Senior SIEM Engineer
About this role
- Design, implement, and maintain security monitoring solutions across enterprise environments.
- Develop, tune, and optimize detection use cases within Microsoft Sentinel and other SIEM platforms.
- Engineer and onboard log sources, ensuring data quality, normalization, and operational reliability.
- Create, maintain, and improve KQL detection rules, analytics, watchlists, and threat hunting queries.
- Automate security operations using PowerShell, Bash, Python, Ansible, and other scripting technologies.
- Deploy and manage SIEM infrastructure components, including Graylog, Logstash, Syslog-ng, Docker/Podman, and related services.
- Perform security engineering activities to enhance monitoring coverage and detection capabilities.
- Investigate and improve security telemetry, reducing false positives while increasing detection accuracy.
- Collaborate with infrastructure, networking, and security teams to integrate new technologies into the monitoring ecosystem.
- Develop technical documentation, implementation guides, and operational procedures.
- Support vulnerability management initiatives by improving visibility and security monitoring.
- Ensure security monitoring solutions follow industry best practices and operational standards.
- Proven experience administering and engineering Microsoft Sentinel environments.
- Strong experience writing and optimizing KQL queries for detection engineering.
- Solid experience with SIEM technologies such as Microsoft Sentinel and Graylog.
- Hands-on knowledge of log collection technologies including Syslog-ng, Logstash, NXLog, Windows Event Forwarding (WEF), and Syslog.
- Experience deploying and maintaining Linux-based security infrastructure.
- Strong scripting and automation skills using PowerShell, Bash, Python, or Ansible.
- Familiarity with Docker, Podman, and containerized deployments.
- Proficiency in English to communicate effectively with technical and executive stakeholders.
- Microsoft certifications such as SC-200 (Microsoft Security Operations Analyst) or AZ-500 (Azure Security Engineer).
- Knowledge of threat modeling frameworks and detection methodologies like MITRE ATT&CK.
- Strong analytical thinking for telemetry optimization and noise reduction.
- Excellent communication skills to convey complex technical concepts to multi-disciplinary teams.
- A proactive approach to continuous learning and adapting to cloud security tools.
- Regular professional development;
- Certification paths resources;
- Regular teambuilding programs;
- Friendly workplace.
Claranet: Make Modern Happen!
Company at a glance
Claranet Portugal is the Portuguese market leader in Information Technologies and a specialist in Cloud, Workplace, Applications, Data & AI and Security solutions and managed services.
Founded in 1996, Claranet Portugal has evolved from an innovative and pioneering Internet Service Provider to an independent Managed Services Provider, with around 1,000 employees operating from two offices (Lisbon and Porto) and two datacentres.
More than 2,200 business customers trust Claranet Portugal to modernise, design, implement and operate their applications, critical infrastructures and data securely, 24x7. It works closely with the world's most influential technology companies, creating innovative services with the best solutions and tools provided by its Strategic Partners.
More information at claranet.com/pt
Top Benefits
- Regular professional development
- Certification paths resources
- Regular teambuilding programs
- Friendly workplace
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?