Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Cooperativa Central Ailos

Information Security Analyst III – Security Operations, WAF, AppSec

Cooperativa Central Ailos

. Administer, configure, monitor, and enhance Web Application Firewall (WAF) and application and API protection solutions .

Posted 10/3/2026full-timeRemote • BrazilMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in administering and enhancing Web Application Firewall (WAF) and application protection solutions, with a strong focus on policy management, incident response, and security monitoring. Proficient in analyzing security events and collaborating with cross-functional teams to improve security posture and mitigate risks.

Highest-signal resume keywords
WAF AdministrationPolicy ManagementIncident ResponseOWASP Top 10 KnowledgeLog Analysis

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Web Application Firewall (WAF)API Protection SolutionsPolicy TuningEvent AnalysisVulnerability RemediationAutomation ScriptingTechnical Incident InvestigationSecurity MonitoringConfiguration ManagementDigital Certificate Management
Soft Skills
CollaborationMentoringTechnical Documentation
Tools & Technologies
HSMEDRSIEMIPS/IDSCloud EnvironmentsLoad BalancersCDNsReverse ProxiesNetwork SegmentationDevelopment Pipelines
Certifications & Qualifications
Offensive Security CertificationDefensive Security CertificationCloud Security Certification
Industry Keywords
Information Security OperationsDDoS ProtectionAPI SecurityVulnerability ManagementSecurity Audits

Tech Stack

Tools & technologies
CloudDNS

About the role

Key responsibilities & impact
  • Administer, configure, monitor, and enhance Web Application Firewall (WAF) and application and API protection solutions
  • Create, fine-tune, and maintain policies, rules, signatures, exception lists, and protection profiles
  • Conduct tuning and reduce false positives, tracking impacts with business, product, and development teams
  • Analyze Layer 7 events and blocks, identifying attacks, vulnerability exploitation, API abuse, scraping, and bots
  • Support controls against L7 DDoS, OWASP Top 10 threats, credential stuffing, enumeration, and feature abuse
  • Participate in onboarding applications, domains, and APIs onto protection solutions
  • Track effectiveness, coverage, blocking volume, and policy maturity metrics
  • Participate in digital certificate management, including mTLS, TLS, eCPF, and eCNPJ
  • Support the administration, monitoring, and maintenance of HSMs, including cryptographic key lifecycle management and integrations
  • Maintain, administer, and optimize security tools in the environment
  • Support security monitoring, triage, investigation, and incident response
  • Contribute to detection engineering, use cases, rules, and visibility improvements
  • Support hardening, attack surface reduction, vulnerability remediation, and configuration strengthening
  • Participate in technical incident analysis, root-cause analysis, containment, eradication, lessons learned, and war rooms
  • Collaborate with Infrastructure, Networks, Cloud, Architecture, AppSec, DevSecOps, CSIRT, and vendors
  • Prepare and maintain technical documentation, procedures, runbooks, and configuration standards
  • Support audits, regulatory requests, and evidence curation
  • Serve as a technical reference for junior and mid-level analysts through mentoring and technical reviews
  • Support solution assessments, proof-of-concept initiatives, and evolution roadmaps
  • Contribute to continuous improvement, routine automation, and delivery standardization

Requirements

What you’ll need
  • Proven experience in information security operations within mid-sized or large corporate environments
  • Hands-on experience administering WAF and application and API protection solutions, including configuration, tuning, policy management, and event analysis
  • Knowledge of the OWASP Top 10 and OWASP API Security
  • Knowledge of web application attack techniques and corresponding mitigation controls
  • Knowledge of HTTP/HTTPS, TLS, DNS, reverse proxies, load balancers, CDNs, and service publishing architectures
  • Familiarity with firewalls, IPS/IDS, EDR, SIEM, vulnerability management, and network segmentation
  • Understanding of cloud environments, containers, microservices, APIs, and integration with development pipelines
  • Ability to analyze logs, correlate events, and conduct technical incident investigations
  • Automation and scripting skills to support operational routines are desirable
  • Industry certifications in offensive or defensive security, cloud, or the application protection solutions in use are desirable

Benefits

Comp & perks
  • Medical Insurance
  • Dental Insurance
  • Renascer Program
  • Special Events and Milestones
  • Education Investment Program
  • Profit-Sharing Plan
  • Individual Development Plan
  • Private Pension Plan
  • Life Insurance
  • Tempo Juntos Program
  • Meal and/or Food Allowance
  • Transportation Allowance
  • Childcare/Nanny Assistance