Job Overview
Job description
- Location:
- Brazil
- Work arrangement:
- On-site
Role Summary
Ensure the continuity, security and evolution of the information technology infrastructure, ensuring that physical and logical resources are always available, updated and aligned with the organization's operational needs, through efficient, preventive and innovative management.
- Configure and manage security policies on Linux operating systems, including access control, file permissions and firewall settings;
- Monitor event logs on Linux servers and stations to identify suspicious or anomalous activities;
- Apply patches and security updates to Linux systems, according to established guidelines;
- Implement hardening practices on Linux servers and stations, aligned with the organization's security standards;
- Carry out periodic compliance audits on Linux systems, verifying adherence to internal and regulatory security policies;
- Evaluate user permissions and privileges settings on Linux systems to identify deviations or excess access;
- Document security incidents related to the Linux environment and propose technical recommendations for mitigation;
- Collaborate with internal teams in investigating incidents involving Linux systems;
- Prepare technical reports on the security status of Linux systems and performance metrics of the tools used;
- Configure and maintain firewalls and other protection tools on Linux systems, such as iptables and UFW (Uncomplicated Firewall);
- Perform periodic scans to detect vulnerabilities on Linux servers and stations;
- Perform integrity audits of critical files and recording systems (logs) in Linux environments;
- Evaluate the use of privileged accounts and segregation of duties on Linux systems during audits;
- Implement and manage data encryption solutions on Linux systems, such as LUKS (Linux Unified Key Setup), to protect sensitive information;
- Evaluate and configure application control policies (SELinux/AppArmor) to prevent the execution of unauthorized software;
- Monitor and respond to security alerts generated by SIEM (Security Information and Event Management) tools specific to Linux environments;
- Implement and monitor security policies to protect critical services, such as SSH, LDAP and databases on Linux systems;
- Perform forensic analysis on compromised Linux systems to identify attack vectors and impacts;
- Evaluate and implement multi-factor authentication (MFA) solutions in Linux environments;
Develop resilient and secure architectures for Linux systems, including network segregation, load balancing and implementing granular controls to minimize attack surfaces;
Carry out simulations of advanced attacks, such as exploitation of zero-day vulnerabilities, privilege escalation techniques and lateral movement, to identify flaws and propose robust improvements;
Create and maintain custom scripts (in Bash, Python, or other languages) to automate tasks such as containing compromised endpoints, deactivating suspicious accounts, and removing malware;
Design and execute advanced ransomware attack prevention, detection and recovery strategies, including immutable backups, rapid restoration of critical systems and regular simulations of disaster scenarios;
Perform other activities related to information security and Linux environments, as required by the operation.
Requirements
EDUCATION
- Completed higher education in the area of Information Technology (IT).
PROFESSIONAL EXPERIENCE
- Experience in information security or Linux environments. The experience must be demonstrated through a Legal Entity contract or Work Card, which must include a start and end date for the activity.
CERTIFICATIONS/COURSES/TRAINING;
- ITIL 4 training, with a minimum workload of 12 (twelve) hours.
- Official ITIL 4 Foundation certification or higher
- Linux Professional Institute LPIC-3 Security certification.
Possess one of the following certifications
- ECSA (EC-Council Certified Security Analyst) or ◦ CySA+ (CompTIA Cybersecurity Analyst) or ◦ ECIH (EC-Council Certified Incident Handler) or
CSIH (Certified Specialist Incident Handler).
Benefits
- Hapvida, Bradesco or Unimed health plan (according to CCT values in the region);
- Hapvida Odonto or Bradesco Dental dental plan;
- Food or Meal Voucher;
- Life insurance 100% funded by Lanlink;
- Totalpass;
- Pharmacy Agreement;
- College Agreement;
- Corporate Education Platform;
- Welcome to the world baby kit;
Moodar Platform.
- Role:
- Information Security Administrator | Linux – Senior
- Job Type:
- Full Time