Blue Team Lead: Threat Detection & Incident Response

Nearshore Portugal

Porto

On-site

EUR 70,000 - 100,000

Full time

47 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Nearshore Portugal seeks a Blue Team Lead to provide technical leadership in threat detection and incident response within an international cybersecurity team. You will help build and maintain detection and response capabilities, guide analysts, and drive security incidents through to resolution.

You will lead incident investigations, develop runbooks, and tune detection rules while collaborating with teams globally. Strong English and a calm, results‑oriented approach are essential.

Qualifications

  • At least 5 years of experience in incident detection and response.
  • Experience in DFIR with Velociraptor or KAPE.
  • Experience with Cortex and vulnerability management.
  • Strong incident management skills and a structured approach to investigations.
  • Ability to guide analysts, collaborate across teams, and make decisions under pressure.
  • Strong written and verbal communication skills.
  • Calm, rigorous, and results‑oriented approach.
  • Good command of English.

Responsibilities

  • Provide technical leadership and support analysts’ skills development.
  • Detect, investigate, and respond to security incidents across the organization.
  • Conduct digital forensic investigations and proactive threat hunting based on threat intelligence.
  • Develop and tune detection rules.
  • Create and maintain operational runbooks.
  • Perform root cause analysis and post-incident reviews.
  • Improve incident response plans and detection and response processes.
  • Evaluate security technologies to strengthen detection and response capabilities.
  • Validate and triage vulnerabilities, tracking remediation through to completion.
  • Participate in emergency response activities when required.
  • Provide regular reporting on security activities and findings.

Skills

Incident detection
Incident response
DFIR
Leadership
English
Team guidance

Tools

Velociraptor
KAPE
Cortex

Job description

Nearshore Portugal seeks a Blue Team Lead to provide technical leadership in threat detection and incident response within an international cybersecurity team. You will help build and maintain detection and response capabilities, guide analysts, and drive security incidents through to resolution.

You will lead incident investigations, develop runbooks, and tune detection rules while collaborating with teams globally. Strong English and a calm, results‑oriented approach are essential.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Blue Team Lead – Detection & Incident Response
Blue Team Lead – Detection & Incident Response

Nearshore Portugal • Porto

On-site
EUR 70,000 - 100,000
Lead Security Engineer - Cloud & Infra
Lead Security Engineer - Cloud & Infra

Nearshore Portugal • Porto

On-site
EUR 90,000 - 130,000
SOC Analyst: Threat Detection & Incident Response
SOC Analyst: Threat Detection & Incident Response

Devoteam | Cyber Trust • Porto

On-site
EUR 35,000 - 48,000
Blue Team Security Engineer — SOC/DFIR in Lisbon
Blue Team Security Engineer — SOC/DFIR in Lisbon

Tekever Corporation • Lisboa

On-site
EUR 40,000 - 65,000
Subsídio de refeição
Seguro de saúde
Transporte para escritórios (Leiria, C
+1
Senior Offensive Security Auditor | Red Team Lead, Portugal
Senior Offensive Security Auditor | Red Team Lead, Portugal

Thales Group • Leça do Balio

Hybrid
EUR 70,000 - 90,000
Flexible working model
Medium travel
Competitive package
EMEA Cyber Defense Lead (Hybrid/Remote)
EMEA Cyber Defense Lead (Hybrid/Remote)

Randstad - Netherlands • Portugal

On-site
EUR 90,000 - 150,000
Hybrid/remote work environment
Remote Security Operations Center Analyst – Threat Detection & Response
Remote Security Operations Center Analyst – Threat Detection & Response

Conclusion Lifecycle • Portugal

On-site
EUR 38,000 - 56,000
Red Team Consultant
Red Team Consultant

Inetum • Portugal

On-site
EUR 50,000 - 70,000
SOC Analyst | Threat Detection & Incident Response Mastery
SOC Analyst | Threat Detection & Incident Response Mastery

Claranet limited • Lisboa

Hybrid
EUR 42,000 - 62,000
Threat Intelligence Analyst
Threat Intelligence Analyst

Thales • Matosinhos

Hybrid
EUR 36,000 - 60,000