Live opening · Posted 7 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Unleash your potential to combat cyber threats and shape the future of cloud security with innovative threat detection and incident response strategies.
Portugal —100% Full Remote (Need to be based in Portugal)
As a SOC Analyst (Tier 1/2), you will be working for our client, a leading organisation protecting digital assets across multi-cloud environments. You will be both the first line of defence and the technical investigator behind it — owning real-time monitoring, triage, validation, and incident response across an advanced enterprise security stack.
Your main responsibilities:
Continuously monitor security alerts across the digital footprint using a SIEM (e.g. Elastic SIEM), network detection (e.g. Darktrace), and EDR/XDR (e.g. CrowdStrike Falcon), and perform initial validation to separate genuine anomalies from false positives (Tier 1).
Investigate verified alerts in depth — correlate endpoint, cloud, and network telemetry to reconstruct attack timelines and assess threat impact (Tier 2).
Monitor, audit, and analyse anomalies across cloud workloads using native security tooling in AWS, Azure, or GCP.
Contribute to detection use-case development and help build and refine security automation workflows (e.g. Cortex XSOAR).
Execute containment actions following documented playbooks — isolate compromised hosts, deploy network blocks, or revoke compromised cloud credentials.
Document findings, log artifacts, and containment actions precisely in the ticketing system, and escalate high-severity or systemic incidents to Tier 3 and the Incident Response lead.
You're ideal for this role if you have:
Experience in a SOC, security monitoring, or incident response role — roughly 1+ year for a Tier 1 focus, 3+ years for a Tier 2 focus.
Hands-on experience with a SIEM platform (Elastic SIEM, Splunk, Microsoft Sentinel, IBM QRadar, or similar).
Experience with EDR/XDR tooling (CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Cortex XDR, or similar).
Familiarity with network detection and response tools (Darktrace, Vectra, ExtraHop, or similar).
Working knowledge of at least one major cloud platform (AWS, Azure, or GCP) and its native security, logging, and monitoring services.
A solid grasp of TCP/IP, common attack techniques, and the MITRE ATT&CK framework.
Strong written communication for clear, precise incident documentation.
Willingness to work in a 24/7 rotating shift environment.
It is a strong plus if you have:
Experience with SOAR platforms and security automation (Cortex XSOAR, Splunk SOAR, Tines, or similar).
Scripting for automation (Python, PowerShell, or Bash).
Relevant certifications (CompTIA Security+ or CySA+, GIAC GCIH/GCIA, cloud security, or vendor certifications such as CrowdStrike or Elastic).
Experience in financial services or another regulated environment.
Language Required for the role:
Fluent English.
Eligibility for the role:
Only candidates with an existing legal right to work in Portugal will be considered.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.