Nava Technology for Business Logo

English

EN

Nava Technology for Business

Information Security Incident Response Specialist

Show original

On-site

São Paulo, SP, Brazil

Salary Range

Not informed

Full Time Employee

Experience Level

Senior

Requirements

5+ years of experience in the career

Desired Skills

Segurança da informação

Tasks and Responsibilities

Show original

Information Security Incident Response Specialist

Position Description

We are seeking an Information Security Incident Response Specialist with strong expertise in Fusion Center operations, DFIR (Digital Forensics and Incident Response), and Digital Forensics to lead deep technical investigations, respond to critical incidents, and support strategic decision-making during cyber crisis scenarios.

This role is essential to ensure advanced detection, coordinated response, detailed forensic analysis, and continuous improvement of the security posture, working in an integrated manner across SOC, Threat Intelligence, Cloud Security, Vulnerability Management, Identity and Access, Business units, and other corporate areas.

Key Responsibilities

Incident Response & DFIR

  • Lead incident response for medium and high-severity security incidents, such as:
    • Ransomware;
    • Advanced intrusions;
    • Data breaches;
    • Account compromise;
    • Insider threats.
  • Operate throughout the entire DFIR lifecycle:
    • Preparation;
    • Identification;
    • Containment;
    • Eradication;
    • Recovery;
    • Lessons learned.
  • Coordinate technical investigations to identify:
    • Root cause;
    • Scope;
    • Impact;
    • Attack timeline.
  • Support incidents with potential regulatory, legal, or reputational impact.

Digital Forensics

  • Perform forensic analysis on:
    • Endpoints;
    • Servers;
    • Memory;
    • Network;
    • Cloud environments.
  • Collect, preserve, and analyze digital evidence following chain of custody and forensic best practices.
  • Analyze attack artifacts, including:
    • Malware;
    • Scripts;
    • Logs;
    • Memory dumps;
    • Disk images.
  • Support audit, legal, and privacy (LGPD) requirements.

Fusion Center

Serve as a technical reference within the Fusion Center model, integrating information from:

  • SOC (SIEM, SOAR, EDR/XDR, and NDR);
  • Threat Intelligence;
  • Vulnerability Management;
  • Cloud Security and IAM;
  • Fraud, OT, and other relevant domains.

Additionally:

  • Correlate events, indicators, and TTPs to develop attack hypotheses and provide contextual risk visibility.
  • Conduct Threat Hunting activities driven by intelligence and adversary behavior.

Processes, Playbooks & Governance

  • Develop, maintain, and evolve incident response playbooks and runbooks.
  • Support simulation exercises, including:
    • Tabletop Exercises;
    • Purple Team exercises;
    • Incident Drills.
  • Produce technical and executive reports tailored to different audiences.
  • Contribute to advancing security maturity, processes, and defensive architecture.

Information Classification

This document contains RESTRICTED information. Its content is intended exclusively for authorized stakeholders within the specific context and process in which it is shared. If the content is modified or shared outside its original context, the information's sensitivity classification must be re-evaluated.
See all jobs at Nava Technology for Business

Share job:

Share job: