Security Engineer - Incident Response

CloudWalk
CloudWalk

São Paulo, SP, Brazil

Posted on Sep 26, 2026

About this role

  • Build our security nervous system. Own and improve the SIEM, telemetry pipelines, enrichment and correlation across CloudWalk.
  • Create detections that matter. Turn attacker behavior, real incidents and Red Team findings into useful signals instead of alert spam.
  • Respond when things get weird. Investigate incidents from first signal to containment, recovery and lessons learned.
  • Hunt before alerts fire. Search proactively for suspicious behavior and visibility gaps.
  • Automate aggressively. Build tools and workflows for triage, enrichment, evidence collection and containment.
  • Work with attackers. The friendly kind. Partner closely with Offensive Security to turn attack paths into detections and controls.
  • Use AI as leverage. Build agents and automations for investigation, log analysis, alert enrichment and response.

What You Need To Succeed

  • Hands-on Experience in a Security Operations Center (SOC), Cyber Threat Intelligence, Incident Response, Security Engineering, or dedicated Insider Threat role.
  • Investigative & Analytical Mindset: You know how to differentiate between a malicious data exfiltration event and an engineer who just doesn't understand the company's cloud storage policy.
  • Technical Chops: Deep, practical experience querying raw logs, writing detection rules, and understanding the data pipeline behind them — you don't just read dashboards, you go to the source.
  • Stack Familiarity (or ability to ramp fast): Google Workspace (Admin SDK, Reports API), Chronicle / Google SecOps (UDM Search, YARA-L), Wiz, SentinelOne (Deep Visibility), Jumpcloud, Tailscale, GCP Audit Logs and IAM. DLP/UEBA tools (e.g., Microsoft Purview, Proofpoint, Forcepoint, Varonis, Exabeam) and SIEM platforms (e.g., Splunk, Sentinel, CrowdStrike LogScale).
  • Scripting Skills: Proficiency in TypeScript (Python/bash a plus). You write tools and services others can rely on, not just one-off scripts.
  • Discretion & Ethics: Unwavering integrity and the ability to handle highly sensitive, confidential personnel investigations with strict adherence to privacy laws and company guidelines.
  • Communication: The ability to translate complex technical forensic findings into clear, non-technical summaries for People and Legal teams.

Nice to Have

  • Experience with insider threat detection, User and Entity Behavior Analytics, or building insider risk workflows.
  • Familiarity with fintech / payment industry security (PCI DSS, card data, Pix, acquiring flows).
  • Experience with LLM-powered security agents or AI-driven detection / triage automation.
  • Kubernetes / Istio service mesh context.

The Future We See

At CloudWalk, we envision a future where AI empowers every field to reach new heights:

  • People teams leveraging AI to transform talent acquisition and employee development.
  • Marketing professionals creating data-driven, AI-powered campaign strategies.
  • Customer Success teams enhancing client experiences with intelligent solutions.
  • Risk analysts combining human expertise with AI to navigate complexities.
  • Designers collaborating with AI to push creative boundaries.

Join us at CloudWalk, where we're not just engineering solutions; we're building a smarter, AI-driven future for payments—together.