Senior SOC Analyst – Cloud Security & Threat Detection
Unleash your potential to combat cyber threats and shape the future of cloud security with innovative threat detection and incident response strategies.
Location & Work Model
Portugal — Remote (full-time, 5 days a week)
As a Senior SOC Analyst – Cloud Security & Threat Detection, you will be working for our client, a leading cybersecurity organization dedicated to safeguarding digital assets across multi-cloud environments. You will play a critical role in monitoring, investigating, and responding to emerging cyber threats, helping to protect sensitive data and infrastructure in a dynamic, fast-paced setting. This position offers opportunities for impactful work and career growth within an innovative security team.
Your main responsibilities:
- Conduct real-time security monitoring and triage across multi-cloud environments using advanced SIEM and EDR tools.
- Investigate and analyze verified alerts to identify root causes, reconstruct attack timelines, and assess threat impact.
- Monitor, audit, and analyze anomalies within cloud workloads utilizing native AWS, Azure, or GCP security tools.
- Develop and refine automated detection use cases and contribute to security automation workflows with Cortex XSOAR and cloud native platforms.
- Execute immediate containment actions such as isolating hosts, deploying blocks, or revoking cloud credentials, following documented SOPs.
- Document all technical findings, incident details, and containment measures meticulously within ticketing systems.
- Escalate high-severity or systemic incidents to Tier 3 engineering and incident response teams.
You’re ideal for this role if you have:
- At least 6 years of experience in SOC, security monitoring, or incident response.
- Hands-on experience with SIEM platforms (Elastic SIEM, Splunk, Microsoft Sentinel, or similar).
- Strong knowledge of EDR/XDR tools (CrowdStrike Falcon or equivalent).
- Familiarity with network detection and response platforms such as Darktrace.
- Working knowledge of one major cloud platform (AWS, Azure, or GCP) and its native security services.
- Solid understanding of TCP/IP, attack techniques, and the MITRE ATT&CK framework.
- Excellent written communication skills for incident documentation.
- Willingness to work in a 24/7 rotating shift environment.
It is a strong plus if you have: (optional)
- Experience with security automation platforms such as Cortex XSOAR or Splunk SOAR.
- Scripting skills (Python, PowerShell, Bash).
- Relevant certifications (e.g., CompTIA Security+, GIAC GCIH/GCIA, vendor certifications).
- Experience within regulated environments such as financial services.
Language Required for the role:
English — Fluent command required.
Eligibility to work in Europe:
Only candidates with an existing legal right to work in Portugal or the European Union will be considered for this role.
#MAKEYourCareerBETTER
Interested? Apply now and include your CV (preferably in English) along with a statement confirming your consent to the processing and storage of your personal data.
Internal number #10116
Benefits
ITDS Clubs
Access to medical insurance
Meal Card
Access to Pluralsight & Udemy
Integrational Events
Seus critérios