Chief Cyber Ops Analyst

EPAM Systems · Remoto, BR

We are seeking a **Chief Cyber Ops Analyst** who will strengthen detection, hunting, and incident response across cloud, identity, endpoint, email, and network signals. You will own the hardest investigations, mentor analysts, and turn operational insight into durable engineering improvements. **Responsibilities** * Own complex, multi\-signal investigations end\-to\-end from triage through root\-cause analysis and closure * Correlate activity across endpoint, identity, network, cloud, and email telemetry to determine scope and impact * Make judgment calls on benign versus malicious activity and defend conclusions with evidence * Perform threat hunts based on threat intelligence and TTPs and map techniques to your environment * Write and refine advanced queries to hunt, pivot, and correlate events across data sources * Build and maintain automation using scripts and integrations to enrich and correlate investigations * Coordinate incident response actions for significant incidents and communicate status to stakeholders * Balance business impact versus risk in containment decisions and escalate cross\-team incidents appropriately * Partner with detection engineering to translate investigation insights into higher\-fidelity detections * Author and tune detection content and measure detection effectiveness over time * Develop reusable analytical patterns and automation such as SOAR playbooks * Mentor analysts and codify knowledge into runbooks and hunt guides * Use approved AI tools to accelerate investigations, hunts, and reporting with disciplined verification **Requirements** * 7\+ years security operations experience owning complex, high\-severity investigations * Proven leadership skills mentoring mid\-level and junior analysts and driving best practices * Strong incident response experience coordinating containment and eradication across teams * Advanced SIEM and EDR expertise using Microsoft Sentinel, Splunk, Elastic Security, Defender for Endpoint, CrowdStrike Falcon, or SentinelOne * Deep query language skills with KQL, SQL, Elastic ES\|QL/Lucene/EQL, or equivalent * Strong scripting skills in Python or PowerShell for automation and API integrations * Solid cloud security fundamentals across Amazon Web Services, Microsoft Azure, and Google Cloud Platform * Strong threat hunting skills using threat intelligence and MITRE ATT\&CK mapping * Strong analytical skills to make evidence\-based decisions under ambiguity * Upper\-Intermediate English proficiency (B2\) * B.S./M.S. degree in Computer Science, Cyber Security, or equivalent experience **Nice to have** * CrowdStrike Falcon Platform * Security Orchestration and Automated Response * Splunk * Digital forensics * Wireshark **We offer** * International projects with top brands * Work with global teams of highly skilled, diverse peers * Healthcare benefits * Employee financial programs * Paid time off and sick leave * Upskilling, reskilling and certification courses * Unlimited access to the LinkedIn Learning library and 22,000\+ courses * Global career opportunities * Volunteer and community involvement opportunities * EPAM Employee Groups * Award\-winning culture recognized by Glassdoor, Newsweek and LinkedIn *EPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.*