CEA logo
CEA

CEA is the exclusive distributor of JCB, Atlas Copco, Ditch Witch, & Dynapac equipment.

Senior Information Security Analyst – Architecture Focus

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 201-500Since 1981H1B SponsorCompany SiteLinkedIn

Location

Brazil

Posted

79 days ago

Salary

0

Seniority

Senior

Job Description

Senior Information Security Analyst – Architecture Focus

CEA

• Prepare technical diagrams, architecture documentation, and threat models; • Analyze system, application, and integration architectures from a security perspective; • Perform technical risk assessments and recommend security controls; • Design secure solutions for cloud, applications, and infrastructure; • Support development, infrastructure, and DevOps teams in implementing controls; • Assess security configurations (hardening, baselines, CIS Benchmarks); • Support audit, compliance, and vulnerability management processes; • Conduct threat modeling, risk analysis, and provide recommendations for internal systems and third-party vendors; • Advanced knowledge of OWASP Top 10, CWE, NIST, and security standards; • Experience performing security-focused code reviews to assist development teams in remediating vulnerabilities; • Develop scripts and automations for vulnerability analysis and mitigation;

Job Requirements

  • Solid experience as an Information Security Analyst;
  • Experience in Cloud Security (AWS, Azure, or GCP);
  • Hands-on experience in application and API security (OWASP Top 10);
  • Practical experience with network controls, WAFs, firewalls, and segmentation;
  • Experience with technical documentation and architecture diagrams;
  • Knowledge of at least one programming language (e.g., Java, Python, Node.js, JavaScript, .NET) to understand code logic;
  • Relevant professional certifications for the role (e.g., CISSP, CISM, OSCP, etc.);
  • Programming languages and API usage;
  • Integration of scripts and web pages;
  • Knowledge of ISO 27001, NIST, and CIS.

Benefits

  • Medical and dental insurance (employee and dependents);
  • Dr. C&A – Telemedicine and teletherapy services;
  • Annual bonus;
  • Parking or transportation allowance (Worksite: Alphaville – Barueri/SP);
  • Birthday off: one paid day off during your birthday month;
  • Flexible working hours;
  • On-site cafeteria;
  • Flexible meal benefit (meal allowance and/or food voucher);
  • Gympass membership;
  • Semi-annual vacation;
  • Employee discount at C&A stores and online;

Related Job Pages

More Security Analyst Jobs

IP House logo

Senior Investigator

IP House

Global IP Protection

Security Analyst79 days ago
OtherRemoteTeam 501-1,000Since 2024H1B No Sponsor

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Our clients rely on us to fiercely protect their intellectual property. To support the company’s rapid growth, we seek a Senior Investigator for our Special Investigations Unit to lead complex investigations aimed at dismantling criminal operations worldwide. The ideal candidate has proven success in using OSINT techniques to identify threat actors and attribute their actions. The successful candidate will be able to function in a broad-based, fast-paced, high-energy environment while executing impactful investigations. Applicants are strongly encouraged to submit a cover letter along with their resume. This will provide you with a greater opportunity to stand out and advance in our selection process. - Conduct comprehensive investigations into potential intellectual property (IP) infringement using advanced open-source intelligence (OSINT) techniques and methodologies. - Utilize various online resources, including social media platforms, websites, forums, and dark web monitoring tools, to gather relevant information. - Leverage effective search strategies to uncover hidden infrastructure and key individuals or organizations engaged in counterfeiting, trademark and copyright infringement, and other IP crimes. - Analyze code and perform network traffic analysis to understand the functionality of illicit websites, devices, and applications, and identify their creators. - Develop scripts using Python (or similar) to automate repetitive investigative tasks. - Translate findings into actionable reports summarizing findings and making well-reasoned recommendations for further investigation or enforcement. - Write detailed criminal referrals based on investigative findings to support legal actions and enforcement efforts. - Stay current on emerging trends and techniques in the OSINT field and intellectual property infringement. - Collaborate with internal and external stakeholders, including intelligence analysts, field investigators, attorneys, and law enforcement, to build strong cases. - Present findings and recommendations to clients, effectively communicating complex information and gathering their requirements to ensure alignment on investigative goals. - Stay current on evolving intellectual property laws and regulations, emerging trends, and technological advancements. Qualifications - Minimum of 3 years of experience conducting high-stakes OSINT investigations. - Proven ability to conduct and document named attribution investigations, moving beyond infrastructure analysis to establish threat actor identities supported by open source, behavioral, and technical evidence. - Demonstrated expertise in advanced OSINT techniques, including social engineering, infiltration, data mining, automation, and dark web analysis. - Proficiency in network traffic analysis and understanding of network protocols. - Experience in reading and analyzing code to understand the functionality of websites, devices, and applications. - Basic proficiency in Python (or similar) to develop scripts for automating investigative tasks. - Excellent written and verbal communication skills in English, with the ability to tailor reports and presentations with complex findings to diverse audiences. - Ability to conduct investigations involving foreign languages. - Strong critical thinking and problem-solving skills. - Ability to work autonomously with minimal oversight. - Ability to manage and prioritize multiple investigations simultaneously. - Basic understanding of intellectual property laws and regulations, with the ability to translate legal concepts into actionable investigative strategies. - A passion for intellectual property protection and a strong ethical compass. Benefits - Flexible work environment. - Comprehensive benefits package designed to support the health, well-being, and financial security of our employees and their families. Company Description IP House is redefining how the world combats illicit trade and intellectual property theft—delivering scalable, end-to-end solutions that empower global brands and rights holders through innovation, strategic expertise, and a relentless commitment to global enforcement. Achieving this ambitious mission requires the collaboration of an exceptionally talented team. We believe our people are the foundation of everything we do—and we invest accordingly. From day one, we foster a culture rooted in continuous learning, professional growth, and shared excellence. Here, you’ll have the opportunity to shape a fast-scaling organization with a strong reputation for results—and room to grow with it. Join us in safeguarding the brands, content, and innovations that shape our world. IP House is an equal opportunity employer dedicated to fostering a respectful, collaborative, and inclusive work environment.

United States
$65K - $75K / year
Ridgeline International, LLC logo

Cyber Security Intern

Ridgeline International, LLC

Solving our customers' toughest data problems

Security Analyst79 days ago
OtherRemoteTeam 201-500Since 2015H1B No Sponsor

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description What You Will Do: - Monitor security tools and platforms to identify potential threats, suspicious behavior, and operational anomalies. - Support vulnerability assessments and penetration testing activities while working closely with senior security staff. - Maintain accurate and current documentation for security policies, procedures, and incident response plans. - Research emerging cyber threats, evolving attack vectors, and industry best practices to inform security decisions. - Ensure compliance requirements are automated and stored in a declarative format using Compliance as Code approach. - Assist with hardening configurations in operational platforms by applying container security strategies and granular network segmentation policies. - Support the team with log analysis, security reporting, and improvements to security tooling. What You Will Learn: - How cybersecurity teams defend against real world threats in a mission critical environment. - How security monitoring tools, SIEM platforms, and threat detection workflows operate in practice. - How to integrate security tooling and workflows into the software development and deployment process using modern CI and CD practices. - Strategies for securing discrete workloads in shared computing environments such as Kubernetes, Docker, and vCenter. - Best practices for using LLMs to support security engineering and security architecture. Qualifications - Currently pursuing a bachelor or master’s degree in Cybersecurity, Computer Science, Information Technology, or a related field. - Foundational understanding of networking concepts including TCP/IP, DNS, firewalls, and VPNs. - Foundational understanding of DevSecOps tooling and concepts including CI and CD, DAST, SAST, and provenance. - Strong analytical and problem-solving skills with keen attention to detail. - Familiarity with automation and container orchestration platforms such as Ansible, Kubernetes, and vCenter. - Ability to communicate technical concepts clearly in both written and verbal formats. - Eagerness to learn and stay current with the evolving cybersecurity landscape. Requirements - Hands-on experience with security tools such as SIEM platforms, vulnerability scanners, or endpoint detection solutions. - Capture-the-Flag competition experience or personal projects showing practical knowledge of DevSecOps concepts. - Experience with development tooling (Git) and scripting languages such as Python, Bash, or PowerShell. - Familiarity with Infrastructure-as-Code concepts (Terraform, CloudFormation). - Familiarity with cloud security concepts (AWS, Azure, or GCP). - Familiarity with automation and container orchestration platforms (Ansible, Kubernetes, vCenter). Physical & Work Environment - Must be capable of remaining stationary for 50% of the time; occasional movement within the office environment may be required. - The role involves continuous interaction with computers and other office productivity equipment. Equal Opportunity Employer Ridgeline International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other characteristic protected by applicable law.

United States

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description The Cybersecurity Analyst will be responsible for monitoring, analyzing, and responding to security incidents. This role involves identifying vulnerabilities, implementing security measures, and ensuring compliance with industry standards. - Monitor network traffic for security incidents and anomalies. - Conduct vulnerability assessments and penetration testing. - Investigate security breaches and other cybersecurity incidents. - Develop and implement security policies and procedures. - Collaborate with IT and other departments to enhance security measures. - Stay updated with the latest cybersecurity trends and threats. - Accountable for SOC-2 and HIPAA compliance through Vanta. - Prepare reports and documentation on security incidents and findings. - Provide training and support to staff on cybersecurity best practices. Qualifications - Bachelor's degree in Computer Science, Information Technology, or related field. - Proven experience in cybersecurity or related roles. - Strong understanding of network protocols, firewalls, and intrusion detection systems, and Security Information and Event Management systems. - Familiarity with cybersecurity frameworks (e.g., NIST, CIS, ISO 27001). - Experience with Rapid7. - Experience with AWS and Microsoft Office 365 required. - Healthcare experience and HIPAA framework is a plus. - Excellent problem-solving and analytical skills. - Strong communication skills and ability to work in a team environment. - Relevant certifications (e.g., CISSP, CEH, CompTIA Security+) are a plus. Requirements - $105,000 - $117,000 a year Benefits - Medical, dental and vision benefits within 30 days of hire. - Paid Time Off: Vacation and Sick Time. - Paid Holidays. - Equipment Provided. - A fun team and special culture.

United States
$105K - $117K / year
Job Closed
Jobgether logo

Senior Information Security Analyst

Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Security Analyst79 days ago
OtherRemoteH1B No Sponsor

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This role provides a critical opportunity to safeguard enterprise systems and data through advanced threat detection, incident response, and proactive security monitoring. The Senior Information Security Analyst will operate within a Security Operations Center (SOC), leveraging cloud, endpoint, and network expertise to identify, analyze, and mitigate cyber threats. This role blends investigative skills, automation, and threat intelligence to protect business assets, while mentoring junior analysts and contributing to SOC process improvements. The position offers a high-impact environment where strategic thinking, technical proficiency, and continuous learning are central to success. - Monitor and triage alerts from security platforms, including CrowdStrike Falcon and Microsoft Sentinel. - Lead investigations into endpoint, network, and cloud security incidents, including malware, privilege escalation, and data exfiltration. - Conduct proactive threat hunting, forensic analysis, and anomaly detection across enterprise systems and cloud environments. - Develop and refine SOC playbooks, runbooks, and automation to improve detection, response, and operational efficiency. - Serve as an escalation point for Tier 1 and Tier 2 analysts, mentoring junior team members and sharing threat intelligence. - Collaborate with internal stakeholders to strengthen cloud security posture, incident readiness, and response workflows. - Participate in red/blue team exercises and continuous SOC process and capability improvements. Qualifications - 4–7 years of experience in a SOC or cybersecurity analyst role. - Expert-level proficiency with CrowdStrike Falcon and Microsoft Defender. - Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, or Elastic. - Deep knowledge of Windows, Linux, and macOS internals. - Practical experience in cloud incident investigations across Azure, AWS, and GCP. - Proficiency in scripting and automation (Python, PowerShell) and advanced log analysis. - Strong understanding of MITRE ATT&CK framework, malware behavior, and incident response methodology. - Excellent written and verbal communication skills, with the ability to influence and mentor teams. - Preferred certifications: CCFR, CCFA, GIAC (GCIA, GCIH), CySA+, or equivalent. - Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field (or equivalent experience). Benefits - Competitive salary reflective of experience and market standards. - Comprehensive healthcare coverage, including medical, dental, vision, and life insurance. - Retirement savings options, including 401(k) and employee stock purchase plan. - Paid time off, including vacation, holidays, and sick leave. - Flexible remote work arrangements across eligible U.S. states. - Opportunities for professional growth, certification support, and participation in industry events. - Collaborative and innovative work environment focused on advanced cybersecurity practices. Company Description

United States
Job Closed