Cybersecurity Engineer Tier 2
About this role
- Act as an L2 SOC Analyst, ensuring in-depth analysis and validation of alerts escalated by Tier 1.
- Perform fine-tuning and optimization of detection rules in Microsoft Sentinel, Microsoft Defender, and other SIEM platforms, focusing on reducing false positives and improving detection quality.
- Conduct root cause analysis of security incidents, identifying attack vectors, impact, and corrective measures.
- Support incident response and DFIR activities, including initial forensic analysis, event correlation, and evidence collection.
- Contribute to threat hunting, behavioral analysis, and advanced threat detection initiatives.
- Identify visibility gaps, logging issues, or excessive noise, and propose technical improvements.
- Support the integration and validation of new log sources and technologies within the SOC.
- Document incidents, technical analyses, and lessons learned, contributing to both technical and operational reports.
- Collaborate with Tier 1 and Tier 3 analysts, promoting best practices and continuous process improvement within the SOC.
- Tune and optimize detection rules (SIEM, EDR/XDR).
- Identify and resolve visibility gaps, noise, or false positives.
- Support onboarding of new log sources and technologies into the SOC.
- Produce technical and executive reports for clients and internal stakeholders.
- Promote best practices, mentor analysts, and support team growth.
- Solid SOC experience (minimum 2–4 years), including incident analysis.
- Hands-on experience with Microsoft Sentinel, Microsoft Defender, and/or other SIEM/EDR/XDR tools.
- Strong technical analysis and incident investigation skills.
- Knowledge of MITRE ATT&CK, incident response (IR) concepts, and DFIR fundamentals.
- Strong communication skills, with the ability to prioritize and collaborate effectively in an operational environment.
- Previous experience in detection fine-tuning and continuous improvement of SIEM rules.
- Experience in Digital Forensics & Incident Response (DFIR).
- Security certifications (e.g., SC-200, GCED, GCIH, GCIA, CySA+, Security+).
- Experience with Microsoft environments and cloud platforms (Azure).
- Regular professional development;
- Certification paths resources;
- Regular teambuilding programs;
- Friendly workplace.
Company at a glance
Claranet Portugal is the Portuguese market leader in Information Technologies and a specialist in Cloud, Workplace, Applications, Data & AI and Security solutions and managed services.
Founded in 1996, Claranet Portugal has evolved from an innovative and pioneering Internet Service Provider to an independent Managed Services Provider, with around 1,000 employees operating from two offices (Lisbon and Porto) and two datacentres.
More than 2,200 business customers trust Claranet Portugal to modernise, design, implement and operate their applications, critical infrastructures and data securely, 24x7. It works closely with the world's most influential technology companies, creating innovative services with the best solutions and tools provided by its Strategic Partners.
More information at claranet.com/pt
Top Benefits
- Professional Development
- Certification Path Resources
- Teambuilding Programs
- Friendly Workplace
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?