Cyber Security Specialist
Come Make an Impact on Millions of Brazilians! At RecargaPay , we're on a mission to deliver the best payment experience for Brazilian consumers and small businesses β by building a powerful digital ecosystem where the banked and unbanked connect, and where consumers and merchants have a one-stop shop for all their financial needs. We serve over 10 million users and process more than USD 4 billion annually. We've been profitable since 2022 and operate our own credit business. We are an AI-first, 100% remote team, scaling in the rapidly changing Brazilian financial market. Our goal? Deliver the best payment experience in Brazil for people and small businesses alike. We value autonomy, ownership, and a bias for action. We're looking for people who are curious, hands-on, and driven by impact β who want to solve real problems, work with strong teams, and rethink what's possible. If you're ready to do your best work, at scale, with purpose β this is your place.
Position Overview
RecargaPay is looking for a Cyber Security Specialist to be a hands-on technical practitioner within our CSIRT (Computer Security Incident Response Team). This person will own the detection, response, and containment of security incidents across our payments platform β executing the full incident lifecycle, building detection logic, and driving automation to shrink response time in a cloud-native, high-volume transactional environment.
Key Responsibilities
- Own the full incident response lifecycle end-to-end: detection, triage, containment, eradication, recovery, and post-mortem.
- Develop and maintain playbooks, runbooks, and response procedures that keep response sharp and repeatable.
- Build and maintain detection and response automations (SOAR) to orchestrate workflows across tools and reduce manual toil.
- Operate and continuously tune the detection stack on Elastic (Elasticsearch/Kibana): queries, dashboards, alerts, and event correlation.
- Maintain the Elastic infrastructure on Linux.
- Manage endpoint detection and response via CrowdStrike (EDR), including proactive threat hunting and containment actions.
- Investigate and respond to incidents in AWS (CloudTrail, GuardDuty, IAM, VPC, and related services).
- Produce incident reports and MTTD/MTTR metrics that give leadership clear visibility into the security posture.
- Collaborate with engineering, infrastructure, and compliance teams to remediate vulnerabilities and reduce the attack surface.
Requirements
Technical Skills
- Solid hands-on experience in security incident response in complex, high-volume environments.
- Strong command of Elasticsearch/Elastic Stack for detection, threat hunting, and alert creation. Experience with AWS security β native security services and cloud log investigation.
- Hands-on experience with CrowdStrike or an equivalent EDR. Workflow automation and orchestration using a SOAR or automation platform.
- Strong Linux proficiency (administration and hardening). Knowledge of BTT (BoitatΓ‘), Apura's threat intelligence tool. Experience with mTLS certificate lifecycle management and AWS ACM (Certificate Manager).
- Fluency with frameworks such as MITRE ATT&CK, NIST IR, and standard incident taxonomies.
Soft Skills
- Technical depth: owns a complex domain (CSIRT tooling and detection engineering) and drives improvements without needing direction. Independent judgment under pressure: makes sound containment decisions in fast-moving incidents with incomplete information.
- Cross-functional influence: translates security findings into clear, actionable guidance for engineering and infrastructure partners.
- Documentation discipline: keeps playbooks, runbooks, and post-mortems current so the team can operate without heroics.
- Continuous improvement mindset: proactively identifies detection gaps and proposes measurable improvements to MTTD/MTTR.
Nice to Have
- Background in financial services, fintech, or other high-volume t