5 дней назад
SIEM Content Development Specialist (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SIEM Content Development Specialist (Cybersecurity): Developing and optimizing SIEM detection content for a telecom Cyber Security Operations Center with an accent on threat detection, security event analysis, and telecom-specific telemetry. Focus on designing detection logic, integrating content into CI/CD workflows, and improving cloud-native security operations across SIEM, EDR, and network technologies.
Location: Lisbon, Portugal; hybrid work with 8–10 in-office days per month
Company
is a global telecommunications company providing connectivity and technology services to millions of customers.
What you will do
- Design, develop, tune, test, release, document, and retire SIEM detection content and rules.
- Modernize detection capabilities through next-generation SIEM technologies and cloud-native security tools.
- Translate threat intelligence, data sources, customer requirements, and use cases into actionable detection logic and response workflows.
- Integrate security content deployment into DevOps, SecOps, CI/CD, and automation workflows using version control.
- Support security event analysis, threat response, blue-team activities, residual risk assessments, and post-incident reviews.
- Measure deployed content effectiveness and prepare cybersecurity reports and advisories for stakeholders.
Requirements
- Bachelor’s or master’s degree in a related field and at least 3 years of relevant experience.
- 2–5 years of SIEM content development experience and at least 2 years of SOC analyst experience at Level 2 or above.
- Hands-on experience with SIEM, EDR, IDS/IPS, firewalls, proxies, web application firewalls, and antivirus technologies.
- Deep knowledge of telecom equipment, network architecture, and protocols including SS7, Diameter, GTP-C, TCP/IP, CIDR, and subnetting.
- Experience with Windows and Linux, cloud platforms, IoT security, Windows Security Event Logs, Syslog, MITRE, cyber kill chain, and APT strategies.
- Fluent English is required. Experience with CI/CD, Git, regular expressions, Kusto or SQL, scripting, and modern SIEM platforms is required or strongly relevant.
Culture & Benefits
- Flexible hybrid work model managed by team leaders.
- Mobile phone, communication plan, data card, and discounts on products and services.
- Well-being programs including nutrition and psychological consultations, webinars, workshops, and service discounts.
- Access to Communities of Practice and a customizable digital learning platform.
- Local and international internal mobility opportunities across departments and roles.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Damia
9 дней назад
Principal Cloud Security Engineer
10 дней назад
AI Security Engineer
52 320 - 70 787€
5 дней назад
Infrastructure Security Engineer
Jaya Talent
11 дней назад
Solution Engineer (Cybersecurity)
11 дней назад
Senior Enterprise Security Engineer (Cybersecurity)
160 000 - 200 000$
9 дней назад