Descrição do trabalho
We're fast learners, hard workers, natural collaborators... and we Make Modern Happen !
Our ambition is to unlock the potential of our digital world so that organisations everywhere can innovate and thrive securely.
We aim to achieve this goal by bringing together the world’s most talented people and the most powerful technologies, combining them to address our customers' challenges and to build something stronger together.
If you share our vision, join us!
Right now, we are looking for a XSOAR Cybersecurity Engineer to integrate our internal team, based in Lisbon or Porto.
Your responsibilities include:
Design, implement and maintain SOAR use cases and automated playbooks on platforms such as Cortex XSOAR, Microsoft Sentinel and FortiSIEM;
Monitor and analyze security alerts from various SIEM platforms, ensuring an effective and timely response;
Correlate and investigate logs from multiple sources (e.g., Elastic, Sentinel, FortiSIEM) to identify malicious patterns and potential incidents;
Develop automation scripts and integrations to speed up incident response;
Continuously optimize SOAR workflows to reduce false positives and improve response efficiency;
Document incident response procedures and contribute to the team knowledge base;
Accompany and train junior SOC analysts in best practices and automation technologies;
Participate in post-incident analysis and contribute to identifying root causes and improving processes.
You must have:
Academic degree level 4 or higher in IT, Computer Science, Security or equivalent professional experience;
Minimum of 3 years experience in SOC environments or security operations;
At least 1 year of practical experience with SOAR platforms;
Proficiency in scripting languages: Python, PowerShell or Bash;
Good understanding of incident response frameworks, threat detection and security monitoring;
Knowledge of and practical experience with: Palo Alto Cortex XSOAR, Microsoft Sentinel and FortiSIEM.
We value:
Experience with other automation tools, such as: Elastic Security (Elastic SIEM), Tines, DFLabs IncMan, Siemplify (Chronicle SOAR) and Swimlane;
Familiarity with integrations via REST APIs;
Knowledge of the MITRE ATT&CK Framework and good technical documentation practices;
Relevant certifications, namely: Palo Alto Cortex XSOAR Certified Automation Engineer; Microsoft SC-200: Security Operations Analyst Associate; Fortinet NSE 5 - FortiSIEM; Elastic Certified Analyst; Swimlane Certified SOAR Developer; Tines Automation Specialist.
We offer:
Regular professional development;
Certification paths resources;
Regular teambuilding programs;
Friendly workplace.
Workplace: Lisbon/Porto (Hybrid)
Claranet: Make Modern Happen!