Hybrid
São Paulo, SP, Brazil
Salary Range
Not informed
Experience Level
Senior
Requirements
Tasks and Responsibilities
Show originalPosition Description
We are seeking a CSIRT Specialist with a strongly hands-on profile, responsible for acting
directly in alert analysis, continuous threat hunting, technical investigation, and practical identification
of security gaps, transforming operational findings into concrete improvements in
detection, response, and protection.
The focus of the role is to operate, investigate, hunt threats, and tune the environment, utilizing security
tools on a daily basis, with a critical view of what is not being detected, where
controls fail, and how to evolve defense based on real-world operations.
Key Responsibilities
Hands-on Analysis of Alerts & Incidents
• Analyze alerts from SIEM, EDR/XDR, NDR, Cloud, and Identity in depth, going beyond
basic triage.
• Investigate suspicious behaviors directly in logs, endpoints, identity, and network.
• Perform technical pivoting across multiple data sources to confirm or rule out
malicious activity.
• Handle incident investigations of low, medium, and high complexity with a technical focus.
Continuous Threat Hunting
• Execute hands-on threat hunting based on:
o Attack hypotheses
o MITRE ATT&CK TTPs
o Analysis of recurring alerts and operational noise
• Identify:
o False negatives
o Non-existent or ineffective detections
o Identity, credential, and permission abuses
• Utilize queries, scripts, and tools to search for anomalous activities that did not generate
alerts.
Practical Identification of Gaps
• Identify real security gaps arising from daily operations, such as:
o Lack of visibility
o Missing or misconfigured logs
o Weak or generic detection rules
o Controls that do not work in practice
• Document gaps with technical evidence, real-world examples, and potential impact.
• Prioritize gaps based on exploitability and technical risk.
Technical Evolution of Detection and Response
• Create, adjust, and optimize:
o Detection rules
o SIEM queries
o EDR/XDR alerts
o Correlation logic
• Transform hunting and incident findings into:
o New detections
o Playbook adjustments
o Improved response times
• Test and validate detections against real-world attack scenarios.
CSIRT & Advanced Operations
• Serve as a technical reference within CSIRT operations.
• Support practical exercises (purple teaming, technical simulations).
• Produce objective technical reports focused on findings, gaps, and corrective actions.
Work collaboratively with SOC, Cloud, Infra, and IAM teams for the technical remediation of identified
issues.
Mandatory Technical Requirements
• Practical experience in CSIRT, SOC Level 2/3, or Threat Hunting.
• Strong hands-on involvement in technical investigation and alert analysis.
Proficiency in:
o SIEM (Splunk, Sentinel, QRadar, Elastic)
o EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)
o Practical application of MITRE ATT&CK
• Ability to write and adjust complex queries (KQL, SPL, Lucene, etc.).
• Experience analyzing:
o Authentication and identity logs
o Endpoint processes and artifacts
o Suspicious activity in cloud environments
• Solid knowledge of NIST 800-61 and CSIRT operational workflows.
Desirable Requirements
• Experience with:
o Structured Threat Hunting
o Purple Teaming
o Basic DFIR
• Knowledge in:
o Cloud Security (Azure, AWS, or GCP)
o IAM and Identity Threat Detection
• Automation and scripting (Python, PowerShell, Advanced KQL).
• Certifications such as:
o GCIH, GCED, GCIA
o Microsoft or Cloud security certifications
Behavioral Competencies
• Technical, curious, and investigative profile
• Ability to go "all the way" in analysis
• Attention to detail and critical thinking
• Objective communication based on evidence
• Autonomy to investigate and propose practical improvements
• Collaboration with technical teams
Position Differentiators
• 100% technical and operational role with direct impact on security
• Autonomy to hunt threats and improve detection
• Exposure to complex environments and real-world attack scenarios
• Direct influence on the practical evolution of the CSIRT
Share job:
Share job: