Security Operations Engineer | Cybersecurity Engineer

Atheneum

Porto

Híbrido

EUR 65 000 - 90 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Hybrid work model
Competitive compensation

Resumo da oferta

Atheneum in Porto is seeking a Security Engineer to own the security posture of a 400-person global company. You will design detections, automate incident response, and shape our cloud and identity protection.

You will work with Defender XDR, Entra ID, Intune, and AWS, build playbooks, partner with platform teams, and help secure AI use across the business while maintaining evidence for auditors and clients.

Qualificações

  • Experience designing and tuning detections and automations to reduce manual workload.
  • Experience handling incident response and post-incident reviews.
  • Knowledge of GDPR and security frameworks (ISO 27001, SOC 2, NIST).
  • Ability to communicate security risk to non-technical stakeholders.

Responsabilidades

  • Own external attack surface, coordinate penetration testing and remediation.
  • Develop and maintain detection logic and automation across Defender XDR and Sentinel.
  • Own backup and ransomware resilience, including restoration testing.
  • Create evidence packs and responses for auditors and clients.
  • Collaborate with platform and security teams to quantify risk and drive improvements.

Conhecimentos

Security Engineering
Cloud Security
Automation
Incident Response
Vulnerability Management

Ferramentas

PowerShell
Python
Defender XDR
Entra ID
AWS IAM

Descrição da oferta de emprego

At Atheneum, we are on a mission to unlock the power of knowledge and connect leading companies to the world's top professionals. Our work is driven by the belief that the insights of experts can help our clients make better business decisions and navigate future challenges and opportunities.

We're building something special in our Porto hub, a collaborative workspace where our values align beautifully with Portuguese work culture. Our hybrid model respects the importance of work-life balance that's central to Portuguese life, while embracing the deep-rooted values of loyalty, family connection, and community.

We're looking for team members who value meaningful face-to-face collaboration (ideally around three days weekly in our vibrant office) whilst having the freedom to manage their own schedule. This balance honours both the Portuguese appreciation for professional relationships built on respect and trust, and Atheneum's commitment to excellence, innovation, ownership, collaboration and inclusion.

About the Role

Our clients, including several of the world's leading consultancies, trust us with confidential research. That trust is the product, and you will be the engineer who protects it. Your mission in one sentence: a single stolen credential can never become a company-wide event.

You’ll own the security posture of a global company: 400 people, 9 offices, a corporate estate on Microsoft 365 and a platform estate on AWS. You’ll work with our Security Analyst, who handles day‑to‑day alert triage and gives us extended‑hours coverage across two timezones. That matters, because it means you are not the triage function. Your job is to set the standards the triage runs on, act as the second pair of eyes on significant security decisions, and spend most of your week engineering the alert queue smaller rather than working it. You also carry the escalation path for significant out‑of‑hours incidents, and help shape this into a small on‑call rotation as the team grows.

You’ll own the identity perimeter across both clouds: conditional access, identity protection and privileged access in Entra ID, and the federation into AWS, working with our platform engineers on their side of the boundary. You’ll harden and automate the endpoint estate through Intune and Microsoft Defender, and where the Defender stack can investigate and respond on its own, you’ll configure it to, keeping your time for the exceptions.

You’ll own our external attack surface: our public websites, exposed services and edge posture. You’ll scope our annual external penetration test against those assets, keep automated scanning and attack‑surface testing running continuously between those tests, own the findings through to remediation, and turn the results into evidence. Code‑level fixes belong to our engineering squads and their leads; finding the weakness and gating the risk belongs to you.

You’ll also own recoverability. Ransomware resilience is a recovery problem before it is a detection problem, so backup posture and scheduled restore tests for the corporate estate are yours, in partnership with the platform team on theirs. A backup only counts once you have restored from it. Incident response planning sits with you too: playbooks, periodic testing, and post‑incident reviews.

Finally, your work has a commercial audience. Client security teams assess us before and during engagements, and you’ll maintain the evidence pack and answer library our Risk and Compliance team uses to respond, turning week‑long questionnaire exercises into answers within days. At Atheneum your security engineering wins and keeps business.

Atheneum is an AI‑first company. Every function works with enterprise frontier models under our Generative AI Acceptable Use Policy, and this role sits on both sides of that. You’ll use AI daily to write detections, build automation and draft evidence. You’ll also help secure the company's use of it: agentic AI brings a new class of risk, from prompt injection hidden in the documents and connectors our LLMs read to over‑broad permissions on agents acting unattended, and that threat model is yours alongside the traditional one.

Technology

Currently we use the following:

  • Microsoft Defender XDR (Endpoint, Office 365, Cloud Apps), Entra ID and Identity Protection, Intune, Purview.
  • Microsoft Sentinel and KQL for log collection, hunting and detection.
  • PowerShell and Python for automation.
  • Frontier models (enterprise tier) for engineering, automation and investigation work, under our Generative AI Acceptable Use Policy.

We're looking for smart people, rather than engineers that can use this tool or that language. You’ll get the opportunity to influence the technology and methodologies we use, but the themes are: identity‑first security, automation over manual process, evidence over assertion, and cloud‑native tooling.

About You

We hire for culture and potential. At Atheneum you’ll be the go‑to person on security, and the qualities that make that work matter more than any certification.

You have a bias to action

You’d rather ship a good control this week than design a perfect one for next quarter. You’ve learned when to refine further and when to release, and you measure yourself on what changed, not what you analysed.

You automate yourself out of repetitive work

When you see the same alert three times, your instinct is to kill the category. You treat manual security operations as a backlog of automation opportunities.

You own outcomes

In a small function, there’s no one to hand things to. You prioritise ruthlessly and escalates early. You know the difference between owning a risk and hiding one. You’re comfortable being the person who decides, and equally comfortable writing down why.

You communicate like it matters

Your write‑ups go in front of client security teams and company leadership. You can explain a technical risk to a lawyer and a decision to an executive, each in their own language.

You are AI‑first in how you work

You already use AI as a core working tool, and you can prove it. You have specific examples of using AI to multiply your output, whether a detection suite built in half the usual time or an automation you would not have attempted alone, and you verify what it produces before you rely on it.

Job Requirements

You should be able to demonstrate the use of some of the below skills, preferably by referencing previous commercial experience:

Security Engineering & Operations
  • Running security operations in a Microsoft 365 environment: Sentinel, Defender XDR, Entra ID, Intune.
  • Building detections and automation (KQL in Sentinel or Defender XDR, PowerShell or Python) that reduced manual workload.
  • Investigating and responding to incidents and writing them up clearly afterwards.
  • Vulnerability management: prioritising by exploitability and driving remediation with other teams.
  • Reviewing threat‑analytics reports and tuning detections, hardening (Defender ASR) and patch SLAs off the back of them.
  • Designing or tuning data‑loss (DLP) and Cloud App Security policies and the detections behind them.
Identity & Cloud
  • Designing or operating conditional access, privileged access, and identity protection.
  • Working knowledge of AWS identity and access management, or the demonstrated ability to extend identity thinking into a second cloud.
Exposure & Evidence
  • Managing an external attack surface: web properties, exposed services, edge and TLS posture.
  • Scoping or consuming penetration tests, running automated or continuous vulnerability scanning, and owning findings through to closure.
  • Producing security documentation or evidence for auditors, clients or compliance teams.
  • Working knowledge of GDPR and common security frameworks (ISO 27001, SOC 2, PCI DSS, NIST, CIS) as they appear in client assessments and audits.
  • Running or contributing to an ISO 27001, SOC 2 or comparable compliance programme: control implementation, company‑wide security policy development, risk assessments, and periodic auditing against the framework.
  • Building and running a security awareness programme: training and phishing simulations that measurably change user behaviour.
  • Assessing third‑party, SaaS and vendor security risk before and during adoption.
AI Fluency
  • Broad, sustained use of AI in your daily work, well beyond occasional prompting.
  • Using AI to build automation, write detection logic or accelerate investigations, with results you can quantify.
  • A verification habit: AI output is a draft to check, never a source, especially where the output is load‑bearing.
  • Awareness of AI‑specific security risk: prompt injection, agentic permissions and data handling rules for what may go into which tool.
Ways of Working
  • Operating with autonomy and minimal supervision, and getting things done.
  • Setting technical direction for colleagues without formal authority.
  • Working effectively in English (we're a multi‑cultural international company).

We understand you might not tick every box on this list. If you're passionate, eager to learn, and ready to contribute your unique strengths, and the role excites you, we're more interested in your potential and approach than in a perfect match of qualifications.

We're building an inclusive workplace where every voice is heard and every idea respected. We actively encourage applications from all backgrounds, especially those underrepresented in tech. A diverse team makes us stronger.

At Atheneum, we believe exceptional tech talent deserves exceptional rewards. Join our growing team in Portugal and enjoy a benefits package designed to support your performance, growth, and quality of life.

All benefits are fully compliant with Portuguese labour laws and exceed standard market offerings for the tech sector.

Join over 400 professionals powering the future of insights. At Atheneum, your skills meet global impact, and your career meets lifestyle.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Backend Staff Engineer
Backend Staff Engineer

login.works • Lisboa

Híbrido
EUR 100 000 - 150 000
Hybrid role
Cyber Security Engineer
Cyber Security Engineer

team.it • Lisboa

Presencial
EUR 42 000 - 62 000
Personalized Talent Management
Broad benefits package
Training and career development
+1
Azure Security Engineer: Automate, Enforce, Protect
Azure Security Engineer: Automate, Enforce, Protect

Affinity • Porto

Presencial
EUR 38 000 - 66 000
Lead Security Operations Engineer
Lead Security Operations Engineer

Pleo • Lisboa

Híbrido
EUR 80 000 - 120 000
Private healthcare
Hybrid/Remote options
Lunch allowance
Application Security Engineer
Application Security Engineer

Thought Machine Group Limited • Portugal

Presencial
EUR 50 000 - 80 000
Highly competitive salary
Voluntary Pension Plan (match up to 5%)
Private Healthcare Insurance
+3
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Thought Machine Group Limited • Portugal

Híbrido
EUR 90 000 - 140 000
Highly competitive salary
Private Healthcare Insurance
Private Life Insurance
+1
Senior Security Engineer
Senior Security Engineer

Innova Recruitment • Porto

Híbrido
EUR 55 000 - 65 000
Bonus
Health insurance
Wellness allowance
+2
Senior SOC & Incident Response Consultant
Senior SOC & Incident Response Consultant

Decskill • Lisboa

Híbrido
EUR 55 000 - 75 000
Lead Software Engineer, mobile applications
Lead Software Engineer, mobile applications

Atheneum • Porto

Híbrido
EUR 50 000 - 70 000
Flexible hybrid work policy
25 days annual leave, increasing to 30
Work From Anywhere for up to 8 weeks
+3
Hybrid Security Ops Engineer (Porto) | AI‑First Cyber Defense
Hybrid Security Ops Engineer (Porto) | AI‑First Cyber Defense

Atheneum • Porto

Híbrido
EUR 65 000 - 90 000
Hybrid work model
Competitive compensation