Blue Team Lead – Detection & Incident Response

Nearshore Portugal

Porto

On-site

EUR 70,000 - 100,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Nearshore Portugal seeks a Blue Team Lead to provide technical leadership in threat detection and incident response within an international cybersecurity team. You will help build and maintain detection and response capabilities, guide analysts, and drive security incidents through to resolution.

You will lead incident investigations, develop runbooks, and tune detection rules while collaborating with teams globally. Strong English and a calm, results‑oriented approach are essential.

Qualifications

  • At least 5 years of experience in incident detection and response.
  • Experience in DFIR with Velociraptor or KAPE.
  • Experience with Cortex and vulnerability management.
  • Strong incident management skills and a structured approach to investigations.
  • Ability to guide analysts, collaborate across teams, and make decisions under pressure.
  • Strong written and verbal communication skills.
  • Calm, rigorous, and results‑oriented approach.
  • Good command of English.

Responsibilities

  • Provide technical leadership and support analysts’ skills development.
  • Detect, investigate, and respond to security incidents across the organization.
  • Conduct digital forensic investigations and proactive threat hunting based on threat intelligence.
  • Develop and tune detection rules.
  • Create and maintain operational runbooks.
  • Perform root cause analysis and post-incident reviews.
  • Improve incident response plans and detection and response processes.
  • Evaluate security technologies to strengthen detection and response capabilities.
  • Validate and triage vulnerabilities, tracking remediation through to completion.
  • Participate in emergency response activities when required.
  • Provide regular reporting on security activities and findings.

Skills

Incident detection
Incident response
DFIR
Leadership
English
Team guidance

Tools

Velociraptor
KAPE
Cortex

Job description

Blue Team Lead – Detection & Incident Response

We are looking for a Blue Team Lead to join an international cybersecurity team and provide technical leadership in threat detection and incident response. You will help build and maintain detection and response capabilities, guide analysts, and drive security incidents through to resolution.

Requirements
  • At least 5 years of experience in incident detection and response.
  • Experience in Digital Forensics and Incident Response (DFIR), including tools such as Velociraptor or KAPE.
  • Experience with Cortex and vulnerability management.
  • Strong incident management skills and a structured approach to investigations.
  • Ability to guide analysts, collaborate across teams, and make decisions under pressure.
  • Strong written and verbal communication skills.
  • A calm, rigorous, and results-oriented approach.
  • Good command of English.
Responsibilities
  • Provide technical leadership and support analysts’ skills development.
  • Detect, investigate, and respond to security incidents across the organization.
  • Conduct digital forensic investigations and proactive threat hunting based on threat intelligence.
  • Develop and tune detection rules.
  • Create and maintain operational runbooks.
  • Perform root cause analysis and post-incident reviews.
  • Improve incident response plans and detection and response processes.
  • Evaluate security technologies to strengthen detection and response capabilities.
  • Validate and triage vulnerabilities, tracking remediation through to completion.
  • Participate in emergency response activities when required.
  • Provide regular reporting on security activities and findings.
Nice to have
  • The job description does not specify additional preferred qualifications.
Working conditions
  • International environment with English as the working language.
  • Close collaboration with the cybersecurity team, reporting to the CISO.
  • Opportunity to shape detection and response capabilities across a global organization.
  • Participation in emergency response activities when required.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Blue Team Lead: Threat Detection & Incident Response
Blue Team Lead: Threat Detection & Incident Response

Nearshore Portugal • Porto

On-site
EUR 70,000 - 100,000
Blue Team Leader
Blue Team Leader

Hiscox • Lisboa

On-site
EUR 60,000 - 80,000
Red Team Consultant
Red Team Consultant

Inetum • Portugal

On-site
EUR 50,000 - 70,000
Detection Engineer
Detection Engineer

Boston Consulting Group (BCG) • Lisboa

On-site
EUR 65,000 - 90,000
Senior Cyber Defense Lead – SIEM & IR
Senior Cyber Defense Lead – SIEM & IR

Hiscox • Lisboa

On-site
EUR 60,000 - 80,000
Detection Engineering Manager
Detection Engineering Manager

Boston Consulting Group (BCG) • Lisboa

On-site
EUR 65,000 - 95,000
Banking Sector | Cyber Security Analyst
Banking Sector | Cyber Security Analyst

Devoteam • Lisboa

On-site
EUR 45,000 - 65,000
Devoteam Cyber Trust | SOC Analyst | FinTech Sector
Devoteam Cyber Trust | SOC Analyst | FinTech Sector

Devoteam | Cyber Trust • Porto

On-site
EUR 35,000 - 48,000
Devoteam Cyber Trust | SOC Analyst | Financial Sector
Devoteam Cyber Trust | SOC Analyst | Financial Sector

Devoteam | Cyber Trust • Porto

On-site
EUR 26,000 - 36,000
Cyber Defense Lead - EMEA
Cyber Defense Lead - EMEA

Randstad Enterprise • Lisboa

Hybrid
EUR 120,000 - 150,000
Hybrid/Remote Work