Tech Stack
AWSAzureDNSGoogle Cloud PlatformPythonSMTPSplunkTCP/IP
About the role
- Monitor security events and alerts in SIEM, EDR, XDR, and other monitoring solutions
- Conduct investigations of security incidents, from initial triage through containment, eradication, and recovery
- Respond to critical incidents in a structured manner, applying incident response methodologies
- Support the development and maintenance of SOC and CSIRT playbooks, runbooks, and procedures
- Perform threat hunting and forensic analysis on systems, networks, and endpoints
- Work with infrastructure, applications, and business teams to identify vulnerabilities and reduce risk
- Produce technical and executive incident reports, including lessons learned and recommendations for improvement
- Contribute to the maturity growth of the SOC and CSIRT by proposing automations, integrations, and process improvements
Requirements
- Experience in security operations, incident response, or monitoring centers (SOC/NOC)
- Knowledge of SIEM solutions (Microsoft Sentinel, Splunk, QRadar, Elastic, etc.), EDR/XDR (CrowdStrike, SentinelOne, Microsoft Defender, etc.), and log analysis
- Familiarity with network protocols (TCP/IP, DNS, HTTP, SMTP) and traffic analysis tools (Wireshark, Zeek)
- Knowledge of attack and defense techniques (MITRE ATT&CK, Kill Chain, IOC/IOA)
- Experience managing and responding to cybersecurity incidents
- Additionally, the following are a plus:
- Security certifications (GCIA, GCIH, CEH, CompTIA Security+, Microsoft SC-200, etc.)
- Experience with SOC automation (SOAR, scripting in Python/PowerShell)
- Experience with cloud environments (AWS, Azure, GCP, OCI) and container security
- Experience in Red Team, Blue Team, or Purple Team projects
- Ability to work in regulated corporate environments (financial sector, payment systems, PCI, LGPD - Brazilian data protection law)
- Profit Sharing Program (PPR)
- Health insurance (Bradesco - co-payment)
- Optional dental coverage (Bradesco)
- Life insurance (Banco do Brasil)
- Optional private pension plan (You may contribute up to 7.8% of salary; Elo's contribution ranges from 100% to 200% according to plan rules)
- Meal/food allowance of R$1,800.00
- R$150.00 flexible balance to use on credit function
- Holiday card of R$750.00
- Home office allowance of R$200.00 for hybrid model and R$300.00 for remote model
- Mobility allowance of R$400.00
- Free parking
- Childcare assistance for parents
- Culture allowance (benefit to be used for theater, cinema, or bookstores)
- Extended parental leave (for same-sex couples, fathers, adoptive parents, etc.)
- Birthday day off
- Zenklub (psychotherapy – up to 4 sessions per month fully covered by Elo)
- WellHub and TotalPass (network of gyms and studios for sports and fitness activities)
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
SIEMEDRXDRthreat huntingforensic analysisincident responselog analysisnetwork protocolsattack techniquesdefense techniques
Soft skills
incident managementstructured responsecommunicationcollaborationproblem-solving
Certifications
GCIAGCIHCEHCompTIA Security+Microsoft SC-200