- Presencial
- Tempo inteiro
- Sénior
Descrição
Hovione is seeking a Cyber Defense Center Senior Analyst to join our global team and help protect our organization's critical infrastructure and operations. In this pivotal role, you will support the implementation and continuous evolution of Hovione's Cyber Defense strategy while performing triage, analysis, and coordination of security alerts, events, and incidents. You will lead investigations of complex cybersecurity incidents including ransomware and advanced persistent threats, and operate as a key stakeholder within our CSIRT function.
You will develop and maintain detection use cases, SIEM correlation rules, and SOAR automation workflows to increase operational effectiveness. Your responsibilities include conducting proactive threat hunting activities, managing our SIEM platform, and collaborating with internal and external stakeholders during significant cyber events. Additionally, you will support cybersecurity monitoring across Operational Technology (OT) and Industrial Control System (ICS) environments, and contribute to Business Continuity and Disaster Recovery preparedness through tabletop exercises and cyber simulations.
Competências
- CrowdStrike Falcon
- CrowdStrike Next-Generation SIEM
- CrowdStrike SOAR
- SIEM management
- Security event correlation
- Incident response
- Threat hunting
- MITRE ATT&CK
- Cyber threat intelligence
- OT/ICS cybersecurity
- Ransomware analysis
- Advanced persistent threat (APT) analysis
- Digital risk monitoring
- Playbook development
- SOAR automation
Responsabilidades
- Support the implementation and continuous evolution of Hovione's Cyber Defense strategy, operational roadmap, and security monitoring capabilities aligned with business, regulatory, and risk management requirements
- Perform triage, analysis, classification, escalation, and coordination of security alerts, events, and incidents, ensuring timely and effective response activities
- Lead and coordinate investigations of complex cybersecurity incidents, including ransomware, advanced persistent threats (APT), supply chain attacks, and insider threat scenarios
- Operate as a key stakeholder within the CSIRT function, supporting incident containment, eradication, recovery efforts, post-incident reviews, and lessons learned initiatives
- Develop, maintain, and continuously improve detection use cases, SIEM correlation rules, SOAR automation workflows, playbooks, and runbooks to increase operational effectiveness and reduce false positives
- Conduct proactive threat hunting activities leveraging threat intelligence, MITRE ATT&CK methodologies, behavioral analytics, and emerging threat indicators
- Manage and optimize Hovione's SIEM platform, ensuring effective log collection, integrations, correlation logic, monitoring coverage, and alerting capabilities
- Collaborate with internal and external stakeholders, including managed security providers, national CERTs, regulatory authorities, and law enforcement agencies during significant cyber events
- Support cybersecurity monitoring and incident response activities across Operational Technology (OT) and Industrial Control System (ICS) environments, ensuring business continuity and operational resilience
- Contribute to Business Continuity and Disaster Recovery (BCDR) preparedness by participating in tabletop exercises, cyber simulations, response testing, and resilience improvement initiatives
Empregos semelhantes
