SOC Analyst (Lisbon - Hybrid)

Open 33d

We're fast learners, hard workers, natural collaborators... and we Make Modern Happen!

Our ambition is to unlock the potential of our digital world so that organisations everywhere can innovate and thrive securely. We aim to achieve this goal by bringing together the world’s most talented people and the most powerful technologies, combining them to address our customers' challenges and to build something stronger together.

If you share our vision, join us!

Right now, we are looking for a SOC Analyst to integrate our internal team.


Your responsibilities include:

  • Support the internal SOC team in the triage, investigation, and resolution of security alerts
  • Monitor security events and alerts across multiple tools (SIEM, EDR, IDS/IPS, firewalls, etc.)
  • Analyze and investigate alerts to identify potential security incidents or suspicious activity
  • Perform triage and classification of incidents according to defined procedures
  • Execute initial response and containment actions when applicable
  • Escalate incidents to advanced security teams or relevant technical teams as needed
  • Perform log analysis and event correlation using SIEM platforms
  • Document incidents, investigations, and actions in line with SOC processes
  • Contribute to the continuous improvement of detection rules and use cases
  • Support the fine-tuning of security tools to reduce false positives
  • Collaborate with IT and cybersecurity teams on incident investigation and resolution

You must have:

  • Minimum of 3 years of experience in Security Operations (SOC) or security monitoring
  • Advanced English (mandatory)
  • Hands-on experience with SIEM platforms (e.g., Splunk, QRadar, Microsoft Sentinel)
  • Experience analysing security logs and network events
  • Solid understanding of network protocols, operating systems, and IT architecture
  • Familiarity with security tools such as EDR/XDR, IDS/IPS, firewalls, and endpoint protection
  • Knowledge of cybersecurity frameworks (e.g., MITRE ATT&CK, NIST)
  • Experience with security incident management processes

We value:

  • Experience in threat hunting or advanced incident analysis
  • Knowledge of security automation and orchestration tools (SOAR)
  • Experience working with cloud environments (Azure, AWS, or GCP)
  • Relevant cybersecurity certifications (e.g., CompTIA Security+, CySA+, GCIH, SC-200)

We offer:

  • Regular professional development;
  • Health insurance, with family package;
  • Office facilities for meals and snacks;
  • Regular teambuilding programs;
  • Friendly workplace.

Workplace: Lisbon - Hybrid

Claranet, Make modern happen!