Back to search
Claranet Portugal Linkedin · Posted yesterday

Senior SIEM Engineer (Hybrid- Porto)

Portugal

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

We're fast learners, hard workers, natural collaborators... and we Make Modern Happen!


Our ambition is to unlock the potential of our digital world so that organisations everywhere can innovate and thrive securely.

We aim to achieve this goal by bringing together the world’s most talented people and the most powerful technologies, combining them to address our customers' challenges and to build something stronger together.


If you share our vision, join us!


Right now, we are looking for a Senior SIEM Engineer to integrate our internal team, based in Porto.


Your responsibilities include:


  • Design, implement, and maintain security monitoring solutions across enterprise environments.
  • Develop, tune, and optimize detection use cases within Microsoft Sentinel and other SIEM platforms.
  • Engineer and onboard log sources, ensuring data quality, normalization, and operational reliability.
  • Create, maintain, and improve KQL detection rules, analytics, watchlists, and threat hunting queries.
  • Automate security operations using PowerShell, Bash, Python, Ansible, and other scripting technologies.
  • Deploy and manage SIEM infrastructure components, including Graylog, Logstash, Syslog-ng, Docker/Podman, and related services.
  • Perform security engineering activities to enhance monitoring coverage and detection capabilities.
  • Investigate and improve security telemetry, reducing false positives while increasing detection accuracy.
  • Collaborate with infrastructure, networking, and security teams to integrate new technologies into the monitoring ecosystem.
  • Develop technical documentation, implementation guides, and operational procedures.
  • Support vulnerability management initiatives by improving visibility and security monitoring.
  • Ensure security monitoring solutions follow industry best practices and operational standards.


You must have:

  • Proven experience administering and engineering Microsoft Sentinel environments.
  • Strong experience writing and optimizing KQL queries for detection engineering.
  • Solid experience with SIEM technologies such as Microsoft Sentinel and Graylog.
  • Hands-on knowledge of log collection technologies including Syslog-ng, Logstash, NXLog, Windows Event Forwarding (WEF), and Syslog.
  • Experience deploying and maintaining Linux-based security infrastructure.
  • Strong scripting and automation skills using PowerShell, Bash, Python, or Ansible.
  • Familiarity with Docker, Podman, and containerized deployments.
  • Proficiency in English to communicate effectively with technical and executive stakeholders.


We value:


  • Microsoft certifications such as SC-200 (Microsoft Security Operations Analyst) or AZ-500 (Azure Security Engineer).
  • Knowledge of threat modeling frameworks and detection methodologies like MITRE ATT&CK.
  • Strong analytical thinking for telemetry optimization and noise reduction.
  • Excellent communication skills to convey complex technical concepts to multi-disciplinary teams.
  • A proactive approach to continuous learning and adapting to cloud security tools.


We offer:

  • Regular professional development;
  • Certification paths resources;
  • Regular teambuilding programs;
  • Friendly workplace.


Workplace: Porto - Hybrid

Claranet: Make Modern Happen!



Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search