Overview
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer - CSIRT based in Brazil.
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer - CSIRT based in Brazil. As a Senior Security Engineer - CSIRT, you will serve as a key technical leader during critical cybersecurity incidents, guiding response efforts from detection through recovery. You will lead complex Level 2 and Level 3 incidents across a high-availability environment, making informed containment and eradication decisions under pressure. The role combines incident response, digital forensics, threat hunting, threat intelligence, and security automation. You will work closely with 24/7 SOC teams, MSSPs, and stakeholders across legal, privacy, communications, and cybersecurity functions. Your investigations will help uncover root causes, assess compromise scope, and turn incidents into actionable intelligence. You will also strengthen playbooks, detection capabilities, and automated response processes to continuously improve the organization’s security posture. The position follows a remote-first model, with the flexibility to work from anywhere in Brazil or from designated offices and coworking spaces.
Act as the primary technical point of contact for Level 2 and Level 3 security incidents, leading response efforts across complex and high-criticality environments. Coordinate incident response activities with MSSPs and 24/7 SOC teams, ensuring operational quality, alignment, and continuous improvement. Collaborate rapidly with multicultural teams and multiple business functions, including Legal, Data Protection, Communications, and cybersecurity teams, throughout security incidents. Develop, maintain, and continuously improve Incident Response playbooks, procedures, and workflows, incorporating automation wherever possible. Lead Digital Forensics and Incident Response activities, including investigation of root causes, assessment of compromise scope, evidence analysis, and post-incident reviews. Drive post-mortem processes by facilitating technical discussions, documenting findings, and translating incidents into actionable improvements. Apply advanced threat detection expertise to create, tune, and enhance detection rules across SIEM and EDR platforms. Manage the full Cyber Threat Intelligence lifecycle, transforming threat data into actionable intelligence that strengthens SOC operations and defensive capabilities. Partner with Tier 1 and Tier 2 vendors to optimize operational routines, improve service delivery, and maximize the value of security contracts. Requirements: At least 5 years of professional experience focused on Incident Response, Digital Forensics, or Threat Hunting. Strong hands-on expertise in Digital Forensics and Incident Response, including the preservation, collection, acquisition, and analysis of digital evidence. Experience investigating systems and networks across Windows, Linux, and macOS environments. Proficiency with memory forensics and host-based forensic tools. Ability to conduct basic static and dynamic malware analysis to identify Indicators of Compromise (IoCs) and understand malicious capabilities. Proven experience leading incident response activities in cloud environments, particularly AWS and GCP. Practical experience with Security Orchestration, Automation and Response (SOAR), including developing automated workflows that improve incident response efficiency. Strong risk assessment and prioritization skills, with the ability to allocate resources and make effective decisions during high-pressure situations. Excellent communication and leadership abilities, including the capacity to clearly explain technical findings to both technical specialists and executive stakeholders. Benefits: Competitive salary. Profit-sharing opportunities. Meal allowance. Health insurance. Dental plan. Life insurance. Childcare subsidy and atypical parenthood subsidy. Wellhub membership. Home office allowance. Employee assistance program covering mental health, social, legal, and financial support. Extended parental leave. Day off for your birthday, Mother’s Day, and Father’s Day. Benefits Club with discounts on everyday services. Discounts at educational institutions. Reading kit for children through PlayKids. Remote-first work model, with the option to work from anywhere in Brazil. Access to São Paulo offices or partner coworking spaces up to twice per week.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from jobgether (lever) →