Senior SOC Analyst – Cloud Security & Threat Detection

ITDS Portugal · Remoto

AtivaTempo inteiroRemotoInformática
Salário
Não informado
Tipo de contrato
Tempo inteiro
Regime remoto
Remoto
Publicado
há 6 dias
Qualidade da vaga
80/100 — Boa oportunidade

Sobre a função

Unleash your potential to combat cyber threats and shape the future of cloud security with innovative threat detection and incident response strategies.

Location & Work Model
Portugal —100% Full Remote

As a SOC Analyst (Tier 1/2), you will be working for our client, a leading organisation protecting digital assets across multi-cloud environments. You will be both the first line of defence and the technical investigator behind it — owning real-time monitoring, triage, validation, and incident response across an advanced enterprise security stack.

Your main responsibilities:
  • Continuously monitor security alerts across the digital footprint using a SIEM (e.g. Elastic SIEM), network detection (e.g. Darktrace), and EDR/XDR (e.g. CrowdStrike Falcon), and perform initial validation to separate genuine anomalies from false positives (Tier 1).
  • Investigate verified alerts in depth — correlate endpoint, cloud, and network telemetry to reconstruct attack timelines and assess threat impact (Tier 2).
  • Monitor, audit, and analyse anomalies across cloud workloads using native security tooling in AWS, Azure, or GCP.
  • Contribute to detection use-case development and help build and refine security automation workflows (e.g. Cortex XSOAR).
  • Execute containment actions following documented playbooks — isolate compromised hosts, deploy network blocks, or revoke compromised cloud credentials.
  • Document findings, log artifacts, and containment actions precisely in the ticketing system, and escalate high-severity or systemic incidents to Tier 3 and the Incident Response lead.
You're ideal for this role if you have: 
  • Experience in a SOC, security monitoring, or incident response role — roughly 1+ year for a Tier 1 focus, 3+ years for a Tier 2 focus.
  • Hands-on experience with a SIEM platform (Elastic SIEM, Splunk, Microsoft Sentinel, IBM QRadar, or similar).
  • Experience with EDR/XDR tooling (CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Cortex XDR, or similar).
  • Familiarity with network detection and response tools (Darktrace, Vectra, ExtraHop, or similar).
  • Working knowledge of at least one major cloud platform (AWS, Azure, or GCP) and its native security, logging, and monitoring services.
  • A solid grasp of TCP/IP, common attack techniques, and the MITRE ATT&CK framework.
  • Strong written communication for clear, precise incident documentation.
  • Willingness to work in a 24/7 rotating shift environment.
It is a strong plus if you have:
  • Experience with SOAR platforms and security automation (Cortex XSOAR, Splunk SOAR, Tines, or similar).
  • Scripting for automation (Python, PowerShell, or Bash).
  • Relevant certifications (CompTIA Security+ or CySA+, GIAC GCIH/GCIA, cloud security, or vendor certifications such as CrowdStrike or Elastic).
  • Experience in financial services or another regulated environment.
Language Required for the role:
  • Fluent English.
Eligibility for the role:
  • Only candidates with an existing legal right to work in Portugal will be considered.


https://itdsportugal.com/en/it-jobs/10116/?utm_source=itjobs

Para se candidatar a este anúncio, visite o anúncio original no ITJobs.

Senior SOC Analyst – Cloud Security & Threat Detection — ITDS Portugal — empregoemportugal.pt