Назад
Company hidden
4 часа Π½Π°Π·Π°Π΄

Senior Security Analyst - SOC/CTI (Fintech)

Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
onsite
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
senior
Английский
c1
Π‘Ρ‚Ρ€Π°Π½Π°
Brazil
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Senior Security Analyst - SOC/CTI (Fintech): Detecting, investigating, and neutralizing threats targeting payment infrastructure, digital assets, and customer data with an accent on real-time SOC operations, cyber threat intelligence, and threat hunting. Focus on leading incident response, mapping adversary TTPs with MITRE ATT&CK, enriching detection engineering, and prioritizing vulnerabilities across on-premises and cloud environments.

Location: Curitiba, Brazil β€” on-site

Company

hirify.global is a global fintech and payments platform connecting digital businesses with customers across 21 high-growth markets.

What you will do

  • Lead threat detection, monitoring, triage, incident response, and forensic investigations across SIEM, EDR/XDR, and cloud-native security tools.
  • Produce and operationalize cyber threat intelligence on threat actors, TTPs, malware families, and campaigns targeting fintech and payment infrastructure.
  • Lead intelligence-driven threat hunting across on-premises and AWS and Azure cloud environments.
  • Develop and tune detection rules, correlation logic, and threat models to reduce dwell time and false positives.
  • Assess vulnerabilities and CVEs against the attack surface, prioritize remediation, and coordinate with IT and development teams.
  • Support PCI-DSS, ISO 27001, LGPD, and other security audits while producing technical and executive-level intelligence reports.

Requirements

  • Hands-on L2/L3 SOC experience in incident handling, threat detection, and security monitoring across on-premises and cloud environments.
  • Proven cyber threat intelligence experience, including threat actor tracking, malware and campaign analysis, and actionable intelligence reporting.
  • Deep knowledge of MITRE ATT&CK, adversary profiling, TTP mapping, threat modeling, and ATT&CK Navigator.
  • Experience conducting structured threat-hunting missions with behavioral analytics and custom queries such as KQL or SPL.
  • Strong proficiency with SIEM, EDR/XDR, threat intelligence platforms, sandbox environments, and cloud-native security tools.
  • Advanced English required for producing and presenting intelligence to technical and executive audiences; at least one required certification must be held: GIAC GCTI, GIAC GCIH, GIAC GCIA, CompTIA CySA+, or eCTHP.

Nice to have

  • Experience with fintech or payments threat landscapes, fraud patterns, and payment infrastructure threats.
  • Experience with PCI-DSS, ISO 27001, and SOC 2 governed environments.
  • Additional certifications such as GIAC GCED, CHFI, eCDFP, BTL2, AWS Certified Security β€” Specialty, or Azure Security Engineer Associate.
  • Experience with MISP, OpenCTI, YARA, or Sigma rules.

Culture & Benefits

  • Annual performance bonus based on company results.
  • Monthly meal allowance and medical and dental plans with dependent coverage.
  • Financial assistance for undergraduate, graduate, and MBA programs.
  • Budget for courses, certifications, and workshops, plus language classes.
  • Semi-flexible hours, a birthday day off, year-end break, and well-being programs.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’