Point your AI agent at freehire and let it find you a job.

Get the CLI →

Liferay

New

Senior Info Security Analyst

Discussion

About Liferay

Liferay is a uniquely profitable B2B enterprise software company with 1,000+ fiery-eyed employees all across Europe, the Americas, the Middle East, Asia, and Africa. As a renowned provider of enterprise open source technologies, we have been recognized by Gartner for empowering businesses around the world to solve complex digital challenges. Liferay’s all-in-one platform unites Liferay DXP with our cloud platform capabilities, built-in analytics, and commerce functionality, reducing time to market and accelerating innovation. Our customer roster includes global companies such as Airbus, US Bank, Honda, and Desjardins.

But we don’t just make awesome software, we are also fueled by a greater-than-profit vision. By building a vibrant business, making technology useful, and investing in communities, we make it possible for people to reach their full potential to serve others. This commitment extends beyond our product; Liferay donates 10% of our profits to charities around the world. Oh, we’re also self-funded which gives us the freedom to work on whatever we think brings the most value to customers and communities in the long run!

About You and this Role

As Senior SOC Analyst, you are instrumental in safeguarding our organization's digital assets through your leadership in advanced threat detection, incident response, and security posture enhancement initiatives. This role requires you to leverage your deep technical expertise to mentor junior analysts, drive process improvements, and contribute strategically to our evolving security landscape.

Key Responsabilities

  • Proactively analyze, investigate, and respond to complex security alerts, sophisticated threats, and advanced persistent threats (APTs) to identify, contain, and remediate security incidents and breaches with minimal supervision.
  • Use AI to automate incident response, investigation and threat hunting activities

  • Act as a lead investigator and primary escalation point within the team during critical security incidents, coordinating response efforts, and driving effective resolution.

  • Take ownership of Liferay security systems, continuously optimizing their configuration, tuning detection rules, and developing new use cases to enhance threat detection, prevention, and response capabilities. This includes leveraging advanced features and integrating with other security tools.

  • Research, evaluate, and recommend cutting-edge security technologies, tools, and methodologies. Propose and implement strategic improvements to our information security controls, architecture, and overall security posture.

  • Provide expert mentorship, guidance, and training to junior and mid-level SOC analysts, fostering their professional growth and enhancing the overall capabilities of the team. Develop and deliver internal security awareness and technical training sessions.

  • Collaborate extensively with engineering, operations, and other IT teams to embed security best practices throughout the organization, troubleshoot complex security issues, and ensure secure system deployments.

  • Identify opportunities for process automation and efficiency gains within the SOC. Develop and implement playbooks, runbooks, and standard operating procedures (SOPs) to streamline incident response and threat hunting activities.
  • Proactively hunt for emerging threats, vulnerabilities, and malicious activities within our environment, leveraging threat intelligence and advanced analytical techniques.

Key Objectives

  • Within 30 days: Complete a comprehensive deep dive into Liferay's security architecture, existing security controls, and current threat landscape, identifying initial areas for enhancement. Begin contributing to high-priority incident investigations.
  • Within 60 days: Take ownership of the development and refinement of at least two critical security detection use cases within our SIEM/security systems. Lead a complex security alert triage process independently, demonstrating advanced analytical capabilities.
  • Within 90 days: Lead and successfully resolve a significant security incident, demonstrating strong incident management and communication skills. Propose and begin implementing a key process improvement or automation initiative within the SOC.

Required Qualifications

  • Experience working in a Security Operations Center (SOC) or a similar information security role with a strong focus on incident detection and response.
  • Deep expertise in IT networking protocols (TCP/IP, DNS, HTTP/S, etc.), web applications, operating systems (Linux/Windows), and cloud environments.

  • Proven experience with SIEM platforms (e.g., Splunk, Elastic, Sentinel) including advanced query languages, correlation rule creation, and dashboard development.

  • Expert-level understanding of common attack vectors, attack methodologies (e.g., MITRE ATT&CK), and adversary tactics, techniques, and procedures (TTPs).

  • Demonstrated experience in leading security incident investigations, including analysis of logs, network traffic, endpoints, and other security telemetry.

  • Strong scripting skills (e.g., Python, PowerShell, Bash) for automation, data analysis, and tool development.

  • Excellent communication and interpersonal skills, with the ability to articulate complex security concepts to technical and non-technical audiences.

  • Ability to work independently and collaboratively in a fast-paced, global environment, managing multiple priorities effectively.
  • Fluent in English.


Preferred Qualifications

  • Bachelor’s or Master’s Degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Advanced experience with cloud security principles and technologies, particularly Google Cloud Platform (GCP).

  • Experience with forensic tools and techniques.

  • Familiarity with containerization technologies (e.g., Docker, Kubernetes).

  • Prior experience in a leadership or mentorship role within a security team.
  • Experience with vulnerability management and penetration testing concepts.

Optional BUT Desired Certifications and Field Knowledge

  • Industry-recognized security certifications such as CISSP, GCIH, GCIA, CEH, CompTIA CySA+, or equivalent.

  • Extensive knowledge of information security frameworks and compliance standards (e.g., ISO 27001, NIST CSF, SOC 1/2, GDPR, HIPAA).

  • Experience with Security Orchestration, Automation, and Response (SOAR) platforms.
  • Knowledge of software development lifecycle (SDLC) security and DevOps security practices.

What We Offer

  • Salary package w/ competitive benefits according to qualifications and experience
    Opportunities to take responsibility, grow professionally, and Stay Nerdy
  • A positive and collaborative work culture
  • Working at a leading open-source company

Equal Opportunities Employer - Statement

Liferay is committed to the equal treatment of all candidates, customers and employees and to fostering a culture of dignity at work. Our operating procedure provides for equal opportunities in recruitment and employment with the aim to eliminate discrimination against any job applicant or employee on the basis of race, age, sexual orientation, gender, religion or beliefs, marital or civil partnerships status, family or dependency status, disability, pregnancy and maternity or membership of a traveling community.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available