Job Overview
Job description
- Location:
- Brazil
- Work arrangement:
- On-site
Role Summary
Mission of the position
Operate Information Security controls with a focus on the Vulnerability Management cycle and the Identity and Access Management (IAM) operation, acting collaboratively in monitoring, screening and initial response to company incidents.
Execute the Vulnerability Management cycle: analysis of scan results, risk-based prioritization, coordination and monitoring of remediation with the responsible areas (Infrastructure, Systems, etc.).
Maintain, update and evolve operational indicators and remediation workbooks (agent coverage, criticality, correction SLA monitoring).
Operate Identity and Access Management (IAM) processes: provisioning, deprovisioning, granting privileges, periodic access review and support for MFA mechanisms.
Actively support corporate access review and segregation of duties (SoD) validation campaigns.
Monitor, classify and investigate alerts generated by security tools within your scope.
Perform initial screening and analysis of security incidents, carrying out structured escalation to the Specialist when necessary.
Produce periodic operational reports and safety indicators for your area of activity.
Develop and maintain technical documentation and standard operating procedures (SOPs) up to date.
Professional experience in Information Security, Infrastructure, Systems Administration or related areas with a focus on security.
Practical experience in the Vulnerability Management process and use of market scanning tools (Qualys, Tenable, Rapid7 or equivalent).
Solid knowledge of Active Directory, IAM, SSO and MFA solutions.
Hands-on experience monitoring and triaging alerts on SIEM platforms.
Knowledge of TCP/IP networks, segmentation and communication protocols.
Knowledge of basic administration of Windows and Linux environments.
Proven ability for technical analysis and diligence in documenting activities.
Strong analytical skills and meticulous attention to detail.
Organization, discipline and focus on executing standardized processes.
Good communication for daily interaction with technical teams and business areas.
Sense of responsibility and interest in continuous learning.
Requirements
Desirable
- Specific experience with Wazuh, Elastic Stack (ELK) or other Open Source SIEM platforms.
- Knowledge of the ISO/IEC 27001 and CIS Controls frameworks.
- Knowledge of LGPD applied to logs, identities and personal data protection in security tools.
- Basic knowledge of scripting (PowerShell, Bash or Python) to automate routine tasks.
- Initial certifications in Information Security (e.g.: Security+, CySA+, SC-900/SC-300 Microsoft).
Benefits
What we offer Portobello Lovers
- Life insurance;
- Health and dental plan;
- Portobello University Corporate Platform;
- Participation in PPR Profits and Results;
- Discounts at pharmacies in the region;
- Private Pension;
- Union;
- Discount network - partnerships with various educational institutions;
- Discounts on purchases of Portobello products;
- Vacation Allowance;
- Portobello Mamma Assistance – for purchasing baby layette;
- Childcare assistance;
- Assistance for PWD dependents;
- Professional Training and Development Programs;
Wellhub and many more!!!
About the Company
LIVING DESIGN IS IN OUR DNA💙
For us, transforming environments and moving people is part of our life purpose, guiding our initiatives towards an increasingly human and sustainable future.
We are the leading brand in the Brazilian ceramic tiles market.
- Role:
- Full Information Security Analyst - Vulnerability and Identity Management
- Job Type:
- Full Time