
Senior Information Security Analyst
Rox Partner
full-time
Posted on:
Location Type: Remote
Location: Brazil
Visit company websiteExplore more
Job Level
About the role
- Implement, administer and enhance PAM solutions (CyberArk), ensuring privileged access control and protection of critical credentials.
- Manage privileged accounts, password vaults and access policies, with integration to Active Directory (AD) and other corporate systems.
- Administer and optimize Fortinet Firewalls (FortiGate), including rule creation, review and troubleshooting.
- Operate and advance XDR and SIEM solutions (Palo Alto – Cortex XDR / Data Lake), including alert tuning and development of use cases.
- Investigate and respond to security incidents, perform root cause analysis and propose continuous improvements.
- Structure and execute vulnerability assessment and management processes, prioritizing based on risk (CVSS) and tracking remediations.
- Perform hardening of Windows and Linux servers, ensuring compliance with security best practices.
- Monitor and analyze security logs and events in on-premises and cloud environments.
- Work with Brand Protection solutions (Rainforest or similar), identifying and mitigating threats such as phishing and brand abuse.
- Define, implement and evolve information security policies, standards and procedures.
- Support audits and compliance initiatives (ISO 27001, LGPD, among others).
- Act as a consultant to business and technology teams, promoting a security culture and risk management.
Requirements
- Solid experience in Information Security, with work in complex corporate environments.
- Hands-on experience implementing and supporting solutions such as CyberArk (PAM), Fortinet (FortiGate) and Palo Alto (XDR / SIEM), from configuration to troubleshooting and environment evolution.
- Advanced knowledge of Active Directory (AD) and identity management.
- Strong networking knowledge (TCP/IP, VPN, segmentation and firewall policies).
- Experience with vulnerability assessment tools and processes.
- Experience in security incident response, with investigative and corrective actions.
- Experience hardening Windows and Linux servers.
- Knowledge in security log monitoring and analysis.
- Nice to have: Experience with Brand Protection (Rainforest or similar).
- Experience with cloud environments (AWS, Azure or GCP).
- Knowledge of automation (Python, PowerShell).
- Experience with security frameworks (NIST, CIS Controls, ISO 27001).
Benefits
- Remote work – Monday to Friday (09:00 to 18:00).
- Home-office allowance – Meal/food credit on an iFood card of R$ 300.00 per month.
- Birthday – On your special day, Rox gives you a gift voucher and a day off to enjoy.
- Courses – Full access via RoxSchool, Alura, Pluralsight, O’Reilly for books and talks, and RoxSchool.
- Certifications – Certification reimbursement up to R$300.00 (TECHNOLOGY) + a R$300.00 bonus per certification achieved from these providers.
- Psychological support – Two psychotherapy sessions covered monthly by ROX with partner psychologists.
- Feedz partnership – A gamified platform to improve communication and track sentiment, engagement, feedback, Individual Development Plans (PDI) and performance.
- WellHub (Gympass) – Partnership with gyms and health & wellness apps.
- We provide the work equipment.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
CyberArkFortinetPalo AltoActive DirectoryTCP/IPVPNPythonPowerShellvulnerability assessmentsecurity incident response
Soft Skills
consultingrisk managementcommunicationproblem-solvinganalytical thinking
Certifications
ISO 27001NISTCIS Controls