Monster Jobs lê cada vaga aberta e diz, de 0 a 100, o match dela com o seu currículo — de graça. Você está vendo esta página sem a parte mais importante dela: a sua.

?

Pode ser 94. Pode ser 31.

O ponteiro só crava quando lemos o seu currículo. Leva 1 minuto, de graça.

DOSSIÊ MJ-9024 · ACESSO PARCIAL

Analista de SOC Pleno (L2)

Shield Consulting · São Paulo, Brasil

PresencialNão informadoSênior

Esta é 1 de 75.386 vagas encontradas nos últimos 30 dias. Nós comparamos todas com o seu currículo — hoje, esta página nem sabe quem você é.

Grátis, sem cartão. Só o seu currículo.

Encontrada há 5 dias

Se candidatar no escuro custa uma noite.
Saber custa um minuto.

A conta que ninguém faz

Você, sozinho, numa noite

~20

vagas abertas e lidas uma a uma — a maioria descartada no terceiro parágrafo, quando o requisito que você não tem finalmente aparece. Dias assim, toda semana.

O Monster Jobs, enquanto isso

75.386

vagas já lidas e entendidas, prontas para ganhar nota contra o seu currículo no momento em que ele chegar. Você não procura mais vaga — recebe as que merecem a sua atenção.

Recrutador faz triagem de candidato.
Aqui, o recrutador é você — de vagas.

Cada uma chega com nota e motivo. Seu único trabalho é dizer sim ou não.

RELATÓRIO DE COMPATIBILIDADE · GERADO POR VAGA, POR PESSOA

Por que essa nota

Para quem tem conta, este bloco explica a nota em português — escrito sobre o seu histórico, não um texto genérico:

O raciocínio da nota é gerado para cada currículo depois do cadastro gratuito.

Aderência técnicapeso 0.45
Senioridadepeso 0.25
Localização e modelo de trabalhopeso 0.2
Setor e contextopeso 0.1

A seu favor

O que do seu histórico pesa a favor aqui.

O que falta

O que a vaga pede e seu currículo ainda não mostra.

Liberar meu relatório grátis

1 minuto: você envia o currículo, nós escrevemos o resto.

Ninguém caça sozinho. Esta vaga foi encontrada por outra pessoa e entrou no acervo de todo mundo. A caça continua enquanto você lê isto — e a sua parte do acervo (75.386 vagas, comparadas com o seu currículo) só passa a existir quando você entra.

O que você decide sobre cada vaga

Cada vaga vira um caso com histórico: candidatei, entrevista, proposta. Estes botões são os reais — só falta a conta.

Descrição da vaga

SOC Analyst II (L2)

Position Overview

In partnership with AgileBlue, Shield Consulting is seeking a SOC Analyst II (L2) to investigate medium- and high-complexity security incidents within a 24x7 SOC operation. This position is ideal for security operations professionals looking to deepen their investigative capabilities by performing analyses that go beyond traditional operational playbooks.

The professional will be responsible for conducting detailed investigations using raw logs, security telemetry, and advanced queries to identify malicious behavior, validate attack hypotheses, and support containment and incident response actions. The role requires technical autonomy, strong analytical skills, and independent decision-making in investigative scenarios.

The analyst will work alongside L1 analysts, taking ownership of escalated cases and supporting the technical growth of the operation. They will also collaborate with senior analysts, security engineers, and support teams to strengthen Shield Consulting clients' environments and continuously improve managed security services.

About Shield Consulting

Shield Consulting is a global boutique consulting firm with operations in Brazil and Portugal, helping organizations strengthen their security and improve governance with greater confidence at every stage of their journey.

About AgileBlue

AgileBlue is an AI-driven Security Operations (SecOps) platform specializing in automated cyber threat detection, investigation, and response across cloud, endpoint, and network environments.

Responsibilities

Security Monitoring and Operations (80%)

  • Handle cases and incidents that exceed the operational scope of L1 analysts
  • Conduct medium- and high-complexity investigations in enterprise environments
  • Build incident timelines using raw logs and multiple telemetry sources
  • Perform security event analysis without relying exclusively on operational playbooks
  • Use playbooks as operational references while maintaining investigative autonomy
  • Investigate suspicious activities by formulating attacker behavior hypotheses based on TTPs and validating them through available telemetry
  • Create and execute security queries using KQL, EQL, or equivalent languages to deepen investigations
  • Analyze endpoint, network, identity, and cloud logs to identify anomalous behavior
  • Execute threat containment and mitigation actions when necessary
  • Identify the root cause of security incidents and events
  • Document analyses, evidence, and timelines in ticketing and incident management platforms
  • Communicate investigation findings to clients through established communication channels
  • Participate in operational handoffs between shifts and teams
  • Perform threat hunting activities previously defined by senior analysts

Technical Support and Development (20%)

  • Support L1 analysts during investigations and operational escalations
  • Identify false-positive trends, operational gaps, and improvement opportunities
  • Contribute to the evolution of SOC playbooks, detection rules, and internal processes
  • Document relevant findings and support continuous improvement initiatives
  • Participate in technical training and ongoing professional development
  • Collaborate with senior analysts, security engineers, and support teams
  • Stay current on threats, vulnerabilities, TTPs, and security best practices

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Networking, Information Technology, or a related field
  • 2–4+ years of experience in SOC operations, security operations, Blue Team activities, or incident response
  • Proven experience investigating incidents using raw logs and multiple telemetry sources
  • Practical knowledge of KQL, EQL, or equivalent security investigation languages
  • Familiarity with the MITRE ATT&CK framework and attacker TTPs
  • Knowledge of endpoint, network, identity, and cloud log analysis
  • Experience with SIEM, EDR, and security monitoring tools
  • Ability to identify anomalous patterns and conduct investigations independently
  • Strong analytical and decision-making skills under pressure
  • Collaborative mindset and commitment to continuous learning
  • Strong verbal and written communication skills in Portuguese and English
  • Technical English proficiency for reading, investigating, and interpreting technical documentation

Additional Information

Employment Type: Full-time

Work Model: Hybrid/Remote

Compensation and Benefits

The position has an approved budget, and the final offer will be aligned according to the candidate’s experience, seniority, and compensation expectations.

Show more Show less
Vale a pena me candidatar? Ver minha nota

Leu tudo e ficou na dúvida? É exatamente isso que a nota resolve.

Por que criar conta agora

Leva 1 minuto

Envie o currículo e pronto. Sem formulário longo, sem questionário, sem teste.

Grátis de verdade

Sem cartão, sem período de teste que expira. Seu currículo só gera as suas notas.

Já tem vaga esperando

75.386 vagas encontradas nos últimos 30 dias — a sua nota nesta e em todas as outras sai assim que o currículo chega.

Criar conta grátis