Cybersecurity Engineer Tier 2

Claranet limited

Lisboa

Presencial

EUR 40 000 - 60 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Claranet limited is looking for a Cybersecurity Engineer Tier 2 based in Lisbon or Porto. This role involves acting as an L2 SOC Analyst, handling the analysis and validation of alerts, and optimizing detection rules across various SIEM tools.

Qualifications include solid SOC experience (2–4 years), hands-on experience with tools like Microsoft Sentinel, and a strong understanding of incident investigation. Candidates with relevant security certifications and knowledge of DFIR will stand out.

Qualificações

  • 2–4 years of SOC experience including incident analysis.
  • Hands-on experience with SIEM tools like Microsoft Sentinel.
  • Strong skills in technical analysis and incident investigation.

Responsabilidades

  • Act as an L2 SOC Analyst, analyzing and validating alerts from Tier 1.
  • Optimize detection rules in Microsoft Sentinel and minimize false positives.
  • Conduct root cause analysis and support incident response activities.

Conhecimentos

SOC experience
Microsoft Sentinel
Technical analysis
Incident investigation
Communication skills

Formação académica

Security certifications (e.g., SC-200, GCED)

Ferramentas

Microsoft Defender
Other SIEM/EDR/XDR tools

Descrição da oferta de emprego

Cybersecurity Engineer Tier 2

Location: Lisbon/Porto

Responsibilities
  • Act as an L2 SOC Analyst, ensuring in-depth analysis and validation of alerts escalated by Tier 1.
  • Perform fine‑tuning and optimization of detection rules in Microsoft Sentinel, Microsoft Defender, and other SIEM platforms, focusing on reducing false positives and improving detection quality.
  • Conduct root cause analysis of security incidents, identifying attack vectors, impact, and corrective measures.
  • Support incident response and DFIR activities, including initial forensic analysis, event correlation, and evidence collection.
  • Contribute to threat hunting, behavioral analysis, and advanced threat detection initiatives.
  • Identify visibility gaps, logging issues, or excessive noise, and propose technical improvements.
  • Support the integration and validation of new log sources and technologies within the SOC.
  • Document incidents, technical analyses, and lessons learned, contributing to both technical and operational reports.
  • Collaborate with Tier 1 and Tier 3 analysts, promoting best practices and continuous process improvement within the SOC.
  • Tune and optimize detection rules (SIEM, EDR/XDR).
  • Identify and resolve visibility gaps, noise, or false positives.
  • Support onboarding of new log sources and technologies into the SOC.
  • Produce technical and executive reports for clients and internal stakeholders.
  • Promote best practices, mentor analysts, and support team growth.
Qualifications
  • Solid SOC experience (minimum 2–4 years), including incident analysis.
  • Hands‑on experience with Microsoft Sentinel, Microsoft Defender, and/or other SIEM/EDR/XDR tools.
  • Strong technical analysis and incident investigation skills.
  • Knowledge of MITRE ATT&CK, incident response (IR) concepts, and DFIR fundamentals.
  • Strong communication skills, with the ability to prioritize and collaborate effectively in an operational environment.
Preferred Qualifications
  • Previous experience in detection fine‑tuning and continuous improvement of SIEM rules.
  • Experience in Digital Forensics & Incident Response (DFIR).
  • Security certifications (e.g., SC-200, GCED, GCIH, GCIA, CySA+, Security+).
  • Experience with Microsoft environments and cloud platforms (Azure).
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

SOC Threat Hunter & SIEM Tuning Engineer (Lisbon/Porto)
SOC Threat Hunter & SIEM Tuning Engineer (Lisbon/Porto)

Claranet limited • Lisboa

Híbrido
EUR 40 000 - 60 000
Cybersecurity Engineer Tier 1 - 24/7 Incident Response
Cybersecurity Engineer Tier 1 - 24/7 Incident Response

Claranet limited • Portugal

Teletrabalho
EUR 45 000 - 65 000
SOC Analyst L1 (Blue Team)
SOC Analyst L1 (Blue Team)

Inetum • Portugal

Híbrido
EUR 30 000 - 45 000
Senior SIEM Engineer
Senior SIEM Engineer

Claranet limited • Porto

Híbrido
EUR 60 000 - 90 000
SOC Analyst L1 (Blue Team)
SOC Analyst L1 (Blue Team)

Inetum • Ponta Delgada

Presencial
EUR 30 000 - 50 000
SOC Analyst L1/L2
SOC Analyst L1/L2

Alongside • Porto

Híbrido
EUR 42 000 - 65 000
Employment Contract
Health Insurance
Meal Card
+2
Senior SOC Analyst (Tier 2) – Hybrid Work & Incident Mastery
Senior SOC Analyst (Tier 2) – Hybrid Work & Incident Mastery

Phiture • Lisboa

Híbrido
EUR 42 000 - 62 000
Modelo de trabalho híbrido
Plano de formação e certificações
Experiência com clientes internos e |
Senior SOC Analyst (Tier 2)
Senior SOC Analyst (Tier 2)

Phiture • Lisboa

Híbrido
EUR 42 000 - 62 000
Modelo de trabalho híbrido
Plano de formação e certificações
Experiência com clientes internos e |
CSIRT Analyst
CSIRT Analyst

PrimeIT • Lisboa

Presencial
Food Allowance
Flex Benefits
Senior SIEM Engineer (Hybrid- Porto)
Senior SIEM Engineer (Hybrid- Porto)

Claranet Portugal • Porto

Presencial
EUR 60 000 - 90 000