About the role
Job Description
* Serve as Tier 2 level for complex technical and Security incidents; * Investigate SOC and other security incidents and alerts generated MS Security portals (MS 365 Defender, MCAS, Azure Sentinel) following the company established processes and incidents response procedures; * Perform technical analysis from varied data sources (endpoint event logs, SIEM data, dashboards, enterprise applications), then develop and present coherent and reasoned next steps; * Proactively identify indicators of compromise and generate and execute Incident Response Plan upon detection; * Ensure excellent communication and collaboration with other teams (operations, legal, sales) to help identify / resolve chronic issues and assist with the creation and implementation of corrective / preventative action plans; * Research, analyze and identify potential vulnerabilities and security deficiencies; * Propose improvements and recommendations to increase visibility and effectiveness of security monitoring systems; * Initiate escalation procedure to counteract potential threats/vulnerabilities; * Validate Change request that are require a Security analyses and approval; * Investigate Phishing/SPAM e-mail messages and take containment actions to mitigate/prevent security breach; * Ensure LDC gets the right delivery performance and quality from third party. Take corrective actions whenever not the case; * Operate, maintain, and monitor the Security tools used.
Qualifications
* Bachelor’s degree in Computer Science, Information Systems, Engineering, or related field; * Professional work experience in the field of Information Security; * Broad understanding of key security concepts/principles (CIA, threats, vulnerabilities, and exploits) * Knowledge of Agile concepts; * Experience working with SOC, MCAS, MS Azure Sentinel, Defender and doing incident response is preferred; * ISC2 SSCP, ISC2 CCSP, Microsoft Azure-500, Microsoft SC-200, CompTIA CySA+ or equivalent certification is considered an advantage.
Additional Information
* Availability to work in a hybrid model (4x1) in São Paulo, SP; * As this position involves interaction with international stakeholders, we kindly ask that the resume be submitted in English.