Cybersecurity Threat Hunter

1 semana atrás


Porto Alegre, Rio Grande do Sul, Brasil beBeeSecurity Tempo inteiro US$90.000 - US$100.000

Job Overview

You will be working as a highly skilled security professional responsible for identifying and responding to malicious or suspicious activity across our environment with speed and confidence. This role involves leading the engineering work behind threat detection and response capabilities—designing scalable systems to detect threats and trigger automated responses.

As a cloud-first SaaS company, we generate large volumes of event data across identity, endpoint, infrastructure, and collaboration systems. The scale and complexity of this telemetry demand improved detection engineering and automation. This is a platform engineering role focused on building and operating a modern detection pipeline integrated with security automation workflows. You will use Python, structured data, and widely adopted frameworks for mapping adversary behaviors and response logic to drive faster, more effective security outcomes.

Responsibilities
  • Implement and operate detection systems, including a scalable cloud-native SIEM platform supporting ingestion from identity, endpoint, SaaS, and infrastructure sources.

  • Develop and maintain detection coverage maps aligned to MITRE ATT&CK techniques, threat modeling, and incident history.

  • Leverage AI to accelerate detection rule creation, enrichment, and triage insights, and conduct AI-assisted threat hunting to surface novel behaviors and codify them as deterministic detections.

  • Build detection observability tools and dashboards to monitor rule effectiveness, alert volumes, and system performance.

  • Design and implement SOAR workflows and automated response playbooks with built-in observability, rollback, and reliability controls.

  • Leverage AI within SOAR for adaptive enrichment, workflow generation, and documentation, while continuously tuning automation based on incident outcomes.

  • Lead incident response activities as part of the incident commander rotation, and drive continuous improvement of runbooks and playbooks using lessons learned and AI support for timelines and summaries.

  • Collaborate cross-functionally with engineering and business stakeholders to embed detection and response into system design, operational processes, and organizational priorities.

Qualifications
  • Required:

    • 5+ years in security engineering, detection engineering, or threat-focused automation roles.
    • Strong knowledge of MITRE ATT&CK framework, detection logic, and IOC/IOA patterns.
    • Familiarity with MITRE D3FEND for defense-in-depth and response playbook design.
    • Hands-on experience designing, deploying, or managing SIEM platforms (vendor-neutral mindset preferred).
    • Strong Python scripting skills for integrations, enrichment logic, and playbook development.
    • Experience working with structured data formats such as JSON, YAML, logs, and metrics.
    • Familiarity with SaaS logging constraints and cloud-native telemetry, preferably AWS.
    • Understanding of event-driven architecture and API-driven integrations.
    • Demonstrated ability to use AI tools to accelerate scripting, generate or translate detection rules, or assist with enrichment workflows, always with human validation for accuracy.
    • Comfortable working autonomously and cross-functionally to deliver reliable detection outcomes.
  • Preferred:

    • Experience building or maintaining detection pipelines using Elastic, Panther, or similar platforms.
    • Experience with detection-as-code practices, managing detection logic as version-controlled code with testing and CI/CD.
    • Experience writing detection rules in formats such as Sigma, including contributing to open-source or internal detection libraries.
    • Experience with MITRE frameworks: ATT&CK, D3FEND, and ATLAS.
    • Experience with OWASP guidance on application telemetry and detection (e.g., AppSensor, Logging Cheat Sheet).


  • Porto Alegre, Rio Grande do Sul, Brasil beBeeResponsibility Tempo inteiro R$65.000 - R$85.000

    Job Title: Threat Intelligence LeadThe Threat Intelligence Lead will own Canonical's threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques and Procedures (TTP) to better our products and internal cybersecurity controls.You will collaborate...

  • Cybersecurity Specialist

    1 semana atrás


    Porto Alegre, Rio Grande do Sul, Brasil beBeeSecurity Tempo inteiro US$100.000 - US$150.000

    Senior Cybersecurity SpecialistThis is a challenging position for an experienced Cybersecurity Specialist who can design and implement scalable systems to detect threats and trigger automated responses.We are looking for someone with the ability to integrate Artificial Intelligence into detection and response workflows to accelerate rule development,...

  • Threat Intelligence Lead

    3 semanas atrás


    Porto Alegre, Rio Grande do Sul, Brasil Canonical Tempo inteiro

    3 months ago Be among the first 25 applicants Get AI-powered advice on this job and more exclusive features. The Threat Intelligence Lead will own Canonical's threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques and Procedures (TTP) to...


  • Porto Alegre, Rio Grande do Sul, Brasil Canonical Tempo inteiro

    3 months ago Be among the first 25 applicants Get AI-powered advice on this job and more exclusive features. The Threat Intelligence Lead will own Canonical's threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques and Procedures (TTP) to...

  • Global Cybersecurity Leader

    1 semana atrás


    Porto Alegre, Rio Grande do Sul, Brasil beBeeSecurity Tempo inteiro R$132.450 - R$158.500

    Chief Security Strategist RoleThis leadership position in cyber security oversees the development of comprehensive security strategies, responsible for managing a team that designs, implements, and evolves Canonical's security practices, techniques, tools, systems, and policies.Key Responsibilities:Lead the selection, mentoring, and growth of technical...

  • Cybersecurity Leader

    1 semana atrás


    Porto Alegre, Rio Grande do Sul, Brasil beBeeSecurity Tempo inteiro R$28.000 - R$40.000

    Job DescriptionOur organization is seeking a seasoned security expert to lead efforts in protecting our information systems from potential threats and vulnerabilities.Develop, implement, and maintain robust security strategies, policies, and procedures to safeguard our data and IT assets.Ensure alignment of security initiatives with business objectives and...


  • Porto Alegre, Rio Grande do Sul, Brasil Infomach Tempo inteiro

    Buscamos um Consultor de Vendas ( Atuar como Hunter) dinâmico e experiente para impulsionar o crescimento de nossos serviços de Cybersecurity, Nuvem AWS e Inteligência Artificial em Porto Alegre e região.O profissional será responsável por prospectar, qualificar e fechar negócios, atuando como um especialista consultivo para nossos...


  • Porto Alegre, Rio Grande do Sul, Brasil Infomach Tempo inteiro R$104.000 - R$130.878 por ano

    Buscamos um Consultor de Vendas ( Atuar como Hunter) dinâmico e experiente para impulsionar o crescimento de nossos serviços de Cybersecurity, Nuvem AWS e Inteligência Artificial em Porto Alegre e região. O profissional será responsável por prospectar, qualificar e fechar negócios, atuando como um especialista consultivo para nossos...


  • Porto Alegre, Rio Grande do Sul, Brasil Infomach Tempo inteiro

    Buscamos um Consultor de Vendas ( Atuar como Hunter) dinâmico e experiente para impulsionar o crescimento de nossos serviços de Cybersecurity, Nuvem AWS e Inteligência Artificial em Porto Alegre e região. O profissional será responsável por prospectar, qualificar e fechar negócios, atuando como um especialista consultivo para nossos clientes....


  • Porto Alegre, Rio Grande do Sul, Brasil beBeeInformation Tempo inteiro R$90.000 - R$120.000

    Senior Information Security ProfessionalThis position is ideal for an experienced and highly skilled information security professional seeking to leverage their expertise in a dynamic organization. As a Senior Information Security Analyst, you will be responsible for leading efforts to protect our organization's information systems from security threats and...