value).
  • Gym allowance (Wellhub).
  • Christmas hamper.
  • Career development track.
  • Extended maternity and paternity leave.

Job title

Cybersecurity Specialist – Blue Team, Cyber Operations

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job