SIEM & Threat Detection Engineer | Security Operations
🚀 Build, tune and continuously improve enterprise threat detection capabilities.
📍 Portugal - Candidates must already have the legal right to work in Portugal.
🌍 International Cybersecurity Programme
🛡️ SIEM | Threat Detection | EDR | Security Engineering
💼 Full-time | B2B
We're looking for an experienced SIEM & Threat Detection Engineer to join a major international cybersecurity environment, helping evolve security monitoring and detection capabilities across multiple customer environments.
You'll work at the intersection of Security Operations and Detection Engineering, focusing on SIEM administration, detection use cases, security content, telemetry integration and continuous improvement of threat detection services.
What you'll do
- Develop, implement, validate and tune security monitoring and detection capabilities
- Administer and optimise SIEM and EDR platforms
- Manage the lifecycle of security detection use cases
- Review, test and tune detection rules and security content
- Onboard and integrate new security data sources and telemetry feeds
- Work with Threat Intelligence and Incident Response teams to translate threats into effective detections
- Support security architecture reviews from a monitoring and detection perspective
- Reduce false positives and continuously improve detection quality
- Build and maintain security operations metrics, dashboards and KPIs
- Perform quality assurance and control validation activities
- Maintain CSOC procedures, documentation and knowledge-base content
- Prepare technical reports and recommendations for internal and external stakeholders
What we're looking for
- 5+ years of relevant IT / Cybersecurity experience
- Proven hands-on experience administering a SIEM platform
- Strong experience with Microsoft Sentinel and/or Splunk
- Experience with other SIEM technologies such as QRadar, ArcSight or ELK
- Strong knowledge of security monitoring and threat detection
- Experience with EDR solutions, including Microsoft Defender for Endpoint and/or CrowdStrike
- Deep knowledge of the Microsoft Security ecosystem, including Sentinel, Defender, XDR and Azure Security
- Strong cloud knowledge across Azure, AWS and/or GCP
- Experience analysing security threats and collaborating with Incident Response teams
- Knowledge of email security and network monitoring
- Fluent English
Nice to have
- Experience designing SIEM architectures
- Experience building log ingestion pipelines across cloud and on-premises environments
- AWS security monitoring experience
- PowerShell, Python, Bash or similar scripting
- Microsoft SC-200
- GCIH / GCFA / CEH / GIAC
- Other relevant cybersecurity certifications
Working Model
- 🏠 Remote - needs to work in Portugal
- 🕘 European working hours (CET/CEST ±2h)
- 🔄 Participation in an on-call rotation — approximately one week per month
- 📅 Initial 6-month engagement, with possibility of extension
- 🌍 International and distributed cybersecurity team
Recruitment Process
Our process is straightforward:
- Initial Screening – Applications are reviewed and selected candidates can expect an initial contact within 2–3 business days after applying
- Technical Validation – 1 to 3 stages with our internal/client technical teams, depending on seniority and profile
- Offer
📅 Applications are open until 12 October 2026.
We aim to keep the process transparent, practical and efficient, with clear feedback throughout each stage.
Apply and let's talk.