Job Closed
This listing is no longer active.
We Take Care of Your Data
Senior Information Security Analyst
Location
Brazil
Posted
46 days ago
Salary
0
Seniority
Senior
Job Description
Senior Information Security Analyst
Rox Partner
• Implement, administer and enhance PAM solutions (CyberArk), ensuring privileged access control and protection of critical credentials. • Manage privileged accounts, password vaults and access policies, with integration to Active Directory (AD) and other corporate systems. • Administer and optimize Fortinet Firewalls (FortiGate), including rule creation, review and troubleshooting. • Operate and advance XDR and SIEM solutions (Palo Alto – Cortex XDR / Data Lake), including alert tuning and development of use cases. • Investigate and respond to security incidents, perform root cause analysis and propose continuous improvements. • Structure and execute vulnerability assessment and management processes, prioritizing based on risk (CVSS) and tracking remediations. • Perform hardening of Windows and Linux servers, ensuring compliance with security best practices. • Monitor and analyze security logs and events in on-premises and cloud environments. • Work with Brand Protection solutions (Rainforest or similar), identifying and mitigating threats such as phishing and brand abuse. • Define, implement and evolve information security policies, standards and procedures. • Support audits and compliance initiatives (ISO 27001, LGPD, among others). • Act as a consultant to business and technology teams, promoting a security culture and risk management.
Job Requirements
- Solid experience in Information Security, with work in complex corporate environments.
- Hands-on experience implementing and supporting solutions such as CyberArk (PAM), Fortinet (FortiGate) and Palo Alto (XDR / SIEM), from configuration to troubleshooting and environment evolution.
- Advanced knowledge of Active Directory (AD) and identity management.
- Strong networking knowledge (TCP/IP, VPN, segmentation and firewall policies).
- Experience with vulnerability assessment tools and processes.
- Experience in security incident response, with investigative and corrective actions.
- Experience hardening Windows and Linux servers.
- Knowledge in security log monitoring and analysis.
- Nice to have: Experience with Brand Protection (Rainforest or similar).
- Experience with cloud environments (AWS, Azure or GCP).
- Knowledge of automation (Python, PowerShell).
- Experience with security frameworks (NIST, CIS Controls, ISO 27001).
Benefits
- Remote work – Monday to Friday (09:00 to 18:00).
- Home-office allowance – Meal/food credit on an iFood card of R$ 300.00 per month.
- Birthday – On your special day, Rox gives you a gift voucher and a day off to enjoy.
- Courses – Full access via RoxSchool, Alura, Pluralsight, O’Reilly for books and talks, and RoxSchool.
- Certifications – Certification reimbursement up to R$300.00 (TECHNOLOGY) + a R$300.00 bonus per certification achieved from these providers.
- Psychological support – Two psychotherapy sessions covered monthly by ROX with partner psychologists.
- Feedz partnership – A gamified platform to improve communication and track sentiment, engagement, feedback, Individual Development Plans (PDI) and performance.
- WellHub (Gympass) – Partnership with gyms and health & wellness apps.
- We provide the work equipment.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
AI Security Analyst
ai2ioFrom Transformative AI to Foundational I/O — Custom solutions for your unique business needs!
• The AI Security Analyst is responsible for evaluating, governing, and securing the organization’s adoption and use of artificial intelligence tools, platforms, and integrations. • Working under the direction of the Information Security Manager, this role ensures that AI technologies are deployed with appropriate security controls, data protection standards, and risk oversight across ai2io’s multi-tenant managed services environment. • Evaluates AI tools, SaaS integrations, and platform capabilities for security risk, data exposure, and compliance alignment before and during organizational adoption. • Develops and maintains the organization’s AI governance framework, including usage policies, application approval workflows, and data classification standards for AI contexts. • Coordinates with AI platform engineering teams to ensure sensitivity labels, access controls, and data boundaries are consistently governed under a centralized security standard. • Monitors AI usage across the organization using Microsoft Defender for Cloud Apps and other telemetry sources to identify shadow AI, unauthorized integrations, and data leakage risks. • Supports GRC and identity security functions as a secondary focus, including compliance evidence collection, access reviews, and framework alignment.
Role Description We’re looking for a Security Analyst Support Intern to join the Wordfence team and gain hands-on experience in securing and supporting WordPress websites. This role will primarily involve: - Working closely with the Wordfence Customer Support team to identify and address customer issues. - Spending time with the Marketing, Quality Assurance, Care and Response, and Threat Intelligence teams. - Gaining insight into SEO, testing, site cleaning, and vulnerability validation processes. This is a 12 week internship with an hourly rate of $25 per hour. Upon completion of the Security+ certification, the hourly rate will increase to $30 per hour. This position requires that you be eligible to work in the United States without immigration assistance and that you currently live in the US. Qualifications - Currently enrolled in a Bachelor’s degree program in Computer Science, Information Security, or a related field. - Basic understanding of web technologies and security concepts. - Strong interest in pursuing a career in information security. - Ability to work collaboratively in a team environment. - Strong attention to detail and commitment to delivering high-quality work. Requirements - Familiarity with WordPress CMS, plugins, and themes (preferred but not required). - Familiarity with website hosting tools such as cPanel and FTP (preferred but not required). - Basic knowledge of network security principles and technologies (preferred but not required). - Experience with customer support or customer-facing roles (preferred but not required). - Basic understanding of QA processes and methodologies (preferred but not required). - Strong analytical and problem-solving skills (preferred but not required). - Excellent verbal and written communication skills (preferred but not required). Responsibilities - Collaborate with the Customer Support team to troubleshoot and resolve customer issues related to the Wordfence plugin. - Participate in weekly meetings with the core Wordfence, Customer Support, and Care and Response teams. - Collaborate with the Marketing team to gain insight into marketing strategy and SEO principles. - Support the Quality Assurance team by testing the Wordfence plugin and website improvements. - Support the Threat Intelligence team by researching plugin vulnerabilities and identifying various exploits. - Conduct independent study and successful completion of Security+ certification. Hiring Process - We review all applications submitted and respond to all candidates usually within one to two weeks. - Please fill in the form provided in this application. The hiring team will look at this first. - Candidates who appear to have the right skills from the initial application will be sent a more detailed Assessment Test. - Participate in a series of phone interviews, usually two or three, all done remotely. - All contracts and offers of employment are contingent on the successful completion of a background check. - All internship positions require a trial period of approximately 1 - 2 weeks with a minimum commitment of 10 hours per week. Benefits - Eligible for paid company holidays. - Eligible for overtime pay. - 401(k) with a 4% Safe Harbor company match that is 100% vested immediately. Diversity at Defiant We value diversity and do not discriminate based on race, color, religion or creed, national origin or ancestry, sex, age, physical or mental disability, military or veteran status, gender identity or expression, marital status, sexual orientation, political ideology, economic status, parental status, or any other non-performance-related status.
• Analyze, investigate, document and report on security alerts and/or potential security incidents identified in customer environments • Process security investigation cases in a thorough, yet timely manner • Serve as an incident coordinator for security events that require urgent response, containment, and remediation • Generate meticulous investigative notes for all security alerts and incidents • Provide continuous feedback on security process improvements and customer satisfaction • Stay up-to-date on security training, certification, and emerging threats • Make appropriate escalations on security investigations when warranted • Ensure shift-change documentation is completed and communicated effectively • Follow all available SOPs and escalation communication matrices • Provide customers with meaningful and constructive security consultation during external communications.
Associate Lead, Regulatory Security Analyst
ScopelyScopely is a touchscreen entertainment network that collaborates and partners with elite game developers and global entertainment companies to deliver industry-
Role Description The Associate Lead, Regulatory Compliance, is responsible for overseeing the continuous execution and monitoring of Scopely’s regulatory and national security compliance obligations within our rapidly expanding, global gaming environment. This role focuses on regulatory program oversight, structured monitoring, and governance execution to ensure Scopely consistently meets its formal compliance commitments. This is achieved through structured oversight, continuous monitoring, and disciplined governance across all teams, systems, and vendors. This role requires close partnership with the Security Officer, Legal, HR, IT, Product, and Data teams to maintain continuous compliance with all regulatory and national security commitments. - Lead oversight of compliance with U.S. foreign investment and privacy regulations, advising internal teams and ensuring regulatory requirements are implemented consistently and effectively. - Monitor adherence to the NSA Cybersecurity Plan, privacy and related regulatory requirements, ensuring controls operate as designed and deviations are promptly addressed. - Oversee regulator-facing communications and required notifications, including non-objection submissions, storage and vendor updates, incident reporting within defined timelines, and annual compliance reporting. - Maintain and manage security compliance documentation, ensuring updates are accurate, timely, and regulator-ready. - Track and monitor role-based access controls for sensitive data, including onboarding/offboarding processes, privilege drift reviews, and third-party access. - Oversee security compliance training for relevant personnel. - Coordinate and support third-party assessments, regulatory reviews, and audit activities. - Maintain structured documentation and evidence repositories to ensure audit readiness at all times. - Identify gaps or process improvements and drive enhancements to strengthen governance and monitoring mechanisms. - Partner with IT and Engineering to ensure monitoring, logging, and segregation controls align with regulatory expectations. Qualifications - 6+ years of experience in cybersecurity governance, regulatory compliance, risk management, or related security oversight roles. - Experience supporting structured regulatory frameworks or government oversight programs. - Strong understanding of identity governance, role-based access controls, least privilege principles, and vendor risk oversight. - Experience managing regulatory reporting timelines and structured compliance documentation. - Experience managing annex-style documentation frameworks or formal regulatory filings. - Demonstrated ability to coordinate audits, assessments, and regulator-facing engagements. - Experience leveraging or building AI-enabled tools to enhance GRC processes, including developing AI assistants or automation workflows to improve regulatory monitoring, documentation, and control oversight. - Strong written communication skills with the ability to draft clear, defensible regulatory communications. - Experience working cross-functionally with Legal, HR, Engineering, and Executive stakeholders. - Strong program management and organizational skills with attention to detail. - Ability to operate independently in a high-accountability environment. - Familiarity with NIST or ISO aligned cybersecurity control framework. Bonus Points - Advanced degree or relevant certifications (CISSP, CISM, CRISC, etc.). Benefits - Comprehensive benefits package, including healthcare benefits, retirement benefits, pet insurance, paid holidays, paid Scopely free days, and unlimited paid time off. Salary Information For candidates in CA, CO, NJ, NY, and WA, the annual salary range is provided below. In addition to base pay, employees may be eligible for equity and bonuses. Base pay offered may vary depending on job-related knowledge, skills, and experience. - CA, CO, NJ, NY, and WA Annual Salary Range: $145,000 — $184,800 USD.


