Skip to content

Open nowPosted 12 hours ago

Analista de Threat Hunting / SIEM

Gupy (Portal de Vagas)78,145 open roles

Where
São Paulo, Brazil
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAnalista de Threat Hunting / SIEMGupy (Portal de Vagas) · São Paulo, Brazil
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Gupy (Portal de Vagas)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Gupy (Portal de Vagas) postings stay open a median of 3 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 12 hours ago

Gupy (Portal de Vagas) median: 3 days open

The posting

No Grupo Stefanini, acreditamos no poder da colaboração. Co-criamos soluções inovadoras em parceria com nossos clientes, combinando tecnologia de ponta, inteligência artificial e a criatividade humana. Estamos na vanguarda da resolução de problemas de negócios, proporcionando impacto real em escala global.Ao se juntar à Stefanini, você se torna parte de uma jornada global de transformação. Estamos empenhados em criar impacto positivo não apenas nos negócios, mas também na vida de nossos colaboradores. Se você procura uma oportunidade de crescimento profissional em uma empresa que valoriza inovação, respeito, autonomia e parceria, você encontra aqui!Junte-se a nós e seja parte da mudança!(LI-HYBRID)(LI-RL1)Responsabilidades e atribuiçõesBuscamos um(a) profissional de Threat Hunting com forte atuação em ambientes de SIEM, com foco principal em Microsoft Sentinel, Microsoft Defender e Google SecOps.O profissional fará parte da operação de Cyber Security, atuando de forma proativa na identificação de comportamentos suspeitos, ameaças avançadas e possíveis comprometimentos que não tenham sido detectados pelos mecanismos tradicionais de monitoramento.Principais responsabilidades- Realizar atividades de Threat Hunting em ambientes corporativos, buscando comportamentos anômalos, indicadores de comprometimento e atividades maliciosas.- Desenvolver e executar hipóteses de Hunting com base em:  - TTPs de atacantes;  - MITRE ATT&CK;  - Threat Intelligence;  - incidentes anteriores;  - vulnerabilidades;  - comportamento de usuários e ativos.- Atuar diretamente com Microsoft Sentinel, Microsoft Defender e Google SecOps.- Criar, revisar e aprimorar consultas para investigação utilizando linguagens como:  - KQL – Kusto Query Language;  - YARA-L / regras e consultas do Google SecOps.- Correlacionar eventos provenientes de endpoints, identidade, cloud, firewall, proxy, Active Directory, Microsoft 365 e outras fontes de segurança.- Identificar possíveis gaps de detecção e trabalhar em conjunto com a equipe de Engenharia de SIEM para criação ou melhoria de regras.- Apoiar investigações de incidentes em conjunto com SOC, CSIRT e demais áreas de Cyber Security.- Documentar hipóteses, evidências, resultados e recomendações das atividades de Hunting.- Apoiar a criação e evolução de casos de uso, playbooks e procedimentos de resposta.- Avaliar alertas e incidentes recorrentes para identificar oportunidades de melhoria nas regras de detecção.- Utilizar informações de Threat Intelligence para direcionar campanhas de Hunting.- Propor novos indicadores, técnicas de detecção e melhorias contínuas para o ambiente de monitoramento.- Acompanhar tendências de ataques, vulnerabilidades e técnicas utilizadas por grupos de ameaça.

Requisitos e qualificações Buscamos uma pessoa com perfil analítico, investigativo e proativo, capaz de ir além dos alertas gerados pelo SIEM.O profissional deve ter capacidade de formular hipóteses, correlacionar diferentes fontes de dados e transformar descobertas de Hunting em melhorias efetivas de detecção e resposta dentro do SOC.Também é importante possuir boa comunicação e capacidade de trabalhar de forma integrada com os times de Monitoramento, Engenharia de SIEM, Threat Intelligence e CSIRT.Conhecimentos técnicos desejados- Experiência prática com SIEM. - Experiência com Microsoft Sentinel. - Experiência com Microsoft Defender, incluindo conhecimentos em:   - Defender for Endpoint;   - Defender for Identity;   - Defender for Office 365;   - Microsoft Entra ID. - Experiência ou conhecimento em Google SecOps / Google Security Operations. - Conhecimento em KQL. - Conhecimento em investigação e correlação de logs. - Conhecimento em MITRE ATT&CK. - Conhecimento de técnicas de ataque e pós-exploração, como:   - Credential Access;   - Persistence;   - Lateral Movement;   - Privilege Escalation;   - Command and Control;   - Data Exfiltration. - Conhecimento de ambientes Windows e Active Directory. - Conhecimentos de redes, protocolos TCP/IP, DNS, HTTP/HTTPS e autenticação. - Capacidade de investigação de eventos relacionados a endpoint, identidade, cloud e rede.Diferenciais- Experiência em SOC, CSIRT ou DFIR. - Conhecimento em Threat Intelligence. - Conhecimento em MISP. - Experiência com criação e tuning de regras de correlação. - Conhecimentos em Python ou PowerShell para automações. - Experiência com resposta a incidentes. - Certificações Microsoft Security, Google Cloud Security ou similares.Informações adicionais🍛 Vale-alimentação ou vale-refeição;👨🏼‍🎓 Desconto em cursos, universidades e instituições de idiomas;📚 Academia Stefanini — plataforma com cursos on-line, gratuitos, atualizados e com certificado;🗣 Mentoring;💉 Clube de vantagens para consultas e exames;🏥 Assistência médica;🦷 Assistência odontológica;💰 Clube de vantagens e descontos nos melhores estabelecimentos;🛫 Clube de viagens;🐶 Convênio para pets.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Gupy (Portal de Vagas)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Gupy (Portal de Vagas)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Gupy (Portal de Vagas)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.