
ITDS Portugal
ITDS is a leader in outsourcing IT engineers and works with various web and mobile technologies for over 30 global clients. It has been recognized as one of the 1000 fastest-growing companies in Europe for three consecutive years, Great Place to Work, and the Forbes Diamond award in 2023. ITDS currently has more than 600 IT professionals working in Portugal, Poland, and the Netherlands.
About company Senior SOC Analyst – Cloud Security & Threat Detection
On-site
October 10, 2026
Unleash your potential to combat cyber threats and shape the future of cloud security with innovative threat detection and incident response strategies.
Location & Work Model
Portugal —100% Full Remote
Your main responsibilities:
- Continuously monitor security alerts across the digital footprint using a SIEM (e.g. Elastic SIEM), network detection (e.g. Darktrace), and EDR/XDR (e.g. CrowdStrike Falcon), and perform initial validation to separate genuine anomalies from false positives (Tier 1).
- Investigate verified alerts in depth — correlate endpoint, cloud, and network telemetry to reconstruct attack timelines and assess threat impact (Tier 2).
- Monitor, audit, and analyse anomalies across cloud workloads using native security tooling in AWS, Azure, or GCP.
- Contribute to detection use-case development and help build and refine security automation workflows (e.g. Cortex XSOAR).
- Execute containment actions following documented playbooks — isolate compromised hosts, deploy network blocks, or revoke compromised cloud credentials.
- Document findings, log artifacts, and containment actions precisely in the ticketing system, and escalate high-severity or systemic incidents to Tier 3 and the Incident Response lead.
You're ideal for this role if you have:
- Experience in a SOC, security monitoring, or incident response role — roughly 1+ year for a Tier 1 focus, 3+ years for a Tier 2 focus.
- Hands-on experience with a SIEM platform (Elastic SIEM, Splunk, Microsoft Sentinel, IBM QRadar, or similar).
- Experience with EDR/XDR tooling (CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Cortex XDR, or similar).
- Familiarity with network detection and response tools (Darktrace, Vectra, ExtraHop, or similar).
- Working knowledge of at least one major cloud platform (AWS, Azure, or GCP) and its native security, logging, and monitoring services.
- A solid grasp of TCP/IP, common attack techniques, and the MITRE ATT&CK framework.
- Strong written communication for clear, precise incident documentation.
- Willingness to work in a 24/7 rotating shift environment.
It is a strong plus if you have:
- Experience with SOAR platforms and security automation (Cortex XSOAR, Splunk SOAR, Tines, or similar).
- Scripting for automation (Python, PowerShell, or Bash).
- Relevant certifications (CompTIA Security+ or CySA+, GIAC GCIH/GCIA, cloud security, or vendor certifications such as CrowdStrike or Elastic).
- Experience in financial services or another regulated environment.
Language Required for the role:
- Fluent English.
Eligibility for the role:
- Only candidates with an existing legal right to work in Portugal will be considered.
Para se candidatar a este anúncio, visite o anúncio original no ITJobs.