Назад
Company hidden
5 дней назад

SIEM Content Development Specialist (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
c1
Страна
Portugal
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
SIEM Content Development Specialist (Cybersecurity): Developing and optimizing SIEM detection content for a telecom Cyber Security Operations Center with an accent on threat detection, security event analysis, and telecom-specific telemetry. Focus on designing detection logic, integrating content into CI/CD workflows, and improving cloud-native security operations across SIEM, EDR, and network technologies.

Location: Lisbon, Portugal; hybrid work with 8–10 in-office days per month

Company

hirify.global is a global telecommunications company providing connectivity and technology services to millions of customers.

What you will do

  • Design, develop, tune, test, release, document, and retire SIEM detection content and rules.
  • Modernize detection capabilities through next-generation SIEM technologies and cloud-native security tools.
  • Translate threat intelligence, data sources, customer requirements, and use cases into actionable detection logic and response workflows.
  • Integrate security content deployment into DevOps, SecOps, CI/CD, and automation workflows using version control.
  • Support security event analysis, threat response, blue-team activities, residual risk assessments, and post-incident reviews.
  • Measure deployed content effectiveness and prepare cybersecurity reports and advisories for stakeholders.

Requirements

  • Bachelor’s or master’s degree in a related field and at least 3 years of relevant experience.
  • 2–5 years of SIEM content development experience and at least 2 years of SOC analyst experience at Level 2 or above.
  • Hands-on experience with SIEM, EDR, IDS/IPS, firewalls, proxies, web application firewalls, and antivirus technologies.
  • Deep knowledge of telecom equipment, network architecture, and protocols including SS7, Diameter, GTP-C, TCP/IP, CIDR, and subnetting.
  • Experience with Windows and Linux, cloud platforms, IoT security, Windows Security Event Logs, Syslog, MITRE, cyber kill chain, and APT strategies.
  • Fluent English is required. Experience with CI/CD, Git, regular expressions, Kusto or SQL, scripting, and modern SIEM platforms is required or strongly relevant.

Culture & Benefits

  • Flexible hybrid work model managed by team leaders.
  • Mobile phone, communication plan, data card, and discounts on hirify.global products and services.
  • Well-being programs including nutrition and psychological consultations, webinars, workshops, and service discounts.
  • Access to Communities of Practice and a customizable digital learning platform.
  • Local and international internal mobility opportunities across departments and roles.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →