Bridge 351

Security Operations Engineer (Full remote)

Bridge 351 Lisbon, Lisbon, Portugal

Software Development · 51-200 employees

4 h ago
Remote Senior (5-10 yrs) Full-time Portugal
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will design and build SecOps tooling, including SIEM and SOAR integrations, to ensure the security and scalability of a cloud-native platform. Additionally, you will lead incident response efforts and develop detection-as-code artifacts to proactively mitigate evolving threats.

What they look for

Security Operations Cloud Security SIEM SOAR EDR Python PowerShell Go Kubernetes Infrastructure-as-code CI/CD Detection Engineering Incident Response Threat Modeling MITRE ATT&CK Telemetry

Requirements

Candidates must have at least 5 years of experience in security operations, cloud security tooling, and scripting languages like Python or Go. Proficiency in infrastructure-as-code, Kubernetes, and established detection engineering frameworks is essential for this role.

Full description

About the Role

We're looking for a Security Operations Engineer to join Information Security Risk and Compliance (ISRC), the team responsible for embedding security and compliance across a cloud-native platform that powers software product development for the energy sector.

The platform is a hybrid-cloud, service-oriented environment giving application teams self-service capabilities across infrastructure, data, delivery, and operations. ISRC ensures this platform — and everything built on it — stays secure, resilient, and trustworthy.

You'll work at the intersection of SecOps tooling, detection engineering, and incident response, building the systems and automation that keep the platform's security operations sharp and scalable.

What You'll Do

SecOps Tooling Engineering

  • Design and build SecOps tooling as part of the broader security tool ecosystem
  • Develop architecture patterns and solution designs for SIEM, SOAR, vulnerability detection & management, EDR, logging pipelines, and user behavior analytics
  • Evaluate and integrate new tools and platforms to strengthen detection, response, and automation
  • Build and maintain scalable data ingestion, correlation, and alerting workflows
  • Automate repetitive security operations tasks — playbooks, scripts, and workflows (e.g., in SOAR tools)
  • Help shape a structured 24x7 security operations capability

Incident Response

  • Provide technical support during incidents, focusing on tooling, data quality, and engineering fixes
  • Improve detection content, correlation rules, dashboards, and data models based on real incident patterns
  • Support rapid instrumentation, log onboarding, and custom tooling during active security events

Detection Engineering

  • Develop, test, and operationalize new detection capabilities based on evolving threats and platform telemetry
  • Create and maintain detection-as-code artifacts (Sigma, YARA, KQL, static analysis rules)
  • Validate detection quality through adversary simulation and purple-teaming
  • Keep rules documented, version-controlled, and validated against production data

What We're Looking For

Must-have:

  • 5+ years of experience in security operations, engineering, and cloud security tooling
  • Hands-on experience with SIEM/SOAR, EDR platforms, log ingestion, and telemetry pipelines
  • Scripting proficiency (Python, PowerShell, or Go)
  • Experience with infrastructure-as-code, CI/CD toolchains, and Kubernetes
  • Familiarity with threat modeling, detection engineering frameworks, TTP matrices, and MITRE ATT&CK
  • Experience creating architectural diagrams, interface specs, and onboarding guides
  • Experience with logging and detection for cloud architectures
  • Fluent English (C1 or above)

Nice-to-have:

  • Experience with Wazuh
  • Familiarity with observability platforms / OpenTelemetry
  • Background as a SOC Analyst (Tier 1–3) or solid understanding of SOC operations
  • Knowledge of security frameworks (BSI, ISO 27001, MITRE ATT&CK, etc.)
  • Experience with GCP or another public cloud provider
  • DFIR / blue team certifications (CySA+, GIAC, GCIH, BTL)
  • Kubernetes security certification (CKS or CNCF-related)

Location: Remote from EU (Travels to Germany foreseen)

Type: Full-time

Sector: Energy