Назад
Company hidden
10 дней назад

Senior SOC Analyst (Cloud Security & Threat Detection)

Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Portugal/Europe
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior SOC Analyst (Cloud Security & Threat Detection) (SIEM/EDR/Cloud): Monitoring, investigating, and containing cyber threats across multi-cloud environments with an accent on real-time alert triage, incident analysis, and automated detection. Focus on reconstructing attack timelines, analyzing AWS, Azure, or GCP workloads, executing containment actions, and escalating high-severity incidents.

Location: Portugal — Remote, full-time, 5 days a week. Candidates must have an existing legal right to work in Portugal or the European Union.

Company

hirify.global is hiring for a client that safeguards digital assets across multi-cloud environments.

What you will do

  • Conduct real-time security monitoring and alert triage across multi-cloud environments using SIEM and EDR tools.
  • Investigate verified alerts, identify root causes, reconstruct attack timelines, and assess threat impact.
  • Monitor cloud workloads and analyze anomalies using native AWS, Azure, or GCP security services.
  • Develop automated detection use cases and contribute to security automation workflows.
  • Execute containment actions, including host isolation, blocking, and cloud credential revocation, according to documented procedures.
  • Document incidents and escalate high-severity or systemic issues to Tier 3 engineering and incident response teams.

Requirements

  • At least 6 years of experience in SOC, security monitoring, or incident response.
  • Hands-on experience with SIEM platforms such as Elastic SIEM, Splunk, or Microsoft Sentinel.
  • Strong knowledge of EDR/XDR tools, including CrowdStrike Falcon or equivalent platforms.
  • Working knowledge of AWS, Azure, or GCP and its native security services.
  • Solid understanding of TCP/IP, attack techniques, and the MITRE ATT&CK framework.
  • Fluent English and willingness to work in a 24/7 rotating shift environment; existing legal work authorization in Portugal or the EU required.

Nice to have

  • Experience with Cortex XSOAR or Splunk SOAR.
  • Scripting skills in Python, PowerShell, or Bash.
  • Relevant security or vendor certifications.
  • Experience in regulated environments such as financial services.

Culture & Benefits

  • Remote work from Portugal on a full-time schedule.
  • Work on cloud security and threat detection in a dynamic security environment.
  • Exposure to multi-cloud infrastructure and advanced security tooling.
  • Opportunities for impactful work and career growth within an innovative security team.

Hiring process

  • Submit a CV, preferably in English.
  • Include a statement confirming consent to the processing and storage of personal data.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →