Job Overview
Job description
- Location:
- Brazil
- Work arrangement:
- On-site
Role Summary
Mission of the position
Operate Information Security controls with a focus on the day-to-day operation of the detection platform (SIEM) and perimeter asset management (NGFW), actively working on monitoring, log screening and initial incident response.
Operate and support the support of the SIEM platform, ensuring the correct collection of log sources, integrity and quality of data received.
Support the creation, review and fine-tuning of detection rules and use cases, aiming to reduce false positives and optimize alerts.
Operate and manage Next Generation Firewalls (NGFW): controlled implementation of access rules, NAT, VPNs, documentation of justifications and periodic review of orphaned rules.
Actively support network segmentation, traffic rules and perimeter hardening activities.
Monitor, classify and investigate security alerts generated by SIEM, firewalls and other perimeter tools.
Perform screening and initial analysis of perimeter security incidents, carrying out structured escalation to the Specialist when necessary.
Produce operational reports, traffic maps and security incident/blockage indicators.
Prepare and keep technical documentation of topologies, network flows and operational procedures (SOPs) updated.
Professional experience in Information Security, Networks, IT Infrastructure or related areas with a focus on security.
Hands-on experience in monitoring, log triage and routine operation of SIEM platforms.
Knowledge in operation and administration of Next Generation Firewalls (Check Point, Palo Alto, Fortinet or equivalent).
Solid and practical knowledge of TCP/IP networks, routing, network segmentation (VLANs, DMZs) and communication protocols.
Knowledge of detection rules, event correlation and log header analysis.
Knowledge of Windows and Linux environments.
Proven ability for technical analysis and diligence in documenting activities.
High analytical capacity, attention to detail and investigative profile.
Organization and discipline to follow change control processes (Change Management).
Good communication for interaction with infrastructure, telecom and external partners teams.
Proactivity and interest in continuous technical evolution in the SecOps area.
Requirements
Desirable
- Specific experience with Wazuh, Elastic Stack (ELK) or other Open Source SIEM platforms.
- Practical knowledge of detection rules mapped to the MITER ATT&CK framework.
- Basics of Identity Management (IAM) and Active Directory structure.
- Knowledge of the ISO/IEC 27001 and CIS Controls frameworks.
- Basic knowledge of scripting (Python, Bash or PowerShell) for automating log analysis.
- Initial certifications in Security or Networks (e.g.: Security+, CCNA, NSE 4 Fortinet, CCSA Check Point).
Benefits
What we offer Portobello Lovers
- Life insurance;
- Health and dental plan;
- Portobello University Corporate Platform;
- Participation in PPR Profits and Results;
- Discounts at pharmacies in the region;
- Private Pension;
- Union;
- Discount network - partnerships with various educational institutions;
- Discounts on purchases of Portobello products;
- Vacation Allowance;
- Portobello Mamma Assistance – for purchasing baby layette;
- Childcare assistance;
- Assistance for PWD dependents;
- Professional Training and Development Programs;
- Wellhub and many more!!!
- We await your registration to be #portobellolover 💙
- All of our vacancies are also aimed at people with disabilities
About the Company
LIVING DESIGN IS IN OUR DNA💙
For us, transforming environments and moving people is part of our life purpose, guiding our initiatives towards an increasingly human and sustainable future.
We are the leading brand in the Brazilian ceramic tiles market.
- Role:
- Full Information Security Analyst - Detection (SIEM) and Perimeter (NGFW)
- Job Type:
- Full Time