- Location
- Sao Paulo, BR
- Workplace
- Remote
- Type
- Full-time
- Department
- Operations
- Source
- Breezy HR
Description
Position: Senior Security Operations (SOC) Analyst (Off-Hours)
Location: Remote
Contract Type: Full-time vendor (Direct contract with Inallmedia.com)
Time Zone Alignment: Eastern Time (ET) / Evening & Overnight Coverage
🧭 About Inallmedia.com Inallmedia.com is a global technology and design firm focused on building impactful digital solutions through remote, distributed teams across LATAM. We partner with international clients across industries, providing long-term technical expertise, product innovation, and team augmentation.
🚀 Project Overview You will join a high-performing cybersecurity team expanding its Security Operations capability toward a 24x7 operating model for a major international client. As a Senior SOC Analyst, your primary focus will be extending daytime Security team coverage during evening and overnight weekday hours. Because first-level monitoring capabilities are already established, you will operate at a senior (L2/L3) level—owning escalated security events, driving incident response, and using lower-volume periods to improve detection engineering, threat hunting, and SOAR automation.
🔍 Key Responsibilities
- Off-Hours Incident Management: Own escalated security events from initial triage through resolution, containment, or senior escalation during weekday evening and overnight hours.
- Multi-Layered Investigation: Investigate complex activity across SIEM, EDR, identity, network, and email security tools while accurately distinguishing false positives from true security incidents.
- Documentation & Shift Handoffs: Maintain clear, detailed documentation of security events and lead structured shift handoffs for seamless transition with the daytime SecOps team.
- Detection Tuning & False-Positive Reduction: Analyze alert patterns during lower-volume periods to refine rules and optimize detection logic.
- Automation & Playbooks: Identify opportunities for security automation (SOAR) and contribute to continuous playbook improvements.
- Backlog Delivery & Threat Hunting: Proactively drive SecOps backlog initiatives, including threat hunting hypotheses and operational capability upgrades.
💡 Must-Have Skills
- Experience Level: 5+ years of relevant experience in cybersecurity and Security Operations (SOC) environments.
- Incident Response & SIEM: Deep expertise in SIEM investigation, end-to-end incident response, and triage of complex security events.
- Endpoint Fundamentals: Strong proficiency in Endpoint Detection and Response (EDR) platforms and endpoint security fundamentals.
- Autonomy & Analytical Rigor: Excellent troubleshooting skills with the ability to work independently and make sound containment decisions under limited supervision.
- Operational Drive: Proactive mindset focused on identifying operational bottlenecks and driving continuous SecOps improvements.
- English Proficiency: Fluent spoken and written English for shift handoffs, reporting, and team collaboration.
🌟 Nice-to-Have Skills
- Tooling & Platforms: Direct experience with Splunk / Splunk ES / Splunk SOAR, SentinelOne, CrowdStrike, Microsoft Defender, or Google SecOps.
- Detection & Frameworks: Experience in detection engineering, rule tuning, threat hunting, and applying the MITRE ATT&CK framework.
- Automation & Scripting: Proficiency in Python or general scripting alongside hands-on SOAR integration experience.
- Cloud & Vulnerability Management: Exposure to AWS/Cloud security environments and vulnerability management tools like Tenable.
🌐 Time Zone & Collaboration This role requires dedicated coverage during weekday evening and overnight hours aligned with US Eastern Time (ET).
💬 Language All interviews, documentation, and daily communication will be in English.
#LI