
Information Security Analyst, Senior – SIEM Administration
Agility
full-time
Posted on:
Location Type: Remote
Location: Brazil
Visit company websiteExplore more
Job Level
About the role
- Administer, maintain, and evolve the Palo Alto XSIAM and Wazuh platforms, ensuring availability, performance, and adherence to best practices.
- Design, develop, and maintain integrations and log ingestion pipelines, defining quality, normalization, and retention standards.
- Design and implement advanced use cases, detection and correlation rules, with a focus on effectiveness and continuous reduction of false positives.
- Design, develop, and maintain playbooks, runbooks, and automations in SIEM/SOAR environments.
- Lead investigations and responses to high-complexity incidents, including containment, root cause analysis, and improvement recommendations.
- Provide technical leadership to the SOC during critical incidents, acting as a focal point and mentoring less-experienced analysts.
- Propose and implement architectural, process, and automation improvements to elevate the organization’s cyber maturity.
- Define and track security KPIs and indicators, producing technical and executive reports.
- Serve as an internal technical reference on topics related to SIEM, XDR, and security automation.
Requirements
- Proven experience (minimum 4 years) in administration and evolution of SIEM/SOAR.
- Hands-on experience with Palo Alto XSIAM and/or Wazuh in production environments.
- Proficiency in Python, scripting, and designing automations for security.
- Solid knowledge of Regex and log manipulation.
- Proficiency in Linux and Windows.
- Proven experience in Incident Response, including handling critical incidents.
- Strong knowledge of EDR/XDR and their integration with SIEM.
- Experience with integrations via APIs, alert enrichment, and advanced automations.
- Experience with Cloud Security (AWS, Azure, or GCP).
- Knowledge of frameworks such as MITRE ATT&CK and NIST 800-53.
- Familiarity with standards like NIST CSF, ISO 27001, OWASP, and security controls.
- English for handling vendor support tickets.