Security Operation Center (SOC) Engineer
Sao Paulo, São Paulo, BR
Overview
The SOC Engineer is responsible for cybersecurity readiness of CIL’s operational technologies and mitigating security events or incidents. As part of the SOC team, the SOC Engineer is responsible for detecting, analyzing, and responding to security incidents, implementing security controls in a fast-paced and dynamic environment, while also leveraging automation and playbooks to streamline processes.
Main Duties and Responsibilities
- Monitor security events and alerts, investigate security incidents, and respond promptly to mitigate potential threats using tools such as Microsoft Sentinel (SIEM) and Defender.
- Proactively search for hidden threats and vulnerabilities across systems, networks, and applications to identify potential risks and ensure ongoing protection.
- Develop and maintain automated workflows, playbooks, and processes to enhance incident response times and improve SOC operational efficiency.
- Continuously analyze security data, identify anomalies, and provide actionable insights for improving security posture within CIL.
- Proactively collaborate with different IT teams to develop high security maturity.
Responsibilities scope
- Security Monitoring and Analysis: Continuously monitor security dashboards, event logs, and alerts to identify, analyze, and respond to potential threats in real-time.
- Threat Intelligence Integration: Leverage threat intelligence feeds and external sources to enhance threat detection capabilities and stay ahead of emerging threats.
- Automation and Playbook Optimization: Create, maintain, and optimize security automation processes and playbooks to improve response times and incident management efficiency.
- Incident Management: Lead the investigation and resolution of security incidents, ensuring proper documentation, root cause analysis, and follow-up actions are taken.
- Security Tool Management: Administer and fine-tune Microsoft Sentinel, Defender, and other security tools used to ensure optimal effectiveness in detecting and mitigating risks.
- Cross-team Collaboration: Work closely with other IT, security, and compliance teams to ensure alignment of security strategies, policies, and incident response procedures.
- Documentation and Reporting: Document security configurations, processes, and procedures. Generate regular reports on security posture, incidents, and progress towards security goals.
Reporting
- Direct reporting line to SOC manager.
Required Competencies
- Team spirit
- Proactive approach
- Excellent communication skills
- Proficient level of English (Min. B level) and Portuguese
- Strong analytical skills, ability to identify practical / pragmatic solutions.
- Time management / planning - effectively managing personal workload
Required Experience
- Experience in security.
- Previous experience with security solutions (FW, Proxy, SIEM).
- Previous experience in Cloud environment (AWS, Azure or other).
Required Education
- University degree
- IT or Security certification (Such as Azure / Compliance / CISSP, CEH, etc.)
Travel
Occasional International Travel might be needed