TL;DR
SOC Detection Lead Expert (Cybersecurity): Leading the design and operation of security detection systems with an accent on offensive security techniques and blue team operations. Focus on developing custom tooling, optimizing C2 frameworks, and enhancing threat detection capabilities against sophisticated attack methodologies.
Location: Hybrid, Lisbon, Portugal
Company
hirify.global is a specialized IT consulting partner with 18 years of experience, focused on agile, people-centered approaches and challenging projects.
What you will do
- Lead the Security Operations Center (SOC) detection strategy and implementation.
- Apply expertise in offensive security, including red teaming and pen testing methodologies.
- Design and operate Command & Control (C2) frameworks with strong OPSEC.
- Develop custom scripts and tooling using Python, PowerShell, C/C++.
- Enhance detection engineering capabilities based on MITRE ATT&CK.
- Troubleshoot and resolve complex cybersecurity issues.
Requirements
- 4+ years of experience in similar functions.
- 4+ years of expertise in Offensive Security (Red Teaming/Pen Testing).
- 2+ years of expertise in Detection Engineering or Blue Team Operations.
- Solid understanding of bypass concepts (payload obfuscation, in-memory execution, anti-analysis).
- Strong expertise in Active Directory exploitation and stealth lateral movement.
- Proficiency in industry-standard offensive security tooling and customization.
- Expertise in Sentineland Kusto Query Language (KQL).
- English: mandatory.
Culture & Benefits
- No-term full-time contract.
- Health Insurance and meal allowance (Coverflex).
- 22 days of paid vacation plus 4 extra days annually (Carnival, Christmas Eve, New Year's Eve, Birthday).
- Referral bonus, special discounts, and flex options.
- Annual training budget.
- Opportunity to join a great team-oriented culture in a dynamically growing international company.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →