Security Operations Engineer | Cybersecurity Engineer
Indexed description
At Atheneum, we are on a mission to unlock the power of knowledge and connect leading companies to the world's top professionals. Our work is driven by the belief that the insights of experts can help our clients make better business decisions and navigate future challenges and opportunities.
We're building something special in our Porto hub, a collaborative workspace where our values align beautifully with Portuguese work culture. Our hybrid model respects the importance of work-life balance that's central to Portuguese life, while embracing the deep-rooted values of loyalty, family connection, and community.
We're looking for team members who value meaningful face-to-face collaboration (ideally around three days weekly in our vibrant office) whilst having the freedom to manage their own schedule. This balance honours both the Portuguese appreciation for professional relationships built on respect and trust, and Atheneum's commitment to excellence, innovation, ownership, collaboration and inclusion.
About the Role
Our clients, including several of the world's leading consultancies, trust us with confidential research. That trust is the product, and you will be the engineer who protects it. Your mission in one sentence: a single stolen credential can never become a company-wide event.
You'll own the security posture of a global company: 400 people, 9 offices, a corporate estate on Microsoft 365 and a platform estate on AWS. You'll work with our Security Analyst, who handles day-to-day alert triage and gives us extended-hours coverage across two timezones. That matters, because it means you are not the triage function. Your job is to set the standards the triage runs on, act as the second pair of eyes on significant security decisions, and spend most of your week engineering the alert queue smaller rather than working it. You also carry the escalation path for significant out-of-hours incidents, and help shape this into a small on-call rotation as the team grows.
You'll own the identity perimeter across both clouds: conditional access, identity protection and privileged access in Entra ID, and the federation into AWS, working with our platform engineers on their side of the boundary. You'll harden and automate the endpoint estate through Intune and Microsoft Defender, and where the Defender stack can investigate and respond on its own, you'll configure it to, keeping your time for the exceptions.
You'll own our external attack surface: our public websites, exposed services and edge posture. You'll scope our annual external penetration test against those assets, keep automated scanning and attack-surface testing running continuously between those tests, own the findings through to remediation, and turn the results into evidence. Code-level fixes belong to our engineering squads and their leads; finding the weakness and gating the risk belongs to you.
You'll also own recoverability. Ransomware resilience is a recovery problem before it is a detection problem, so backup posture and scheduled restore tests for the corporate estate are yours, in partnership with the platform team on theirs. A backup only counts once you have restored from it. Incident response planning sits with you too: playbooks, periodic testing, and post-incident reviews.
Finally, your work has a commercial audience. Client security teams assess us before and during engagements, and you'll maintain the evidence pack and answer library our Risk and Compliance team uses to respond, turning week-long questionnaire exercises into answers within days. At Atheneum your security engineering wins and keeps business.
Atheneum is an AI-first company. Every function works with enterprise frontier models under our Generative AI Acceptable Use Policy, and this role sits on both sides of that. You'll use AI daily to write detections, build automation and draft evidence. You'll also help secure the company's use of it: agentic AI brings a new class of risk, from prompt injection hidden in the documents and connectors our LLMs read to over-broad permissions on agents acting unattended, and that threat model is yours alongside the traditional one.
Technology
Currently we use the following:
- Microsoft Defender XDR (Endpoint, Office 365, Cloud Apps), Entra ID and Identity Protection, Intune, Purview.
- Microsoft Sentinel and KQL for log collection, hunting and detection.
- Amazon Web Services (AWS) for our platform estate.
- PowerShell and Python for automation.
- Frontier models (enterprise tier) for engineering, automation and investigation work, under our Generative AI Acceptable Use Policy.
We're looking for smart people, rather than engineers that can use this tool or that language. You'll get the opportunity to influence the technology and methodologies we use, but the themes are: identity-first security, automation over manual process, evidence over assertion, and cloud-native tooling.
About You
We hire for culture and potential. At Atheneum you'll be the go-to person on security, and the qualities that make that work matter more than any certification.
You have a bias to action
You'd rather ship a good control this week than design a perfect one for next quarter. You've learned when to refine further and when to release, and you measure yourself on what changed, not what you analysed.
You automate yourself out of repetitive work
When you see the same alert three times, your instinct is to kill the category. You treat manual security operations as a backlog of automation opportunities.
You own outcomes
In a small function, there's no one to hand things to. You prioritise ruthlessly and escalate early. You know the difference between owning a risk and hiding one. You're comfortable being the person who decides, and equally comfortable writing down why.
You communicate like it matters
Your write-ups go in front of client security teams and company leadership. You can explain a technical risk to a lawyer and a decision to an executive, each in their own language.
You are AI-first in how you work
You already use AI as a core working tool, and you can prove it. You have specific examples of using AI to multiply your output, whether a detection suite built in half the usual time or an automation you would not have attempted alone, and you verify what it produces before you rely on it.
Job Requirements
You should be able to demonstrate the use of some of the below skills, preferably by referencing previous commercial experience:
Security Engineering & Operations
- Running security operations in a Microsoft 365 environment: Sentinel, Defender XDR, Entra ID, Intune.
- Building detections and automation (KQL in Sentinel or Defender XDR, PowerShell or Python) that reduced manual workload.
- Investigating and responding to incidents and writing them up clearly afterwards.
- Vulnerability management: prioritising by exploitability and driving remediation with other teams.
- Reviewing threat-analytics reports and tuning detections, hardening (Defender ASR) and patch SLAs off the back of them.
- Designing or tuning data-loss (DLP) and Cloud App Security policies and the detections behind them.
Identity & Cloud
- Designing or operating conditional access, privileged access, and identity protection.
- Working knowledge of AWS identity and access management, or the demonstrated ability to extend identity thinking into a second cloud.
Exposure & Evidence
- Managing an external attack surface: web properties, exposed services, edge and TLS posture.
- Scoping or consuming penetration tests, running automated or continuous vulnerability scanning, and owning findings through to closure.
- Producing security documentation or evidence for auditors, clients or compliance teams.
- Working knowledge of GDPR and common security frameworks (ISO 27001, SOC 2, PCI DSS, NIST, CIS) as they appear in client assessments and audits.
- Running or contributing to an ISO 27001, SOC 2 or comparable compliance programme: control implementation, company-wide security policy development, risk assessments, and periodic auditing against the framework.
- Building and running a security awareness programme: training and phishing simulations that measurably change user behaviour.
- Assessing third-party, SaaS and vendor security risk before and during adoption.
AI Fluency
- Broad, sustained use of AI in your daily work, well beyond occasional prompting.
- Using AI to build automation, write detection logic or accelerate investigations, with results you can quantify.
- A verification habit: AI output is a draft to check, never a source, especially where the output is load-bearing.
- Awareness of AI-specific security risk: prompt injection, agentic permissions and data handling rules for what may go into which tool.
Ways of Working
- Operating with autonomy and minimal supervision, and getting things done.
- Setting technical direction for colleagues without formal authority.
- Working effectively in English (we're a multi-cultural international company).
We understand you might not tick every box on this list. If you're passionate, eager to learn, and ready to contribute your unique strengths, and the role excites you, please apply anyway! We're more interested in your potential and approach than in a perfect match of qualifications.
We're building an inclusive workplace where every voice is heard and every idea respected. We actively encourage applications from all backgrounds, especially those underrepresented in tech. A diverse team makes us stronger.
At Atheneum, we believe exceptional tech talent deserves exceptional rewards. Join our growing team in Portugal and enjoy a benefits package designed to support your performance, growth, and quality of life.
All benefits are fully compliant with Portuguese labour laws and exceed standard market offerings for the tech sector.
Join over 400 professionals powering the future of insights. At Atheneum, your skills meet global impact, and your career meets lifestyle.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search