Noesis

We are an international technology consultancy with a thousand talents specialized in different technologies. Every day, we work together to create innovative solutions that impact society. We are in Portugal, Spain, the Netherlands, Brazil, Ireland, and the USA. It is in cultural diversity and opportunities that we find the motivation to innovate and challenge ourselves to be better.
About company

Cybersecurity incident coordination & automation engineer

Remote

location Lisbon

date August 20, 2026

types Full-time

wage 36k-44k EUR

Cybersecurity Incident Coordination & Automation Engineer

Noesis is looking for the following profile:

Cybersecurity Incident Coordination & Automation Engineer is responsible for coordinating the incident response and designing, implementing, and verifying the detection and response automation capabilities of the SOC. Monitors and supports the review of metrics for services provided by the MSSP. Ensures alignment of cybersecurity operations with the Information Security Management Manual (ISMM) and with the regulatory requirements applicable to the aviation sector (NIS2, EASA PART-IS, GDPR).

Main Tasks and Responsibilities:

  • Coordinate the response to information security incidents throughout their lifecycle, according to established procedures;
  • Design, develop and maintain detection rules (detection-as-code) mapped to MITRE ATT&CK, in Microsoft Sentinel and Microsoft 365 Defender;
  • Develop and maintain response automations (SOAR) — Logic Apps, playbooks and integrations (e.g., ITSM) — reducing MTTR and manual effort;
  • Carry out Detection Assurance activities: purple teaming, technical audit of MSSP, hunting for false negatives and coverage validation;
  • Drive and verify MSSP performance via metrics, leading service reviews and ensuring compliance with SLAs;
  • Ensure operational quality (QA) in incident handling and adherence to playbooks;
  • Ensure alignment of processes with the Information Security Management Manual (ISMM) and contribute to its update;
  • Ensure compliance with regulatory obligations and reporting to authorities (ANAC, EASA, CNCS, CNPD), in the context of NIS2, EASA PART-IS and GDPR;
  • Onboarding and governance of log sources and cost optimization of the SIEM platform (FinOps Sentinel);
  • Produce operational indicators and evidence of compliance for audits;
  • Support the development and maintenance of operational documentation (playbooks, runbooks, RACI).

Requirements:

  • Educational Background: Bachelor's degree (master's preferred) in Information Technologies (e.g., Computer Science, Electrical Engineering, Telecommunications, Information Security);
  • Professional experience: between 2-5 years in a SOC environment, detection engineering or incident response;
  • Proven experience in detection and/or automation engineering (SOAR);
  • Solid knowledge of Microsoft Sentinel and Microsoft 365 Defender;
  • Proficiency in KQL and scripting (e.g., Python, PowerShell);
  • Knowledge of MITRE ATT&CK and threat hunting / purple teaming methodologies;
  • Familiarity with Information Security Management Systems (ISMS/ISMM) and reference frameworks (e.g., ISO/IEC 27001);
  • Knowledge of applicable regulatory requirements (NIS2, EASA PART-IS, GDPR) and reporting obligations to authorities;
  • Knowledge of Operating Systems (e.g., Windows, Linux) and Networking;
  • Proficiency in spoken and written Portuguese and English.

Preferred Requirements:

  • Previous experience in the aviation sector or in critical infrastructure / highly regulated environments;
  • Relevant certifications (e.g., Microsoft SC-200, AZ-500, SC-100; GIAC GCDA/GCIA; ISO/IEC 27001 Lead Implementer/Auditor);
  • Experience in Infrastructure as Code (IaC) and CI/CD for detection-as-code;
  • Experience in vendor/MSSP governance and preparing for audits;
  • Knowledge of FinOps practices applied to SIEM.

If you meet these requirements and would like to join an innovative organization that continuously invests in the training of its talents, send us your application.

Join us. Let’s innovate together!

All our recruitment and selection processes are based on equal opportunities, valuing the competence and potential of each person and ensuring that no candidate is discriminated against based on gender, ethnicity, sexual orientation, age, religion or physical condition.

- Announcement created under Law no. 4/2019, of January 10th