Security Engineer - Incident Response
São Paulo, SP, Brazil
Posted on Sep 26, 2026
About this role
- Build our security nervous system. Own and improve the SIEM, telemetry pipelines, enrichment and correlation across CloudWalk.
- Create detections that matter. Turn attacker behavior, real incidents and Red Team findings into useful signals instead of alert spam.
- Respond when things get weird. Investigate incidents from first signal to containment, recovery and lessons learned.
- Hunt before alerts fire. Search proactively for suspicious behavior and visibility gaps.
- Automate aggressively. Build tools and workflows for triage, enrichment, evidence collection and containment.
- Work with attackers. The friendly kind. Partner closely with Offensive Security to turn attack paths into detections and controls.
- Use AI as leverage. Build agents and automations for investigation, log analysis, alert enrichment and response.
What You Need To Succeed
- Hands-on Experience in a Security Operations Center (SOC), Cyber Threat Intelligence, Incident Response, Security Engineering, or dedicated Insider Threat role.
- Investigative & Analytical Mindset: You know how to differentiate between a malicious data exfiltration event and an engineer who just doesn't understand the company's cloud storage policy.
- Technical Chops: Deep, practical experience querying raw logs, writing detection rules, and understanding the data pipeline behind them — you don't just read dashboards, you go to the source.
- Stack Familiarity (or ability to ramp fast): Google Workspace (Admin SDK, Reports API), Chronicle / Google SecOps (UDM Search, YARA-L), Wiz, SentinelOne (Deep Visibility), Jumpcloud, Tailscale, GCP Audit Logs and IAM. DLP/UEBA tools (e.g., Microsoft Purview, Proofpoint, Forcepoint, Varonis, Exabeam) and SIEM platforms (e.g., Splunk, Sentinel, CrowdStrike LogScale).
- Scripting Skills: Proficiency in TypeScript (Python/bash a plus). You write tools and services others can rely on, not just one-off scripts.
- Discretion & Ethics: Unwavering integrity and the ability to handle highly sensitive, confidential personnel investigations with strict adherence to privacy laws and company guidelines.
- Communication: The ability to translate complex technical forensic findings into clear, non-technical summaries for People and Legal teams.
Nice to Have
- Experience with insider threat detection, User and Entity Behavior Analytics, or building insider risk workflows.
- Familiarity with fintech / payment industry security (PCI DSS, card data, Pix, acquiring flows).
- Experience with LLM-powered security agents or AI-driven detection / triage automation.
- Kubernetes / Istio service mesh context.
The Future We See
At CloudWalk, we envision a future where AI empowers every field to reach new heights:
- People teams leveraging AI to transform talent acquisition and employee development.
- Marketing professionals creating data-driven, AI-powered campaign strategies.
- Customer Success teams enhancing client experiences with intelligent solutions.
- Risk analysts combining human expertise with AI to navigate complexities.
- Designers collaborating with AI to push creative boundaries.
Join us at CloudWalk, where we're not just engineering solutions; we're building a smarter, AI-driven future for payments—together.