Submit
Senior SIEM Engineer
Porto
Job description
You'll work across Microsoft Sentinel and Graylog — a combination that's rare to own end-to-end. Most SIEM roles lock you into one ecosystem; here you'll build detection logic, tune KQL rules, and integrate log sources across both a Microsoft-native and an open-source SIEM stack.
Responsibilities:
- Design, implement, and maintain security monitoring solutions in enterprise environments.
- Develop, tune, and optimize detection use cases in Microsoft Sentinel and other SIEM platforms.
- Design and integrate log sources, ensuring data quality, normalization, and operational reliability.
- Create, maintain, and improve KQL detection rules, analytics, watchlists, and threat-hunting queries.
- Automate security operations using PowerShell, Bash, Python, Ansible, and other scripting technologies.
- Implement and manage SIEM infrastructure components, including Graylog, Logstash, Syslog-ng, Docker/Podman, and related services.
- Perform security engineering activities to improve monitoring coverage and detection capabilities.
- Investigate and improve security telemetry, reducing false positives and increasing detection accuracy.
- Collaborate with infrastructure, network, and security teams to integrate new technologies into the monitoring ecosystem.
- Develop technical documentation, implementation guides, and operational procedures.
- Support vulnerability management initiatives, improving visibility and security monitoring.
- Ensure security monitoring solutions follow industry best practices and operational standards.
Requirements
Requirements:
- Proven experience administering and engineering Microsoft Sentinel environments.
- Extensive experience creating and optimizing KQL queries for detection engineering.
- Solid experience with SIEM technologies, such as Microsoft Sentinel and Graylog.
- Practical knowledge of log collection technologies, including Syslog-ng, Logstash, NXLog, Windows Event Forwarding (WEF), and Syslog.
- Experience implementing and maintaining Linux-based security infrastructure.
- Solid scripting and automation skills using PowerShell, Bash, Python, or Ansible.
- Familiarity with Docker, Podman, and containerized deployments.
- English proficiency to communicate effectively with stakeholders, both at the technical and executive level.
Nice to Have:
- Microsoft certifications, such as SC-200 (Microsoft Security Operations Analyst) or AZ-500 (Azure Security Engineer).
- Knowledge of threat modeling frameworks and detection methodologies, such as MITRE ATT&CK.
- Strong analytical reasoning ability for telemetry optimization and noise reduction.
Want to apply?
Position
Name*
Email*
Phone number*
Country*
City*
Linkedin
Faça upload do seu CV*
(max. 4MB)
Upload your photo or video
(max. 4MB)


