Cybersecurity Engineer Tier 2

Claranet

Lisboa

Presencial

EUR 45 000 - 65 000

Tempo integral

Há 2 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Destaca-te para esta função — gera um currículo e uma carta de apresentação personalizados em cerca de um minuto.

Ultrapassa os filtros ATS

Resumo da oferta

Claranet in Lisbon/Porto is seeking a Cybersecurity Engineer Tier 2 to join our internal SOC team. You will act as an L2 SOC Analyst, validating alerts escalated by Tier 1 and tuning detection rules in Microsoft Sentinel and Defender.

You will conduct root-cause analysis of incidents, support DFIR activities, and contribute to threat hunting, reporting, and continuous improvement of SOC processes. Collaboration with teams and clear communication are essential.

Qualificações

  • Solid SOC experience with incident analysis.
  • Hands-on with Microsoft Sentinel and Defender.
  • Strong technical analysis and incident investigation skills.
  • Knowledge of MITRE ATT&CK and IR/DFIR concepts.

Responsabilidades

  • Act as an L2 SOC Analyst handling alerts escalated by Tier 1.
  • Tune and optimize detection rules in SIEM/EDR/XDR.
  • Perform root cause analysis of security incidents.
  • Support DFIR activities including evidence collection.
  • Produce technical and executive reports for clients.

Conhecimentos

SOC experience
MITRE ATT&CK
DFIR fundamentals
Incident investigation

Formação académica

Security certifications (SC-200, GCED, GCIA, CySA+, Security+)

Ferramentas

Microsoft Sentinel
Microsoft Defender
SIEM/EDR/XDR
Azure

Descrição da oferta de emprego

We're fast learners, hard workers, natural collaborators... and weMake Modern Happen!

Our ambition is to unlock the potential of our digital world so that organisations everywhere can innovate and thrive securely.

We aim to achieve this goal by bringing together the world’s most talented people and the most powerful technologies, combining them to address our customers' challenges and to build something stronger together.

Right now, we are looking for aCybersecurity Engineer Tier 2 to integrate our internal team, based inLisbon/ Porto.

Your responsibilities include:

  • Act as an L2 SOC Analyst, ensuring in -depth analysis and validation of alerts escalated by Tier 1.
  • Perform fine -tuning and optimization of detection rules in Microsoft Sentinel, Microsoft Defender, and other SIEM platforms, focusing on reducing false positives and improving detection quality.
  • Conduct root cause analysis of security incidents, identifying attack vectors, impact, and corrective measures.
  • Support incident response and DFIR activities, including initial forensic analysis, event correlation, and evidence collection.
  • Contribute to threat hunting, behavioral analysis, and advanced threat detection initiatives.
  • Identify visibility gaps, logging issues, or excessive noise, and propose technical improvements.
  • Support the integration and validation of new log sources and technologies within the SOC.
  • Document incidents, technical analyses, and lessons learned, contributing to both technical and operational reports.
  • Collaborate with Tier 1 and Tier 3 analysts, promoting best practices and continuous process improvement within the SOC.
  • Tune and optimize detection rules (SIEM, EDR/XDR).
  • Identify and resolve visibility gaps, noise, or false positives.
  • Support onboarding of new log sources and technologies into the SOC.
  • Produce technical and executive reports for clients and internal stakeholders.
  • Promote best practices, mentor analysts, and support team growth.
You must have:
  • Solid SOC experience (minimum 2–4 years), including incident analysis.
  • Hands -on experience with Microsoft Sentinel, Microsoft Defender, and/or other SIEM/EDR/XDR tools.
  • Strong technical analysis and incident investigation skills.
  • Knowledge of MITRE ATT&CK, incident response (IR) concepts, and DFIR fundamentals.
  • Strong communication skills, with the ability to prioritize and collaborate effectively in an operational environment.
We value:
  • Previous experience in detection fine -tuning and continuous improvement of SIEM rules.
  • Experience in Digital Forensics & Incident Response (DFIR).
  • Security certifications (e.g., SC -200, GCED, GCIH, GCIA, CySA+, Security+).
  • Experience with Microsoft environments and cloud platforms (Azure).
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Cybersecurity Engineer Tier 2
Cybersecurity Engineer Tier 2

Claranet limited • Lisboa

Híbrido
EUR 40 000 - 60 000
Cybersecurity Engineer Tier 2: L2 SOC Analyst
Cybersecurity Engineer Tier 2: L2 SOC Analyst

Claranet • Lisboa

Presencial
EUR 45 000 - 65 000
SOC Threat Hunter & SIEM Tuning Engineer (Lisbon/Porto)
SOC Threat Hunter & SIEM Tuning Engineer (Lisbon/Porto)

Claranet limited • Lisboa

Híbrido
EUR 40 000 - 60 000
Senior SIEM Engineer
Senior SIEM Engineer

Claranet limited • Porto

Híbrido
EUR 60 000 - 90 000
Engenheiro de Cibersegurança ( Hibrido Lisboa)
Engenheiro de Cibersegurança ( Hibrido Lisboa)

Claranet limited • Lisboa

Híbrido
EUR 45 000 - 75 000
SOC Analyst L1/L2
SOC Analyst L1/L2

Alongside • Portugal

Híbrido
EUR 35 000 - 55 000
Employment Contract
Health Insurance
Meal Card
+3
Senior SOC & Incident Response Consultant
Senior SOC & Incident Response Consultant

Decskill • Lisboa

Híbrido
EUR 55 000 - 75 000
Cybersecurity Engineer Tier 1 - 24/7 Incident Response
Cybersecurity Engineer Tier 1 - 24/7 Incident Response

Claranet limited • Portugal

Teletrabalho
EUR 45 000 - 65 000
Cybersecurity Analyst L2 (Blue Team)
Cybersecurity Analyst L2 (Blue Team)

Inetum • Funchal

Híbrido
EUR 38 000 - 52 000
Cyber Security Engineer
Cyber Security Engineer

team.it • Lisboa

Presencial
EUR 42 000 - 62 000
Personalized Talent Management
Broad benefits package
Training and career development
+1