Senior SOC Analyst – Cloud Security & Threat Detection
ITDS Portugal · Remoto
Salário
Não informado
Tipo de contrato
Tempo inteiro
Regime remoto
Remoto
Publicado
há 6 dias
Qualidade da vaga
80/100 — Boa oportunidade
Sobre a função
Unleash your potential to combat cyber threats and shape the future of cloud security with innovative threat detection and incident response strategies.
Location & Work Model
Portugal —100% Full Remote
Your main responsibilities:
- Continuously monitor security alerts across the digital footprint using a SIEM (e.g. Elastic SIEM), network detection (e.g. Darktrace), and EDR/XDR (e.g. CrowdStrike Falcon), and perform initial validation to separate genuine anomalies from false positives (Tier 1).
- Investigate verified alerts in depth — correlate endpoint, cloud, and network telemetry to reconstruct attack timelines and assess threat impact (Tier 2).
- Monitor, audit, and analyse anomalies across cloud workloads using native security tooling in AWS, Azure, or GCP.
- Contribute to detection use-case development and help build and refine security automation workflows (e.g. Cortex XSOAR).
- Execute containment actions following documented playbooks — isolate compromised hosts, deploy network blocks, or revoke compromised cloud credentials.
- Document findings, log artifacts, and containment actions precisely in the ticketing system, and escalate high-severity or systemic incidents to Tier 3 and the Incident Response lead.
- Experience in a SOC, security monitoring, or incident response role — roughly 1+ year for a Tier 1 focus, 3+ years for a Tier 2 focus.
- Hands-on experience with a SIEM platform (Elastic SIEM, Splunk, Microsoft Sentinel, IBM QRadar, or similar).
- Experience with EDR/XDR tooling (CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Cortex XDR, or similar).
- Familiarity with network detection and response tools (Darktrace, Vectra, ExtraHop, or similar).
- Working knowledge of at least one major cloud platform (AWS, Azure, or GCP) and its native security, logging, and monitoring services.
- A solid grasp of TCP/IP, common attack techniques, and the MITRE ATT&CK framework.
- Strong written communication for clear, precise incident documentation.
- Willingness to work in a 24/7 rotating shift environment.
- Experience with SOAR platforms and security automation (Cortex XSOAR, Splunk SOAR, Tines, or similar).
- Scripting for automation (Python, PowerShell, or Bash).
- Relevant certifications (CompTIA Security+ or CySA+, GIAC GCIH/GCIA, cloud security, or vendor certifications such as CrowdStrike or Elastic).
- Experience in financial services or another regulated environment.
- Fluent English.
- Only candidates with an existing legal right to work in Portugal will be considered.
https://itdsportugal.com/en/it-jobs/10116/?utm_source=itjobs
Para se candidatar a este anúncio, visite o anúncio original no ITJobs.