# Cyber Security Specialist

> RecargaPay · Brazil (Remote) · — · Posted 2026-08-17

**Workplace:** remote

**Department:** Risks

## Description

Come Make an Impact on Millions of Brazilians! At RecargaPay, we're on a mission to deliver the best payment experience for Brazilian consumers and small businesses — by building a powerful digital ecosystem where the banked and unbanked connect, and where consumers and merchants have a one-stop shop for all their financial needs. We serve over 10 million users and process more than USD 4 billion annually. We've been profitable since 2022 and operate our own credit business. We are an AI-first, 100% remote team, scaling in the rapidly changing Brazilian financial market. Our goal? Deliver the best payment experience in Brazil for people and small businesses alike. We value autonomy, ownership, and a bias for action. We're looking for people who are curious, hands-on, and driven by impact — who want to solve real problems, work with strong teams, and rethink what's possible. If you're ready to do your best work, at scale, with purpose — this is your place.  
  
Position Overview  
RecargaPay is looking for a Cyber Security Specialist to be a hands-on technical practitioner within our CSIRT (Computer Security Incident Response Team). This person will own the detection, response, and containment of security incidents across our payments platform — executing the full incident lifecycle, building detection logic, and driving automation to shrink response time in a cloud-native, high-volume transactional environment.  
  
**Key Responsibilities**

-   Own the full incident response lifecycle end-to-end: detection, triage, containment, eradication, recovery, and post-mortem.
-   Develop and maintain playbooks, runbooks, and response procedures that keep response sharp and repeatable.
-   Build and maintain detection and response automations (SOAR) to orchestrate workflows across tools and reduce manual toil.
-   Operate and continuously tune the detection stack on Elastic (Elasticsearch/Kibana): queries, dashboards, alerts, and event correlation.
-   Maintain the Elastic infrastructure on Linux.
-   Manage endpoint detection and response via CrowdStrike (EDR), including proactive threat hunting and containment actions.
-   Investigate and respond to incidents in AWS (CloudTrail, GuardDuty, IAM, VPC, and related services).
-   Produce incident reports and MTTD/MTTR metrics that give leadership clear visibility into the security posture.
-   Collaborate with engineering, infrastructure, and compliance teams to remediate vulnerabilities and reduce the attack surface.

## Requirements

Technical Skills

-   Solid hands-on experience in security incident response in complex, high-volume environments.
-   Strong command of Elasticsearch/Elastic Stack for detection, threat hunting, and alert creation. Experience with AWS security — native security services and cloud log investigation.
-   Hands-on experience with CrowdStrike or an equivalent EDR. Workflow automation and orchestration using a SOAR or automation platform.
-   Strong Linux proficiency (administration and hardening). Knowledge of BTT (Boitatá), Apura's threat intelligence tool. Experience with mTLS certificate lifecycle management and AWS ACM (Certificate Manager).
-   Fluency with frameworks such as MITRE ATT&CK, NIST IR, and standard incident taxonomies.

Soft Skills

-   Technical depth: owns a complex domain (CSIRT tooling and detection engineering) and drives improvements without needing direction. Independent judgment under pressure: makes sound containment decisions in fast-moving incidents with incomplete information.
-   Cross-functional influence: translates security findings into clear, actionable guidance for engineering and infrastructure partners.
-   Documentation discipline: keeps playbooks, runbooks, and post-mortems current so the team can operate without heroics.
-   Continuous improvement mindset: proactively identifies detection gaps and proposes measurable improvements to MTTD/MTTR.

Nice to Have

-   Background in financial services, fintech, or other high-volume transactional environments.
-   Scripting (Python / Bash) for automation and tool integration.
-   Certifications such as GCIH, GCIA, GCFA, OSCP, or equivalent. Experience with compliance requirements (PCI-DSS, LGPD).

## Benefits

-   Competitive and market-aligned salary.
-   Remote work — wherever you are, you’re part of the team!
-   Home office allowance through a monthly deposit in the RecargaPay app.
-   Health and dental plans with no co-pay.
-   Life insurance.
-   Flexible meal allowance (via Flash).
-   TotalPass membership to take care of your health.  
    

### Diversity & Inclusion at RecargaPay

At RecargaPay, you’ll have the freedom to be who you are because we believe that diverse perspectives and experiences make us more creative and stronger. Here, everyone is welcome to express themselves authentically. We value the richness of each journey and the multiple ways of seeing the world, without distinctions of gender, race, sexual orientation, age, religion, or any other characteristic that makes us unique.

### About the Use of Your Data

By sharing your resume with us, you authorize the use of your data for analysis during the selection process and possibly for other opportunities within the RecargaPay group. You can request the update or deletion of your information at any time, in accordance with LGPD (General Data Protection Law).

## Apply

[Apply at RecargaPay](https://apply.workable.com/recargapay/j/FAC21D7C0B/apply)

---
Powered by [Workable](https://www.workable.com)
