- Presencial
- Tempo inteiro
- Sénior
Descrição
Hovione is seeking a Cyber Defense Center Senior Security Engineer to architect and manage our SOAR ecosystem, designing and continuously improving automated playbooks, workflows, and response actions. You will lead detection engineering activities across SIEM, EDR, NDR, cloud, and OT security platforms, develop intelligence-driven detection and response capabilities, and conduct advanced threat hunting exercises leveraging MITRE ATT&CK methodologies.
In this role, you will own the global log ingestion and telemetry architecture, develop and maintain integrations between security platforms and enterprise systems through API-driven automation, and lead our Cyber Threat Intelligence enablement program. You will define and monitor engineering performance metrics including detection coverage, automation effectiveness, and alert quality, while evaluating and integrating emerging cybersecurity technologies to strengthen Hovione's Cyber Defense strategy.
Competências
- SOAR
- SIEM
- EDR
- NDR
- Detection Engineering
- CrowdStrike Falcon
- CrowdStrike Next-Generation SIEM
- CrowdStrike SOAR
- MITRE ATT&CK
- Threat Intelligence
- Threat Hunting
- Security Automation
- OT/ICS Cybersecurity
- Azure
- AWS
- API Integration
- Security Orchestration
- Log Ingestion
- Telemetry
- Scripting
Responsabilidades
- Architect and manage the Cyber Defense Center's SOAR ecosystem, designing, developing, and continuously improving automated playbooks, workflows, and response actions that streamline the alert-to-resolution lifecycle
- Lead detection engineering activities by developing, testing, tuning, and deploying detection content across SIEM, EDR, NDR, cloud, and OT security platforms using detection-as-code and CI/CD methodologies
- Design and maintain automated enrichment capabilities that integrate threat intelligence platforms, asset inventories, identity providers, vulnerability management tools, and enterprise security controls
- Own the global log ingestion and telemetry architecture, ensuring effective onboarding, normalization, enrichment, and quality management of security data from IT, cloud, OT, laboratory, and manufacturing systems
- Develop and maintain integrations between security platforms and enterprise systems, including ITSM, CMDB, identity management, vulnerability management, and security controls through API-driven automation
- Lead the Cyber Threat Intelligence (CTI) enablement program, managing intelligence collection, operationalization, and distribution through platforms such as MISP, OpenCTI, or commercial Threat Intelligence Platforms
- Build intelligence-driven detection and response capabilities, ensuring threat intelligence indicators and adversary techniques are continuously translated into actionable detections, hunting activities, and response playbooks
- Conduct advanced threat hunting exercises across endpoint, network, cloud, and OT environments, leveraging MITRE ATT&CK methodologies and intelligence-led hunting techniques
- Define, monitor, and report engineering performance metrics, including detection coverage, automation effectiveness, alert quality, analyst efficiency gains, MTTD, MTTR, and false-positive reduction
- Evaluate and integrate emerging cybersecurity technologies, contributing to the evolution of Hovione's Cyber Defense strategy through innovation, technical leadership, and cybersecurity architecture improvements
Empregos semelhantes
