Sr. Cyber Security Analyst
- Come Make an Impact on Millions of Brazilians! At RecargaPay , we're on a mission to deliver the best payment experience for Brazilian consumers and small businesses โ by building a powerful digital ecosystem where the banked and unbanked connect, and where consumers and merchants have a one-stop shop for all their financial needs. We serve over 10 million users and process more than USD 4 billion annually. We've been profitable since 2022 and operate our own credit business. We are an AI-first, 100% remote team, scaling in the rapidly changing Brazilian financial market. Our goal? Deliver the best payment experience in Brazil for people and small businesses alike. We value autonomy, ownership, and a bias for action. We're looking for people who are curious, hands-on, and driven by impact โ who want to solve real problems, work with strong teams, and rethink what's possible. If you're ready to do your best work, at scale, with purpose โ this is your place.
Position Overview
RecargaPay is looking for a Senior Cyber Security Analyst to join our CSIRT (Computer Security Incident Response Team). Reporting to the CSIRT Coordinator, this person will be a hands-on individual contributor focused on Detection & Response (Blue Team) โ investigating, containing, and eradicating security incidents across our cloud-native, high-volume payments platform, and continuously improving our detection coverage and automations.
Key Responsibilities
- Act as a senior responder across the full incident lifecycle: detection, triage, containment, eradication, recovery, and post-mortem.
- Perform threat hunting and proactive investigation across endpoints, cloud, and network telemetry.
- Build, tune, and maintain detection rules, dashboards, and alerts on Elastic (Elasticsearch/Kibana), reducing false positives and improving signal quality.
- Develop and maintain detection and response automations (SOAR) to orchestrate workflows and reduce manual toil.
- Investigate and respond to endpoint incidents via CrowdStrike (EDR), including containment and root-cause analysis.
- Investigate and respond to incidents in AWS (CloudTrail, GuardDuty, IAM, VPC, etc.).
- Conduct log analysis and investigation across Linux systems.
- Contribute to and maintain playbooks, runbooks, and response procedures. Produce clear incident documentation, timelines, and lessons-learned reports.
- Collaborate with engineering, infrastructure, and compliance teams to remediate vulnerabilities and strengthen the security posture.
Requirements
Technical Skills
- Solid hands-on experience as a security analyst in a SOC/CSIRT or Blue Team, handling real incidents end to end. Strong command of Elasticsearch/Elastic Stack for detection engineering, hunting, and alerting.
- Experience with AWS security (native security services and cloud log investigation).
- Hands-on experience with CrowdStrike or an equivalent EDR.
- Workflow automation and orchestration using a SOAR/automation platform. Strong Linux proficiency (administration, hardening, and log analysis).
- Fluency with frameworks such as MITRE ATT&CK, NIST IR, and incident taxonomies. Soft Skills Strong analytical skills and ability to stay effective under pressure during active incidents.
- Hands-on ownership: takes full responsibility for incidents assigned, seeing them through from alert to closed post-mortem without hand-holding.
- Detection craft: proactively identifies gaps in coverage and improves rule quality โ doesn't just work the queue. Clear communication under pressure: keeps stakeholders informed during active incidents with concise, accurate updates.
- Collaborative remediation: works effectively with engineering and infrastructure partners to close vulnerabilities, not just document them.
- Continuous learning: stays current on the threat landscape relevant to fintech/payments and brings relevant insights back to the team.
Soft Skills
- Strong analytical skills and ability