Security Engineer - Incident Response

São Paulo, BRAFull-timeRisk and Compliance
Apply for this role

About CloudWalk

We're hiring a hands-on Insider Risk Security Engineer to build, tune, and operate our insider threat program. This is not a ticket-triage or compliance-report role. You'll be in the trenches analyzing user behavior, tuning detection engines, reconstructing timelines across our entire stack, and writing the automation that makes investigations faster, deeper, and more consistent. You'll act as the technical engine of our team, bridging security operations, detection engineering, and automation — while partnering discreetly with Legal, People, and IT to protect our most critical data from accidental exposure and malicious exfiltration. One day you're reconstructing a user's timeline across five platforms to determine if a data exfiltration happened. Next, you're writing a detection rule in YARA-L to catch that class of behavior going forward, or shipping a tool that automates the triage you just did manually.

About this role

  • Build our security nervous system. Own and improve the SIEM, telemetry pipelines, enrichment and correlation across CloudWalk.
  • Create detections that matter. Turn attacker behavior, real incidents and Red Team findings into useful signals instead of alert spam.
  • Respond when things get weird. Investigate incidents from first signal to containment, recovery and lessons learned.
  • Hunt before alerts fire. Search proactively for suspicious behavior and visibility gaps.
  • Automate aggressively. Build tools and workflows for triage, enrichment, evidence collection and containment.
  • Work with attackers. The friendly kind. Partner closely with Offensive Security to turn attack paths into detections and controls.
  • Use AI as leverage. Build agents and automations for investigation, log analysis, alert enrichment and response.

What You Need To Succeed

  • Hands-on Experience in a Security Operations Center (SOC), Cyber Threat Intelligence, Incident Response, Security Engineering, or dedicated Insider Threat role.
  • Investigative & Analytical Mindset: You know how to differentiate between a malicious data exfiltration event and an engineer who just doesn't understand the company's cloud storage policy.
  • Technical Chops: Deep, practical experience querying raw logs, writing detection rules, and understanding the data pipeline behind them — you don't just read dashboards, you go to the source.
  • Stack Familiarity (or ability to ramp fast): Google Workspace (Admin SDK, Reports API), Chronicle / Google SecOps (UDM Search, YARA-L), Wiz, SentinelOne (Deep Visibility), Jumpcloud, Tailscale, GCP Audit Logs and IAM. DLP/UEBA tools (e.g., Microsoft Purview, Proofpoint, Forcepoint, Varonis, Exabeam) and SIEM platforms (e.g., Splunk, Sentinel, CrowdStrike LogScale).
  • Scripting Skills: Proficiency in TypeScript (Python/bash a plus). You write tools and services others can rely on, not just one-off scripts.
  • Discretion & Ethics: Unwavering integrity and the ability to handle highly sensitive, confidential personnel investigations with strict adherence to privacy laws and company guidelines.
  • Communication: The ability to translate complex technical forensic findings into clear, non-technical summaries for People and Legal teams.

Nice to Have

  • Experience with insider threat detection, User and Entity Behavior Analytics, or building insider risk workflows.
  • Familiarity with fintech / payment industry security (PCI DSS, card data, Pix, acquiring flows).
  • Experience with LLM-powered security agents or AI-driven detection / triage automation.
  • Kubernetes / Istio service mesh context.

The Future We See

How We Think About Security Operations We don't want a SIEM because a compliance framework says we should have one. We want to know what is happening. Good detections should explain attacker behavior, not generate noise. Incidents should improve the system. Repetitive investigation should become automation. The goal is simple: combine telemetry, engineering, offensive security and AI so we can detect attacks quickly, understand them clearly and respond before a small problem becomes a very expensive one.