Information Security Analyst
Location
Brazil
Posted
8 days ago
Salary
0
Seniority
Senior
Job Description
Information Security Analyst
Hitss Brasil
• Work in a complementary capacity to the Security Operations Center (SOC), performing specialized handling, containment, and response activities for cyber events and incidents; • Conduct threat intelligence, Threat Hunting, and Purple Team activities to proactively identify risks and threats to the technology environment; • Perform in-depth analysis of security logs and digital forensics to investigate cyber events and incidents; • Develop and use automations with languages such as Python, PowerShell, or Bash to support detection, containment, and mitigation processes; • Periodically assess the technology environment to identify vulnerabilities and security gaps in servers, systems, and images; • Apply vulnerability remediations and hardening configurations to strengthen the security of technology assets and reduce cyber risks.
Job Requirements
- Bachelor's degree in Information Technology or a related field;
- Postgraduate degree or MBA in the relevant area;
- Knowledge of technical English.
- Preferred qualifications**
- ITIL Foundation v4 certification or higher.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
• Lead detection and response for incidents affecting: Manufacturing systems (OT/ICS), Connected medical/surgical devices, Enterprise IT environments • Manage SOC operations with prioritization of IT security, production integrity, and supply chain impact • Investigate and respond to incidents involving: Intellectual property theft, Disruptions and/or ransomware affecting production lines, IT vulnerabilities • Partner with IT, production, and engineering to embed secure-by-design principles across the IT & product lifecycle • Conduct threat modeling and security risk assessments for surgical and medical devices • Support compliance with: IT security guidance, SOX, ISO27001, EU GDPR / NIS2 • Identify and remediate product vulnerabilities (secure firmware, APIs, connectivity) • Secure manufacturing environments (plants, production lines, robotics, control systems) • Lead vulnerability and patch management for industrial control systems • Reduce risk to production continuity and product integrity • Monitor threat landscape with emphasis on: Nation-state attacks targeting IP, Supply chain compromise, Medical device exploitation • Implement Zero Trust principles across corporate IT and manufacturing environments • Ensure alignment with: SOX, ISO 27001, NIST CSF / NIST 800-53, Global data protection regulations (GDPR where applicable)
Senior Cyber Security Analyst
Healthmap SolutionsHealthmap Solutions is a kidney population health management company accredited by the National Committee for Quality Assurance (NCQA). The organization uses ad
Role Description Healthmap Solutions is seeking a Senior Cyber Security Analyst to drive the day-to-day activity in our cyber engineering practice. The ideal candidate will be responsible for responding to alerts from the Security Operations Center, supporting security incidents, and driving vulnerability and patch management resolution with Infrastructure partners. The Senior Cyber Security Analyst is a critical resource responsible for protecting an organization's computer networks, systems, and data from cyber threats, breaches, and unauthorized access. - Monitoring & Detection: Continuously monitoring network traffic and system logs for suspicious activity, often using SIEM (Security Information and Event Management) tools. - Incident Response: Investigating security alerts, leading or supporting the response to breaches, and performing root-cause analysis to prevent recurrence. - Vulnerability Management: Conducting regular vulnerability scans and penetration tests to identify and patch security weaknesses before they can be exploited. - Compliance & Policy: Ensuring the organization adheres to regulatory frameworks (e.g., HIPAA, GDPR, PCI-DSS, NIST) and maintaining internal security policies. - Security Architecture: Assisting in the implementation of security measures like firewalls, VPNs, encryption, and endpoint protection software. - Communication: Acting as a bridge between technical teams and leadership by translating complex security risks into actionable business insights. - Perform other duties as assigned. Qualifications - Bachelor’s degree in cyber security (or) related degree or equivalent work experience. - 5 years’ experience in IT or security related roles. - Certified Information Security Systems Professional (CISSP) preferred. - Demonstrated competency in cloud environments. - Proficiency in network protocols (TCP/IP), operating systems (Windows/Linux), scripting (Python/PowerShell), and common security tools (Splunk, CrowdStrike, etc.). - Analytical thinking, problem-solving, strong attention to detail, and the ability to explain security concepts to non-technical stakeholders. - Performing Information Security/Information Technology risk assessments experience. - Ability to align security and compliance objectives with the broader business goals and growth strategy. - Proven track record of scaling GRC programs, often using tools like ServiceNow GRC, Archer, or OneTrust. - Knowledge of frameworks such as NIST, ISO 27001, and various regional/industry-specific regulations. Requirements - Ability to effectively prioritize and execute tasks in a high-pressure environment. - Excellent Customer service skills. - Calm and confident under pressure. - Collaboration and Conflict management. Working Conditions - All roles require: - Sitting: Ability to sit for extended periods stationary or while driving. - Dexterity/Effort: Repetitive motion for typing and/or texting; good manual dexterity for handling packages, paperwork, operation of motor vehicles and/or electronic devices. - Sense Acuity: Ability to see/read computer monitors or other electronic devices. - Additionally, on-site or at location positions (ex. Mailroom, IT or Admin) may require: - Lift/Carry/Push/Pull: Occasional movement of equipment, or materials up to 50/75 Pounds. - Bend/Twist: Occasional bending, twisting, and stooping; occasional need to kneel or crouch. - Additionally, traveling positions (ex. Field Care Navigators or Quality Practice Advisors) may require: - Sense Acuity: Ability to see/read road signs, maps, and electronic devices; good visual acuity for driving, including peripheral vision and depth perception. - Environmental: Possible exposure to travel, traffic and/or other outdoor hazards; possible exposure to various weather conditions, including extreme heat, cold, rain, and snow.
Role Description Join our team as a Cybersecurity Analyst, where you'll play a critical role in assessing and analyzing cybersecurity documentation for client information systems. You'll apply your scripting skills to develop and improve automations that streamline our assessment processes. Your work will align with FISMA, NIST RMF for Federal Civilian Agencies, RMF for DoD/DoW IT, FedRAMP, and departmental standards, with a primary focus on FedRAMP. - Engage directly with clients through verbal communication to perform interviews for assessments, understand their needs, and provide effective solutions. - Conduct comprehensive assessments by analyzing cybersecurity documentation and performing evidence collection, interviews, and tests to evaluate compliance with relevant standards such as FISMA, NIST RMF, and FedRAMP. - Create scripts and utilize scripting skills to automate repetitive tasks and improve the efficiency of security assessments, reporting, and evidence collection. - Conduct system and network vulnerability scanning and analysis using tools such as Nessus/ACAS, SCC, and DISA STIGs/STIG Viewer. - Prepare clear and accurate reports and documentation, with an emphasis on creating scripts to automate analysis and report generation. - Work independently or as part of a client delivery team in a fast-paced, deadline-driven, remote environment. - Travel up to 25% for client engagements as required. Qualifications - Strong verbal communication skills with the ability to articulate ideas clearly and confidently in face-to-face and phone interactions with clients. - Basic knowledge of Cloud Computing, FedRAMP, FISMA, NIST/DoD RMF, and NIST SP 800-series publications. - Demonstrable scripting skills in at least one language (e.g., Python, PowerShell, Bash) for task automation. - Beginner knowledge of testing tools such as Nessus/ACAS, SCC, DISA STIGs/STIG Viewer. - Strong organizational, planning, and attention to detail skills. - Self-motivated with a strong technical aptitude. - Must obtain a FedRAMP required (A2LA R311) industry certification within 3 months. Requirements - High School diploma, Technical Certifications, and a Bachelor's Degree in Engineering, Information Systems, Technology, or related field. - Must be a U.S. citizen with the ability to obtain a security clearance as required by our government customers. Benefits - Incentive Bonus Plans - Medical, Dental, Vision benefits - 401K with Company Match - 10 Paid Holidays - Generous Paid Time Off Packages - Employee Stock Purchase Plan - Paid Parental & Family Leave - and more! Technical Certifications - Cisco Certified Network Associate Security (CCNA Security) - Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops) - Cybersecurity Analyst (CySA+) - GIAC Certified Incident Handler (GCIH) - GIAC Systems and Network Auditor (GSNA) - GIAC Certified Intrusion Analyst (GCIA) - Certified Information Systems Auditor (CISA) - Certified Information System Security Professional or Associate (CISSP or Associate) - Certified Secure Software Lifecycle Professional (CSSLP) - Certified Information Systems Security Officer (CISSO) - CyberSec First Responder (CFR) - CompTIA Advanced Security Practitioner Continuing Education (CASP+) Continuing Education (CE) - CompTIA Cloud+ (Cloud+) - Global Industrial Cyber Security Professional (GICSP) - Securing Cisco® Networks with Threat Detection Analysis (SCYBER) Preferred Qualifications - 1+ years of experience in performing or participating in FISMA-based security Assessment and Authorization (A&A) activities. - Experience in creating and maintaining scripts for cybersecurity tools and processes, such as vulnerability scanning or compliance checks. - Proficiency in performing technical assessments using standard industry tools such as Nessus, DB Protect, Acunetix, and ACAS (for DoD). - Ability to identify and mitigate cyber security risks through formal assessment activities. - Experience and technical knowledge in security engineering, secure architecture development, system and network security, authentication and security protocols, applied cryptography, and application security.
Role Description As our AI and Cloud Security Analyst, you provide day-to-day L2 coverage of the AI security detection fabric — triaging and supporting investigation of AI-specific detections from runtime defense, behavioral/intent monitoring, model-security, and adversarial-testing platforms. You turn that telemetry into insight through data analytics and produce the OCR (operational, compliance, and risk) reporting that gives leadership, control owners, and auditors a continuous picture of AI and cloud risk. You also help monitor the security posture of our Azure, AWS, and GCP environments. You escalate to a dedicated L3 engineer and work alongside two AI & Cloud Security Architects. Responsibilities - L2 coverage of the AI Security toolset - Monitor AI security detections across the detection fabric — runtime defense/AIDR events, intent and behavioral anomalies, model-level detections, and adversarial-testing signals. - Validate detections, classify severity and impact, propose and implement policy updates, and escalate complex cases to L3 with complete, reusable context. - Investigate AI-specific events across all five AI archetypes: - Embedded SaaS copilots - Low-code/no-code agents - Homegrown agentic pipelines - Device-based coding agents - Homegrown models - Support the AI asset-intelligence layer - Data analytics: Query and correlate AI and security telemetry (KQL), identify anomalies and attack patterns, and build/maintain dashboards tracking the program's key metrics. - OCR reporting (operational, compliance, and risk): Produce recurring dashboards and executive summaries communicating AI-security posture, KPIs, and trends to stakeholders and control owners. - Maintain rigorous case documentation and shift/handover notes. - Build working fluency in the OWASP Top 10 for LLM Applications 2025, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS. - Monitor and triage cloud security alerts across Azure, AWS, and GCP from company CSPM platform. - Support cloud compliance monitoring and reporting against CIS Benchmarks and NIST 800-53 r5 / CSF 2.0 baselines. - Assist with cloud workload vulnerability triage (VMs, containers, images) and with Microsoft 365 / Google Workspace security-signal review. - Partner with the L3 engineer, SOC, cloud teams, and incident responders on investigations and enrichment spanning cloud, identity, endpoint, and AI telemetry. Qualifications - Solid security operations fundamentals: alert monitoring, triage, validation, incident classification, escalation, and case management against SLAs. - Strong data analytics and reporting: KQL (and/or SQL) for querying and correlation; dashboard and report development. - Foundational AI/GenAI security awareness: LLM risks, agentic AI and MCP concepts, AI guardrails, and familiarity with the OWASP LLM Top 10 and MITRE ATLAS. - Working knowledge of cloud security in at least one of Azure/AWS/GCP. - Scripting for automation and enrichment (PowerShell and/or Python). - Familiarity with CIS Benchmarks and NIST (800-53, CSF); awareness of NIST AI RMF and the EU AI Act is beneficial. - Analytical rigor, attention to detail, and clear English communication across a globally distributed team. Requirements - Experience in SOC, security operations, cloud security, or security-analyst role with hands-on monitoring, triage, and investigation experience. - Demonstrable experience producing analytics, dashboards, and reporting from security telemetry for technical and executive audiences. - Experience supporting compliance or audit evidence collection (NIST, CIS, ISO, or similar) is a plus. - Certifications are an advantage, not mandatory: CompTIA Security+, CySA+, SC-200, SC-900, AZ-500, AWS or GCP security/foundational credentials. - Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience. Working Conditions - Willing to work nonstandard business hours for projects, business impact issues, and incident response. - Some travel required. - Flexible remote work. Benefits - Elective Benefits: Tailored to your country to best accommodate your lifestyle. - Grow Your Career: Accelerate your path to success with formal programs on leadership and professional development. - Elevate Your Personal Well-Being: Boost your financial, physical, and mental well-being through seminars, events, and our global Life Empowerment Assistance Program. - Diversity, Equity & Inclusion: Valuing every voice is how we succeed. - Make the Most of our Global Organization: Network with other new co-workers within your first 30 days through our onboarding program. - Connect with Your Community: Participate in internal, peer-led inclusive communities and activities.




