Somando inovação para multiplicar resultados.
Analista de Segurança da Informação Sr – APP SEC
Location
Brazil
Posted
13 days ago
Salary
0
Seniority
Senior
Job Description
Analista de Segurança da Informação Sr – APP SEC
Positivo S+
• Estruturar e evoluir práticas de Secure Software Development Life Cycle (S-SDLC) • Realizar modelagem de ameaças (Threat Modeling) em aplicações e APIs • Implementar e administrar ferramentas de segurança: SAST DAST SCA IAST • Executar análises de código com foco em vulnerabilidades e boas práticas de segurança • Atuar na gestão de vulnerabilidades, incluindo: identificação priorização análise de risco acompanhamento da remediação • Integrar controles de segurança em pipelines CI/CD • Apoiar times de desenvolvimento na adoção de práticas DevSecOps • Atuar com segurança em ambientes Cloud (AWS, Azure ou GCP) • Implementar boas práticas de segurança em containers e orquestração: Docker Kubernetes • Trabalhar com soluções de proteção de borda: WAF API Gateway IDS/IPS Next Generation Firewall • Apoiar iniciativas de hardening, segmentação de rede e controle de acesso • Garantir aderência a frameworks e padrões como: OWASP Top 10 OWASP ASVS OWASP SAMM ISO 27001/27002 NIST Cybersecurity Framework
Job Requirements
- Experiência comprovada de pelo menos 3 anos em Application Security
- Vivência prática com AppSec, DevSecOps e segurança em desenvolvimento
- Conhecimento em automação de pipelines CI/CD com foco em segurança
- Experiência com ferramentas de análise de vulnerabilidades e revisão de código
- Conhecimento em arquitetura de aplicações, APIs e microsserviços
- Experiência com ambientes cloud e containers
- Conhecimento em Git e fluxos de versionamento
- Familiaridade com gestão de incidentes e riscos de segurança
Benefits
- Convênios médico e odontológico.
- Seguro de Vida.
- Vale Alimentação/Vale Refeição
- Vale Transporte.
- Clube de Descontos.
- Acesso ao Wellhub (academias) e Mente Tranquila.
- Desconto nos produtos Positivo.
- Parceria com Universidade.
- E muito mais.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Junior Network Security Analyst
Skadden, Arps, Slate, Meagher & Flom LLPSkadden, Arps, Slate, Meagher & Flom LLP (Skadden) is a New York-based law firm with more than 20 global offices. As an employer, Skadden is known for its fast-
Title: Junior Network Security Analyst Location: White Plains Job Description: We invite you to review our current business services professionals openings to learn about the opportunities available across the firm. About Us Skadden, Arps, Slate, Meagher & Flom LLP has forged a reputation as one of the most prestigious law firms in the world. Relying on innovation, intellect, teamwork and tenacity, our lawyers deliver the highest quality advice and novel solutions to our clients’ legal issues. We are known for handling the most complex transactions, litigation/controversy issues, and regulatory matters, as well as for the strong partnerships we build with clients and each other. Our attorneys, who reflect a broad range of experiences and perspectives, work together seamlessly across 50-plus practices and 21 offices in the world’s major financial centers. The Opportunity We are seeking a Junior Network Security Analyst to join our Firm. This position will be based in our White Plains office (hybrid). The Junior Network Security Analyst will have responsibility for supporting the implementation, administration, and maintenance of the Firm’s security systems and controls. This role assists with monitoring security tools, responding to routine security issues, and helping protect the Firm’s technology environment through established procedures and best practices. - Perform daily review of automated security reports and escalate as necessary - Prepare reports from security tools for distribution to relevant teams - Assist security team with responding to system generated security alerts - Assist with internal audits, vulnerability scans and risk assessments - Assist with annual penetration testing, review of findings and tracking issue resolution - Assist with issues tracking follow-up and testing remediation completeness - Participate in testing, documentation and implementation of new or updated security technologies - Perform other related duties as assigned. Qualifications - Proficient with MS Office including, Access, Project and Visio - Knowledge of network management and security technologies and approaches - Understanding of Microsoft Active Directory and Operating Systems - Basic ability to program scripts and batch files - Ability to quickly learn new technologies and concepts and apply that knowledge effectively - Ability to work both independently and with a team to accomplish multiple tasks and projects - Excellent troubleshooting and problem-solving skills. - Organizes and prioritizes tasks effectively - Ability to accommodate shifting priorities - Ability to communicate clearly and effectively. - Deals courteously and effectively with others. - Works well under pressure - Flexibility to adjust responsibilities and hours to meet operating needs. Education and Experience - Bachelor's Degree or equivalent - Minimum of 1 years' directly related experience, ideally within a multi-national enterprise IT environment. Law firm or financial services experience preferred. Culture & Life at Skadden What makes Skadden special is our people and the culture, community and spirit of collaboration we have created. We believe in teamwork and inspiring each other to be our best in an atmosphere that promotes professionalism and excellence in all that we do. We know that inclusion and drawing on the strength of a wide spectrum of talent only make us better and is vital to the firm's success. Our goal is for everyone at the firm to enjoy a challenging career with opportunities for development and growth and to support the well-being of our attorneys and business services professionals. Benefits The overall well-being of our team is important to us. We offer generous benefits to help you achieve wellness in all areas of your life. - Competitive salaries and year-end discretionary bonuses. - Comprehensive health care (medical, dental, vision), savings plan/401(k) and voluntary benefits. - Generous paid time off. - Paid leave options, including parental. - In-classroom, remote, and on-demand learning and professional development opportunities. - Robust well-being classes and programs. - Opportunities to give back and make an impact in local communities. For further details, please visit: https://www.skadden.com/careers/staff/employee-benefits The starting base salary for this position is expected to be within the range listed under Salary Details. Actual salary will be determined based on skills, experience (to the extent relevant) and other-job related factors, consistent with applicable law. Salary Details $85,000 - $90,000 EEO Statement Skadden is an Equal Opportunity Employer. It does not discriminate against applicants or employees based on any legally impermissible factor including, but not limited to, race, color, religion, creed, sex, national origin, ancestry, age, alienage or citizenship status, marital or familial status, domestic partnership status, caregiver status, sexual orientation, gender, gender identity or expression, change of sex or transgender status, genetic information, medical condition, pregnancy, childbirth or related medical conditions, sexual and reproductive health decisions, disability, any protected military or veteran status, or status as a victim of domestic or dating violence, sexual assault or offense, or stalking. Applicants who require an accommodation during the application process should contact Alex Taylor at (212) 735-2176. Skadden Equal Employment Opportunity Policy Skadden Equal Employment Opportunity Policy Applicants Have Rights Under Federal Employment Law Applicants Have Rights Under Federal Employment Law In accordance with the Transparency in Coverage Rule, click here to review machine-readable files made available by UnitedHealthcare: Transparency in Coverage
Cyber Security Analyst
MercorCincinnatus is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for full-time and long-term contingent roles. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Roles hired through Cincinnatus are not project-based or freelance engagements. They are structured, role-based positions that typically involve full-time or fixed-term commitments, close collaboration with a client's internal teams, and integration into standard enterprise workflows. Cincinnatus is a legal entity separate from Mercor. While opportunities may be discovered through Mercor's platform, employment, onboarding, payroll, and benefits for these roles are administered by Cincinnatus. Equal Employment Opportunity Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. Cincinnatus is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans throughout the job application process.
Role Description Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey. Position: Cybersecurity Experts Type: Contract Compensation: $70–$90/hour Location: Remote - Analyze and review content for security vulnerabilities with a focus on pattern recognition and classification in an AI context. - Apply expertise in systems programming and security concepts to enhance AI model threat detection and reasoning. - Work asynchronously with a team of highly qualified experts across your domain. - Craft, solve, and review challenging problems with real-world applicability. - Emphasize independent work and flexible hours to meet project goals. Qualifications - 2+ years of experience in programming with C, C++, or Java. - Familiarity with security vulnerability classification such as OWASP or CVEs. - Understanding of core cybersecurity concepts, including web security and common attack vectors. - Strong attention to detail and pattern recognition skills. - Clear written and verbal communication in English. - Currently based in the U.S., Canada, UK, Australia, or New Zealand. - Ability to pass an enhanced background check. Requirements - Start Date: Mid-April; exact dates confirmed closer to the start date. Application Process - Complete a short interview and questionnaire to assess domain expertise. - Paid for up to 1 hour of onboarding time, including screening and onboarding videos if hired. - Upload resume. - AI interview based on your resume. - Submit form. Resources & Support - For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome - For any help or support, reach out to: support@mercor.com - Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.
• Configurar e gerenciar soluções de SIEM, EDR e MDR para garantir detecção e resposta a incidentes eficazes. • Atuar em atividades de gestão de vulnerabilidades e propor medidas de mitigação de riscos. • Conduzir análises e investigações relacionadas a incidentes de segurança. • Monitorar e analisar alertas de segurança para identificar ameaças emergentes. • Contribuir para a melhoria contínua dos processos e políticas de segurança. • Elaborar relatórios e dashboards para apoiar a tomada de decisão. • Atualizar-se constantemente sobre novas ameaças, tendências e ferramentas no mercado.
Security Analyst I
DraftKings Inc.Defining what it means to build and deliver the most extraordinary sports & entertainment experiences.The Crown is Yours
At DraftKings, AI is becoming an integral part of both our present and future, powering how work gets done today, guiding smarter decisions, and sparking bold ideas. It's transforming how we enhance customer experiences, streamline operations, and unlock new possibilities. Our teams are energized by innovation and readily embrace emerging technology. We're not waiting for the future to arrive. We're shaping it, one bold step at a time. To those who see AI as a driver of progress, come build the future together. The Crown Is Yours As a Security Analyst I, you'll help protect the systems that power our products by monitoring, investigating, and responding to security events across both corporate and production environments. In this role, you'll operate at the center of detection and response, working across endpoints, identity systems, and cloud infrastructure. You'll make a direct impact from day one and gain hands-on experience with modern technologies while strengthening your foundation in incident response and security operations. What You'll Do - Triage and investigate security alerts across endpoints, identity systems, cloud environments, and production workloads. - Support response efforts for a range of security investigations, including account compromise, endpoint activity, and suspicious behavior in cloud, CI/CD, or production systems. - Collect and analyze relevant data (e.g., logs, system activity) to help scope incidents, identify impacted systems, and track activity across environments. - Escalate higher-risk or unclear activity, and support senior team members in ongoing investigations. - Execute containment or remediation actions as directed, and document findings clearly throughout the investigation lifecycle. - Support vulnerability and posture management efforts by validating findings and helping track remediation activities. What You'll Bring - At least 2 years of experience in cybersecurity, IT, or a related field. - Experience working in a security operations, monitoring, or incident response environment. - Familiarity with alert triage, and working within structured processes. - Basic understanding of identity and access concepts, endpoint and common attack patterns (e.g., phishing, credential misuse), and cloud or application environments - Strong analytical skills and attention to detail. - Clear written and verbal communication skills. - Ability to follow processes, collaborate with a team, and escalate when needed. #LI-TK1 #LI-HYBRID Join Our Team We're a publicly traded (NASDAQ: DKNG) technology company headquartered in Boston. As a regulated gaming company, you may be required to obtain a gaming license issued by the appropriate state agency as a condition of employment. Don't worry, we'll guide you through the process if this is relevant to your role.



