Security Engineer

ARMIS Group

Porto

Presencial

EUR 50 000 - 80 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Learning culture
Impact projects
Collaborative environment

Resumo da oferta

ARMIS Group is seeking a seasoned SOC Lead to drive Tier 3 escalation for security incidents and work with the client’s technical teams to ensure clear communication between SOC and client. You will develop and maintain incident response automations using Logic Apps and Playbooks, and perform proactive Threat Hunting to improve detections and data sources.

Join a team that values continuous learning, collaboration across multidisciplinary teams, and international client engagement in a dynamic

Qualificações

  • Proven experience in cybersecurity, preferably in SOC environments (Tier 2/3).
  • Strong knowledge of Microsoft security solutions, including Microsoft Sentinel (SIEM/SOAR) and Microsoft Defender XDR.
  • Experience with Microsoft M365 ecosystem and hybrid/cloud architecture environments.
  • Development of incident response automations using Logic Apps and Playbooks.
  • Good to know: KQL, PowerShell, and/or Python.
  • Familiarity with hybrid identity environments such as Active Directory and Microsoft Entra ID.
  • Experience in Threat Hunting activities and development of detections/analytic rules.
  • Ability to create and maintain technical documentation, operational guides, runbooks, and SOC procedures.
  • Valued certifications: SC-200, AZ-500, and SC-300.

Responsabilidades

  • Act as SOC Lead / Tier 3 escalation point for security incidents.
  • Collaborate closely with the client’s technical teams and ensure effective communication between SOC and client.
  • Develop and maintain incident response automations using Logic Apps and Playbooks.
  • Perform proactive Threat Hunting activities and improve detection capabilities through analytic rules and new data sources.
  • Create and maintain SOC operational guides, runbooks, and procedures.
  • Contribute to the continuous improvement of SOC processes and report directly to the CISO.

Conhecimentos

Cybersecurity
Microsoft security solutions
Microsoft Sentinel
Microsoft Defender XDR
Microsoft 365
Incident response automations
Logic Apps
Playbooks
KQL
PowerShell
Python
Active Directory
Microsoft Entra ID
Threat Hunting
SOC procedures
Documentation
English fluency
Certifications SC-200
Certifications AZ-500
Certifications SC-300

Ferramentas

Logic Apps
Playbooks
Active Directory
Microsoft Entra ID
Microsoft Sentinel
Microsoft Defender XDR
Microsoft 365

Descrição da oferta de emprego

Join Our Team at ARMIS – Moving Business Through Technology
About Us

ARMIS is a global leader in technological innovation, dedicated to developing and implementing cutting-edge solutions tailored to meet our clients’ unique needs. With expertise spanning various industries, from smart mobility through Intelligent Transportation Systems to digital transformation in finance, energy, and sports.

Our capabilities include:

  • Leveraging AI and RPA to lead the new era of intelligent solutions.
  • Developing custom corporate applications.
  • Implementing proactive security measures.
  • Transforming data into opportunities with Data Analytics.

At ARMIS, people are our greatest asset, and we believe in their continuous development. We provide a dynamic and challenging work environment where innovation is at the heart of everything we do.

We are always on the lookout for bright, ambitious individuals eager to make an impact. If you thrive in dynamic and innovative environments, are passionate about technology and its potential to transform industries and enjoy working on multidisciplinary teams to solve complex challenges, then ARMIS is the place for you. Join us and be part of shaping the future of technology.

Whatever you’re working on, what are the technical skills you’re likely to have?
  • Proven experience in Cybersecurity, preferably in SOC environments (Tier 2/3).
  • Strong knowledge of Microsoft security solutions, including Microsoft Sentinel (SIEM/SOAR) and Microsoft Defender XDR.
  • Experience with Microsoft M365 ecosystem and hybrid/cloud architecture environments.
  • Development of incident response automations using Logic Apps and Playbooks.
  • Good to know: KQL, PowerShell, and/or Python.
  • Familiarity with hybrid identity environments such as Active Directory and Microsoft Entra ID.
  • Experience in Threat Hunting activities and development of detections/analytic rules.
  • Ability to create and maintain technical documentation, operational guides, runbooks, and SOC procedures.
  • Valued certifications: SC-200, AZ-500, and SC-300.
What makes you a good candidate for this role?
  • Proactive and autonomous mindset in identifying and resolving security issues.
  • Strong communication skills, both written and verbal, with technical and non-technical stakeholders.
  • Ability to work closely with multidisciplinary teams and international clients.
  • Strategic and innovative approach to cybersecurity challenges and risk mitigation.
  • Strong collaboration and teamwork capabilities in SOC and security operations environments.
  • Continuous improvement mindset and constant awareness of the evolving threat landscape.
  • Fluency in English, both written and spoken, for regular communication with international teams and clients.
What will be your responsibilities in this position?
  • Act as SOC Lead / Tier 3 escalation point for security incidents.
  • Collaborate closely with the client’s technical teams and ensure effective communication between SOC and client.
  • Develop and maintain incident response automations using Logic Apps and Playbooks.
  • Perform proactive Threat Hunting activities and improve detection capabilities through analytic rules and new data sources.
  • Create and maintain SOC operational guides, runbooks, and procedures.
  • Contribute to the continuous improvement of SOC processes and report directly to the CISO.
What We Offer?
  • A culture of continuous learning and professional growth.
  • Opportunities to work on impactful projects across diverse industries.
  • A collaborative, supportive, and innovation-driven environment.
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Full Stack Engineer
Full Stack Engineer

ARMIS Group • Porto

Presencial
EUR 42 000 - 64 000
SOC Security Engineer — Incident Response & Threat Hunting
SOC Security Engineer — Incident Response & Threat Hunting

ARMIS Group • Porto

Presencial
EUR 50 000 - 80 000
Learning culture
Impact projects
Collaborative environment
Senior Security Analyst
Senior Security Analyst

OutSystems • Portugal

Presencial
EUR 70 000 - 100 000
Growth opportunities
Professional development funds
Internal mobility
Data Engineer
Data Engineer

ARMIS Group • Porto

Presencial
EUR 40 000 - 60 000
Career growth
Impactful projects
Collaborative environment
XSOAR Cybersecurity Engineer
XSOAR Cybersecurity Engineer

Claranet Portugal • Portugal

Híbrido
EUR 40 000 - 60 000
Certification paths resources
Regular teambuilding programs
Friendly workplace
AI Security Specialist
AI Security Specialist

LUZA Group • Lisboa

Presencial
EUR 55 000 - 90 000
Remote work when possible
Work equipment provided
Benefits plan
+1
Senior SIEM Engineer
Senior SIEM Engineer

Claranet limited • Porto

Híbrido
EUR 60 000 - 90 000
Cybersecurity Engineer Tier 2
Cybersecurity Engineer Tier 2

Claranet limited • Lisboa

Híbrido
EUR 40 000 - 60 000
Cyber Security Engineer
Cyber Security Engineer

team.it • Lisboa

Presencial
EUR 42 000 - 62 000
Personalized Talent Management
Broad benefits package
Training and career development
+1
Devoteam Cyber Trust | Application Security - Lead | Banking Sector
Devoteam Cyber Trust | Application Security - Lead | Banking Sector

Devoteam • Portugal

Presencial
EUR 40 000 - 60 000