Describe your role

Job Opportunities for You

Back to All Offers

How to use the job offers’ basket?

Checkout

Senior SOC Analyst – Cloud Security & Threat Detection

Portugal
Remote

5 250 - 7 350

EUR

(B2B)

or platforms to report for placement. This job order requires no additional technologies tools
English
Senior
Banking
SOC Analyst

Unleash your potential to combat cyber threats and shape the future of cloud security with innovative threat detection and incident response strategies.

Location & Work Model
Portugal —100% Full Remote

As a SOC Analyst (Tier 1/2), you will be working for our client, a leading organisation protecting digital assets across multi-cloud environments. You will be both the first line of defence and the technical investigator behind it — owning real-time monitoring, triage, validation, and incident response across an advanced enterprise security stack.

Your main responsibilities:
  • Continuously monitor security alerts across the digital footprint using a SIEM (e.g. Elastic SIEM), network detection (e.g. Darktrace), and EDR/XDR (e.g. CrowdStrike Falcon), and perform initial validation to separate genuine anomalies from false positives (Tier 1).
  • Investigate verified alerts in depth — correlate endpoint, cloud, and network telemetry to reconstruct attack timelines and assess threat impact (Tier 2).
  • Monitor, audit, and analyse anomalies across cloud workloads using native security tooling in AWS, Azure, or GCP.
  • Contribute to detection use-case development and help build and refine security automation workflows (e.g. Cortex XSOAR).
  • Execute containment actions following documented playbooks — isolate compromised hosts, deploy network blocks, or revoke compromised cloud credentials.
  • Document findings, log artifacts, and containment actions precisely in the ticketing system, and escalate high-severity or systemic incidents to Tier 3 and the Incident Response lead.
You're ideal for this role if you have: 
  • Experience in a SOC, security monitoring, or incident response role — roughly 1+ year for a Tier 1 focus, 3+ years for a Tier 2 focus.
  • Hands-on experience with a SIEM platform (Elastic SIEM, Splunk, Microsoft Sentinel, IBM QRadar, or similar).
  • Experience with EDR/XDR tooling (CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Cortex XDR, or similar).
  • Familiarity with network detection and response tools (Darktrace, Vectra, ExtraHop, or similar).
  • Working knowledge of at least one major cloud platform (AWS, Azure, or GCP) and its native security, logging, and monitoring services.
  • A solid grasp of TCP/IP, common attack techniques, and the MITRE ATT&CK framework.
  • Strong written communication for clear, precise incident documentation.
  • Willingness to work in a 24/7 rotating shift environment.
It is a strong plus if you have:
  • Experience with SOAR platforms and security automation (Cortex XSOAR, Splunk SOAR, Tines, or similar).
  • Scripting for automation (Python, PowerShell, or Bash).
  • Relevant certifications (CompTIA Security+ or CySA+, GIAC GCIH/GCIA, cloud security, or vendor certifications such as CrowdStrike or Elastic).
  • Experience in financial services or another regulated environment.
Language Required for the role:
  • Fluent English.
Eligibility for the role:
  • Only candidates with an existing legal right to work in Portugal will be considered.

Internal number #10116

Benefits

ITDS Clubs

Access to medical insurance

Meal Card

Access to Pluralsight & Udemy

Integrational Events

Your criteria

Want to be notified about new job openings
that match your preferences?

By providing e-mail address and clicking „Notify Me” you agree that ITDS will send e-mail notification that match criteria you have provided.