Agility

Information Security Analyst, Senior – SIEM Administration

Agility

full-time

Posted on:

Location Type: Remote

Location: Brazil

Visit company website

Explore more

AI Apply
Apply

Job Level

About the role

  • Administer, maintain, and evolve the Palo Alto XSIAM and Wazuh platforms, ensuring availability, performance, and adherence to best practices.
  • Design, develop, and maintain integrations and log ingestion pipelines, defining quality, normalization, and retention standards.
  • Design and implement advanced use cases, detection and correlation rules, with a focus on effectiveness and continuous reduction of false positives.
  • Design, develop, and maintain playbooks, runbooks, and automations in SIEM/SOAR environments.
  • Lead investigations and responses to high-complexity incidents, including containment, root cause analysis, and improvement recommendations.
  • Provide technical leadership to the SOC during critical incidents, acting as a focal point and mentoring less-experienced analysts.
  • Propose and implement architectural, process, and automation improvements to elevate the organization’s cyber maturity.
  • Define and track security KPIs and indicators, producing technical and executive reports.
  • Serve as an internal technical reference on topics related to SIEM, XDR, and security automation.

Requirements

  • Proven experience (minimum 4 years) in administration and evolution of SIEM/SOAR.
  • Hands-on experience with Palo Alto XSIAM and/or Wazuh in production environments.
  • Proficiency in Python, scripting, and designing automations for security.
  • Solid knowledge of Regex and log manipulation.
  • Proficiency in Linux and Windows.
  • Proven experience in Incident Response, including handling critical incidents.
  • Strong knowledge of EDR/XDR and their integration with SIEM.
  • Experience with integrations via APIs, alert enrichment, and advanced automations.
  • Experience with Cloud Security (AWS, Azure, or GCP).
  • Knowledge of frameworks such as MITRE ATT&CK and NIST 800-53.
  • Familiarity with standards like NIST CSF, ISO 27001, OWASP, and security controls.
  • English for handling vendor support tickets.