Senior Security Engineer
5 мес. назад
PortugalEuropeSeniorHybrid
incident responsethreat analysissecurity monitoringvulnerability assessment
Senior Security Engineer role within the Detection, Analysis, and Response Team focusing on incident response and threat neutralization.
О компании
- is a leading global marketplace for the luxury fashion industry. The Marketplace connects customers in over 190 countries and territories with items from more than 50 countries and over 1,400 of the world’s best brands, boutiques, and department stores, delivering a truly unique shopping experience and access to the most extensive selection of luxury on a global marketplace. TECHNOLOGY We're on a mission to build end-to-end products and technology that powers the an incredible e-commerce experience for luxury customers everywhere, understanding the motivations and needs of our customers and partners, to designing and testing hypotheses, to creating industry-leading experiences for luxury customers. PORTO Our office is near Porto, in the north of Portugal, an
Обязанности
- Lead the analysis and response to security anomalies, intrusion attempts, and breaches; perform root-cause analysis, containment, and comprehensive post-incident reporting.
- Conduct advanced threat hunting to identify undetected threats using data from endpoints, servers, cloud environments, and network traffic.
- Act as the senior escalation point for the SOC, providing expert analysis on complex security tickets.
- Continuously improve incident response policies, playbooks, and SOC operational processes.
- Analyze and mitigate web-based security events using CDN security solutions (e.g., Akamai, Cloudflare).
- Collaborate effectively with internal engineering and business teams through clear, technical, and executive-level
- communication. Participate in an on-call rotation to respond to urgent security incidents or emerging threats.
Требования
- You have 8+ years in Information Security, with at least 5+ years specifically dedicated to Cyber Security Incident Response (CSIRT) or Digital Forensics.
- Experienced in host-based investigations across Windows, Linux, and various network/security appliances.
- A professional with hands-on experience analyzing security events within AWS, Azure or other major Cloud environments.
- Knowledgeable of analyzing events from EDR, HIPS, DLP, IPS/IDS, and SaaS solutions (e.g., Google Worksapce, O365, Email Security).
- Proficient in managing and analyzing logs from Web Security solutions like Akamai or Cloudflare.
- Skilled in querying SIEM solutions and analyzing "big data" or high-volume logs to identify patterns of compromise.
- Able to automate response workflows and script in Python, Bash, or PowerShell.
- Graduate in Computer Science, Cybersecurity, or equivalent practical experience.
- Experience operating SIEM platforms and developing custom detection use cases.
- Deep understanding of container security and orchestration (Kubernetes, Docker).
- Advanced knowledge of network traffic/packet analysis and network forensics.
- Relevant industry certifications such as GCIH, GCFA, GNFA, CISSP, or OSCP.
Условия
- Health insurance for the whole family, flexible working environment and well-being support and tools
- Extra days off, sabbatical program and days for you to give back for the community
- Training opportunities
- Flexible benefits program
Другое
- is an equal opportunities employer ensuring that all applicants are treated equally and fairly throughout our recruitment process. We are determined that no applicant experiences discrimination on the basis of sex, race, ethnicity, religion or belief, disability, age, gender identity, ancestry, sexual orientation, veteran status, marriage and civil partnership, pregnancy and maternity, or any other basis prohibited by applicable law.
- It has come to our attention that there may be fraudulent activities involving individuals or organizations falsely claiming to represent in order to attract candidates to a SCAM. Please be aware that does not conduct recruitment processes through messaging apps or any unofficial communication channels, other than our official careers website. Additionally, will never ask candidates for any form of payment during the recruitment process.