Cresol Cooperativa logo
Cresol Cooperativa

Fornecendo soluções financeiras com excelência por meio do relacionamento.

Information Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 5,001-10,000Since 1995H1B No SponsorCompany SiteLinkedIn

Location

Brazil

Posted

4 days ago

Salary

0

Seniority

Senior

Job Description

Information Security Analyst

Cresol Cooperativa

• Incident Management: Lead the incident response lifecycle (preparation, identification, containment, eradication, and recovery). • Forensic Analysis: Perform digital forensics on hosts (Windows/Linux/iOS/Android), memory, networks, and cloud environments to identify the root cause of compromises. • Advanced Monitoring: Work together with the SOC/Support team to triage high-complexity alerts in XDR/SIEM and NDR tools. • Threat Hunting: Conduct proactive searches for threats that may have bypassed existing security controls. • Documentation and Reporting: Produce detailed technical reports and forensic findings to support executive decision-making and regulatory compliance (Bacen/LGPD). • Continuous Improvement: Recommend adjustments to detection rules and security policies based on the tactics (TTPs) observed during investigations.

Job Requirements

  • Degree: Degree in Computer Science, Information Systems, Information Security, or a related field.
  • Technical Experience: Solid knowledge of Windows and Linux operating systems, network protocols (TCP/IP), and log analysis.
  • Tooling: Experience with XDR solutions (e.g., SentinelOne, Sophos, CrowdStrike), SIEM, and forensic tools (e.g., Autopsy, FTK, Volatility, or similar).
  • Attack Knowledge: Practical understanding of the MITRE ATT&CK framework.
  • Languages: Technical English for reading documentation and drafting reports.
  • Differentials: Recognized certifications (e.g., GCIH, GCFE, CHFI, or equivalent); previous experience in the financial sector and knowledge of Bacen regulations; proficiency with scripting languages (Python or PowerShell) for automating collection and analysis tasks; knowledge of cloud infrastructure (AWS/Azure) and edge security.

Benefits

  • Length-of-Service Bonus – We recognize your dedication and career with us.
  • Postgraduate Assistance – We invest in your knowledge with a special incentive for postgraduate studies.
  • Educational Discounts – Exclusive partnerships with universities for Undergraduate, Postgraduate, and MBA programs.
  • Cresol Corporate University – Continuous learning to boost your career.
  • Birthday Day Off – In your birthday month, in addition to a special gift, you are entitled to one day off to celebrate as you wish.
  • New Parent Bonus – A special incentive to celebrate the arrival of your child.
  • Baby Kit – Cresol’s care begins at birth, with a special gift to welcome the new family member.
  • Wedding Assistance – Financial support to celebrate this new chapter in your life.
  • Christmas Allowance – A gift to make your holiday meal even more special alongside your loved ones.
  • Health Plan – Your health comes first; the monthly fee is 100% covered by Cresol.
  • Dental Plan – Your health also starts with a smile: the monthly fee is 100% covered by Cresol, with no cost for procedures included in the plan.
  • Physical Activity Incentive – Access to initiatives such as gyms, yoga, meditation, and other practices focused on your well-being.
  • Workplace Exercise – Stretching and exercise sessions during the workday to promote energy and well-being.
  • Blood Donation Incentive – We value life-saving actions and provide a financial benefit for blood donors.
  • Cresol Cares – Support for your emotional health through free online therapy sessions for you and up to two dependents (spouse, children, or parents).
  • Life Insurance – Additional protection, including coverage for serious illnesses.
  • Cresol Longevity – Incentives to build financial reserves for a more secure future.
  • Private Pension – Incentives to build financial reserves for a more secure future.
  • Meal and/or Food Voucher – To make your daily life more practical.
  • Childcare Assistance – Support for the care and education of your children up to 7 years old.
  • School Supplies Assistance – Incentive for the education of your children up to 11 years and 11 months.
  • Transportation Voucher – We facilitate your commute with public transportation support.
  • Flexible Vacation – The possibility to split your vacation into up to three periods for better personal planning.
  • Pet Leave – Adopted a pet? You receive 2 days off to enjoy the new family member.
  • Extended Maternity Leave – In addition to the 120 days provided by law, you can choose between 30 additional full days or 60 days at half-time.
  • Extended Paternity Leave – More time to enjoy this special moment, with 5 additional days beyond those provided by law.
  • Special Care Allowance – Benefit for employees who are parents of people with disabilities who require full-time care.
  • Justified Absence: Parents of children with disabilities are entitled to up to 5 days of justified absences per year for medical appointments or hospitalizations.
  • Death Benefit – Financial support paid monthly for one year to the legal dependents of an employee who has passed away.
  • Funeral Assistance – Financial support to help cover expenses during this difficult time.
  • Bereavement Leave – An additional 3 business days of leave, beyond those required by law, for the loss of parents, children, siblings, or a spouse.
  • Uniform – Comfort, identity, and pride in wearing our brand every day.

Related Job Pages

More Security Analyst Jobs

Cherokee Federal logo

Security Analyst

Cherokee Federal

Building. Solving. Serving.

Full TimeRemoteTeam 5,001-10,000Since 1969H1B No Sponsor

• Monitor and analyze security events utilizing Splunk Enterprise Security (ES). • Build, maintain, and tune Splunk searches, correlation rules, alerts, and dashboards. • Conduct incident response activities from detection through containment, eradication, recovery, and closure. • Investigate endpoint security incidents utilizing Microsoft Defender for Endpoint. • Perform endpoint policy management and incident investigations. • Assess AWS cloud security telemetry utilizing GuardDuty, Security Hub, and related cloud security services. • Identify threats, vulnerabilities, suspicious activity, and cloud misconfigurations. • Execute alert triage, incident scoping, and escalation activities according to established playbooks. • Recommend updates and improvements to operational procedures and incident response playbooks. • Support threat hunting activities and detection engineering initiatives aligned to MITRE ATT&CK methodologies. • Perform phishing investigations, alert enrichment, and forensic review activities. • Conduct root cause analysis and document corrective actions following security incidents. • Track incidents and operational tasks utilizing case management systems. • Participate in tabletop exercises and operational readiness activities. • Collaborate with Security Operations teams, Incident Response personnel, and federal stakeholders. • Prepare reports and communicate findings to technical and non-technical audiences. • Perform other job-related duties as assigned.

United States
$153K - $160K / year

Senior Digital Forensics Examiner

DISCO

DISCO.ac specializes in cloud-based music catalog management, discovery, and promotion and offers a Software-as-a-Service (SaaS) platform through which professi

Role Description The Senior Forensic Examiner is responsible for performing advanced forensic scoping, forensic consultation, forensic collection, forensic analysis, forensic reporting, and expert testimony. They are responsible for determining the most defensible method of collection and troubleshooting any data issues that may arise. They are also responsible for the more intricate and new data source collections and analysis. What You'll Do - Forensic Collections and Investigations: - Conducts forensic collections of digital evidence using best practices and approved software and hardware. - Acquires electronic data from cloud sources, computers, mobile devices, and other digital media in a forensically sound manner. - Consults with customers to conduct forensic collections, perform exports and reporting, and conduct investigations. - Forensic Reporting: - Creates summary reports, forensic artifact reports, and formal forensic expert reports when requested by the client. - Maintains contemporaneous forensic examination notes. - Expert Testimony (Written/Oral): - Provides expert testimony regarding investigative forensic findings. - Technical Consultancy and Support: - Serves as a technical consultant on data management and digital forensic methodology and concepts. - Provides technical guidance and assistance to staff involved in the investigation and litigation process to prevent evidence spoliation. - Quality Assurance and Legal Support: - Ensures all hardware and software are verified and validated according to established guidelines and the Federal Rules of Evidence. - Drafts affidavits, declarations, expert reports, and provides oral testimony in defense of forensic findings or processes. Qualifications - 9+ years of progressive technical experience demonstrating relevant skills in digital forensic collections and investigations. - Hands-on experience with digital forensic tools such as MetaSpike Forensic Email Collector (FEC), X-Ways, AccessData Forensic ToolKit (FTK), OpenText EnCase, Cellebrite UFED/PA, Cellebrite Digital Collector, Cellebrite Inspector, Magnet Forensics Axiom Cyber, Paraben E3, Fookes Aid4Mail, and GetData Forensic Explorer (FEX). - Experience with the chain of custody and evidence handling best practices. - Strong understanding and knowledge of disk structures, file systems, and forensic artifacts for modern operating systems for Windows and Apple computers. - Strong understanding, knowledge and experience of Microsoft Purview and Google Workspace and their metadata. - Experience applying forensic investigative and litigation support principles methodologies. - Excellent documentation and communication skills with technical report writing experience. - Ability to multitask and manage multiple projects and competing priorities simultaneously. - Capability to work independently and within a team environment. Requirements - 5+ years experience within the private sector of e-Discovery, performing collections of email, cloud sources, mobile devices, workstations, servers, and structured data. - 5+ years experience performing forensic investigations and analysis. - Experience testifying in civil or criminal courts in defense of forensic investigative findings. Authorization to Work in the U.S. - Candidates must be legally authorized to work in the United States without sponsorship now or in the future. - DISCO is not currently sponsoring visas, including, but not limited to, H-1B, TN, or EAD, and we are not accepting visa transfers. Benefits - Open, inclusive, and fun environment. - Benefits, including medical, dental and vision insurance, as well as 401(k). - Competitive salary plus RSUs. - Flexible PTO. - Opportunity to be a part of a company that is revolutionizing the legal industry. - Growth opportunities throughout the company.

United States
Eltropy Inc. logo

Senior Cybersecurity Analyst

Eltropy Inc.

Eltropy is on a mission to disrupt the way people access financial services. Eltropy enables financial institutions to digitally engage in a secure and compliant way. Using our world-class digital communications platform, community financial institutions can improve operations, engagement, and productivity. CFIs (Community Banks and Credit Unions) use Eltropy to communicate with consumers via Text, Video, Secure Chat, co-browsing, screen sharing, and chatbot technology — all integrated in a single platform bolstered by AI, skill-based routing, and other contact center capabilities. Customers are our North Star No Fear - Tell the truth Team of Owners Eltropy is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

Full TimeRemoteTeam 51-200

Role Description We are seeking a Senior Cybersecurity Analyst – GRC (Governance, Risk, and Compliance) to support and improve our security compliance and risk management program. This individual will help manage third-party audits, perform risk assessments, ensure ongoing compliance with security frameworks, and support business teams with customer and vendor assurance. You’ll work closely with security, engineering, legal, and customer teams to ensure Eltropy’s security posture remains strong, transparent, and audit-ready. - Assist in the preparation and execution of third-party audits and assessments, including SOC 2, PCI-DSS, NIST CSF, and ISO 27001. - Support the development and maintenance of Eltropy’s GRC program, ensuring alignment with business and regulatory requirements through well-defined policies, controls, and risk processes. - Respond to customer security questionnaires and due diligence requests. - Conduct and manage vendor security assessments, maintain risk tracking, and ensure third-party compliance. - Perform risk assessments across systems, tools, and business processes; manage mitigation plans and maintain an exceptions register. - Contribute to access governance, including quarterly access reviews, enforcement of least privilege, and identity and access documentation. - Draft, review, and update security policies, standards, and procedures to reflect current risk posture and best practices. - Lead or support security awareness programs to promote a risk-conscious culture among staff and end users. - Contribute to the development and testing of incident response and disaster recovery plans. - Monitor and analyze cybersecurity threats, trends, and technologies, and recommend enhancements to Eltropy’s security posture. - Help ensure the security of IT infrastructure by supporting the implementation and maintenance of measures against unauthorized access, cyber threats, and vulnerabilities. - Track and report on compliance status, audit readiness, and risk trends to key stakeholders. Qualifications - 3–5 years of experience in cybersecurity or IT risk/compliance, with a focus on GRC. - Familiarity with major frameworks like SOC 2, PCI-DSS, ISO/IEC 27001, and NIST CSF. - Experience supporting third-party audits or certifications. - Knowledge of risk management processes and frameworks. - Ability to respond to security due diligence questionnaires and document technical and organizational controls. - Understanding of access governance and identity lifecycle best practices. - Excellent communication, documentation, and stakeholder coordination skills. - Comfort with tools like Vanta, Drata, or similar GRC platforms. Preferred Skills - Experience in a SaaS, FinTech, or regulated technology environment. - Familiarity with cloud environments such as GCP, AWS, or Azure. - Understanding of security operations, incident response, or DevSecOps concepts. Certifications (Preferred But Not Mandatory) - CISA – Certified Information Systems Auditor - ISO 27001 Lead Auditor / Implementer - PCI ISA – Internal Security Assessor Company Description Eltropy is a rocket ship FinTech on a mission to disrupt the way people access financial services. Eltropy enables financial institutions to digitally engage in a secure and compliant way. Using our AI enabled digital conversations platform, community financial institutions can improve operations, engagement and productivity. - CFIs (Community Banks and Credit Unions) use Eltropy to communicate with consumers via Text, Video, Secure Chat, co-browsing, screen sharing and chatbot technology — all integrated in a single platform bolstered by AI, skill-based routing and other contact center capabilities. - Customers are our North Star - No Fear - Tell the truth - Team of Owners Eltropy is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

Worldwide
ND Energy logo

Senior Research Security Compliance Analyst

ND Energy

ND Energy's vibrant research community is developing clean and sustainable energy solutions for generations to come!

Full TimeRemoteTeam 11-50Since 2005H1B No Sponsor

• Provide support in the areas of export controls, research conflict of interest, and research security. • Identify, analyze, track, and communicate new and emerging federal, state, and sponsor research security legislation, policies, requirements, and resources. • Interpret complex regulatory guidance and provide clear recommendations to University leadership, researchers, and staff. • Facilitate compliance with federal, state, sponsor, and institutional requirements. • Provide high-level support related to research security, export controls and research conflict of interest aspects of sponsored projects. • Conduct initial reviews of international outside activities and agreements to assess research security and compliance considerations. • Conduct reviews of travel disclosures and provide briefings as needed. • Support the development, revision, and implementation of University policies, guidance documents, and resources. • Develop educational materials and provide outreach, training, and advisory support to researchers and staff to promote awareness and compliance. • Serve as a subject matter expert and advise internal stakeholders on mitigation and best practices. • Provide program management for sponsored projects, including coordinating project activities, engaging stakeholders, supporting recruitment efforts, and developing reports, products, and resources. • Manage multiple priorities in a dynamic regulatory environment while maintaining accuracy and attention to detail.

India
$125K / year