Information Security Incident Response Specialist
Position Description
We are seeking an Information Security Incident Response Specialist with strong expertise in Fusion Center operations, DFIR (Digital Forensics and Incident Response), and Digital Forensics to lead deep technical investigations, respond to critical incidents, and support strategic decision-making during cyber crisis scenarios.
This role is essential to ensure advanced detection, coordinated response, detailed forensic analysis, and continuous improvement of the security posture, working in an integrated manner across SOC, Threat Intelligence, Cloud Security, Vulnerability Management, Identity and Access, Business units, and other corporate areas.
Key Responsibilities
Incident Response & DFIR
- Lead incident response for medium and high-severity security incidents, such as:
- Ransomware;
- Advanced intrusions;
- Data breaches;
- Account compromise;
- Insider threats.
- Operate throughout the entire DFIR lifecycle:
- Preparation;
- Identification;
- Containment;
- Eradication;
- Recovery;
- Lessons learned.
- Coordinate technical investigations to identify:
- Root cause;
- Scope;
- Impact;
- Attack timeline.
- Support incidents with potential regulatory, legal, or reputational impact.
Digital Forensics
- Perform forensic analysis on:
- Endpoints;
- Servers;
- Memory;
- Network;
- Cloud environments.
- Collect, preserve, and analyze digital evidence following chain of custody and forensic best practices.
- Analyze attack artifacts, including:
- Malware;
- Scripts;
- Logs;
- Memory dumps;
- Disk images.
- Support audit, legal, and privacy (LGPD) requirements.
Fusion Center
Serve as a technical reference within the Fusion Center model, integrating information from:
- SOC (SIEM, SOAR, EDR/XDR, and NDR);
- Threat Intelligence;
- Vulnerability Management;
- Cloud Security and IAM;
- Fraud, OT, and other relevant domains.
Additionally:
- Correlate events, indicators, and TTPs to develop attack hypotheses and provide contextual risk visibility.
- Conduct Threat Hunting activities driven by intelligence and adversary behavior.
Processes, Playbooks & Governance
- Develop, maintain, and evolve incident response playbooks and runbooks.
- Support simulation exercises, including:
- Tabletop Exercises;
- Purple Team exercises;
- Incident Drills.
- Produce technical and executive reports tailored to different audiences.
- Contribute to advancing security maturity, processes, and defensive architecture.
Information Classification
This document contains RESTRICTED information. Its content is intended exclusively for authorized stakeholders within the specific context and process in which it is shared. If the content is modified or shared outside its original context, the information's sensitivity classification must be re-evaluated.