10 дней назад
Senior SOC Analyst (Cloud Security & Threat Detection)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior SOC Analyst (Cloud Security & Threat Detection) (SIEM/EDR/Cloud): Monitoring, investigating, and containing cyber threats across multi-cloud environments with an accent on real-time alert triage, incident analysis, and automated detection. Focus on reconstructing attack timelines, analyzing AWS, Azure, or GCP workloads, executing containment actions, and escalating high-severity incidents.
Location: Portugal — Remote, full-time, 5 days a week. Candidates must have an existing legal right to work in Portugal or the European Union.
Company
is hiring for a client that safeguards digital assets across multi-cloud environments.
What you will do
- Conduct real-time security monitoring and alert triage across multi-cloud environments using SIEM and EDR tools.
- Investigate verified alerts, identify root causes, reconstruct attack timelines, and assess threat impact.
- Monitor cloud workloads and analyze anomalies using native AWS, Azure, or GCP security services.
- Develop automated detection use cases and contribute to security automation workflows.
- Execute containment actions, including host isolation, blocking, and cloud credential revocation, according to documented procedures.
- Document incidents and escalate high-severity or systemic issues to Tier 3 engineering and incident response teams.
Requirements
- At least 6 years of experience in SOC, security monitoring, or incident response.
- Hands-on experience with SIEM platforms such as Elastic SIEM, Splunk, or Microsoft Sentinel.
- Strong knowledge of EDR/XDR tools, including CrowdStrike Falcon or equivalent platforms.
- Working knowledge of AWS, Azure, or GCP and its native security services.
- Solid understanding of TCP/IP, attack techniques, and the MITRE ATT&CK framework.
- Fluent English and willingness to work in a 24/7 rotating shift environment; existing legal work authorization in Portugal or the EU required.
Nice to have
- Experience with Cortex XSOAR or Splunk SOAR.
- Scripting skills in Python, PowerShell, or Bash.
- Relevant security or vendor certifications.
- Experience in regulated environments such as financial services.
Culture & Benefits
- Remote work from Portugal on a full-time schedule.
- Work on cloud security and threat detection in a dynamic security environment.
- Exposure to multi-cloud infrastructure and advanced security tooling.
- Opportunities for impactful work and career growth within an innovative security team.
Hiring process
- Submit a CV, preferably in English.
- Include a statement confirming consent to the processing and storage of personal data.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
14 дней назад
Senior Security Engineer (CSIRT)
13 дней назад
Security Incident Response Analyst (Cloud Security)
14 дней назад
Cyber Defense Analyst (AI)
11 дней назад
Senior DevSecOps Engineer (Infrastructure & Cloud Security)
12 дней назад
Staff CSIRT Analyst (Cybersecurity)
200 000 - 210 000$
10 дней назад
Security Operations Analyst (Cybersecurity)
110 000 - 140 000AUD