Submeter

Senior SIEM Engineer

Porto

Descrição da posição

You'll work across Microsoft Sentinel and Graylog — a combination that's rare to own end-to-end. Most SIEM roles lock you into one ecosystem; here you'll build detection logic, tune KQL rules, and integrate log sources across both a Microsoft-native and an open-source SIEM stack.


Responsibilities:

  • Design, implement, and maintain security monitoring solutions in enterprise environments.
  • Develop, tune, and optimize detection use cases in Microsoft Sentinel and other SIEM platforms.
  • Design and integrate log sources, ensuring data quality, normalization, and operational reliability.
  • Create, maintain, and improve KQL detection rules, analytics, watchlists, and threat-hunting queries.
  • Automate security operations using PowerShell, Bash, Python, Ansible, and other scripting technologies.
  • Implement and manage SIEM infrastructure components, including Graylog, Logstash, Syslog-ng, Docker/Podman, and related services.
  • Perform security engineering activities to improve monitoring coverage and detection capabilities.
  • Investigate and improve security telemetry, reducing false positives and increasing detection accuracy.
  • Collaborate with infrastructure, network, and security teams to integrate new technologies into the monitoring ecosystem.
  • Develop technical documentation, implementation guides, and operational procedures.
  • Support vulnerability management initiatives, improving visibility and security monitoring.
  • Ensure security monitoring solutions follow industry best practices and operational standards.

Requirements

Requirements:
  • Proven experience administering and engineering Microsoft Sentinel environments.
  • Extensive experience creating and optimizing KQL queries for detection engineering.
  • Solid experience with SIEM technologies, such as Microsoft Sentinel and Graylog.
  • Practical knowledge of log collection technologies, including Syslog-ng, Logstash, NXLog, Windows Event Forwarding (WEF), and Syslog.
  • Experience implementing and maintaining Linux-based security infrastructure.
  • Solid scripting and automation skills using PowerShell, Bash, Python, or Ansible.
  • Familiarity with Docker, Podman, and containerized deployments.
  • English proficiency to communicate effectively with stakeholders, both at the technical and executive level.
Nice to Have:

  • Microsoft certifications, such as SC-200 (Microsoft Security Operations Analyst) or AZ-500 (Azure Security Engineer).
  • Knowledge of threat modeling frameworks and detection methodologies, such as MITRE ATT&CK.
  • Strong analytical reasoning ability for telemetry optimization and noise reduction.

Quer se candidatar?
Cargo
Nome*
Email*
Telefone*
País*
Cidade*
Linkedin
Upload your CV* (máx. 4MB)
Faça upload da sua foto ou video (máx. 4MB)
Submeter