CareerPlanGet AI match score →

Senior SOC Engineer

Porto, Porto, Portugal💼 Full-time🗓 2026-06-12 → 2026-07-27

Do you want to join one of the largest professional services organizations on the market? Then Deloitte is for you. Here, you'll have the chance to boost your career and strengthen your skills in our technological universe. We're an international Tech Hub and we're looking for the best experts in Cybersecurity to join our centers of excellence and our community. At Deloitte, you will transform the world as we know it and develop unique and innovative solutions in the most varied and complex transformation projects, from Portugal to the world. We're going to strengthen our Cyber area and we're looking for experienced professionals who have a natural aptitude for working as part of a team and in a multi-project environment. You can find out all the roles you'll be fulfilling, according to your profile, so you can take a leap forward in your career! Will you join us? We're waiting for you.

Your day by day and responsibilities

Senior SOC Engineer is responsible for designing, implementing, optimizing, and maintaining the technologies that enable the Security Operations Center to detect, analyze, and respond to threats effectively. This role focuses on SIEM engineering, EDR tuning, SOAR automation, log ingestion, use case development, and platform reliability across cloud and on-prem environments.

SIEM Engineering

Architect, deploy, and maintain SIEM platforms.

Build and optimize data ingestion pipelines (Syslog, API, Event Hubs, Logstash, Agents).

Create detection rules using KQL, SPL, AQL, EQL, Sigma, Analytics Rules.

Implement normalization, parsing, enrichment, and correlation logic.

Ensure log source onboarding, health monitoring, and telemetry completeness.

EDR / XDR Engineering

Administer and optimize EDR Platforms.

Develop custom policies, behavioral detections, and response actions.

Monitor sensor health, coverage, and integration with SIEM/SOAR.

SOAR Automation

Design and maintain playbooks and workflows.

Automate repetitive processes such as enrichment, triage, notifications, and containment.

Integrate SOAR with ITSM tools (ServiceNow, Jira), EDR, firewalls, and threat intel platforms.

Security Engineering & Architecture

Integrate threat intelligence feeds (STIX/TAXII, MISP, Anomali).

Collaborate with threat hunters, SOC analysts, and DFIR teams to develop new detection capabilities.

Maintain documentation, architecture diagrams, and platform standards.

Ensure compliance with logs, retention, and auditing requirements (ISO 27001, SOC 2, NIST).

Operational Support

Troubleshoot log ingestion, detection failures, and platform performance issues.

Support purple team exercises and detection coverage assessments (MITRE ATT&CK mapping).

Participate in on‑call rotation for security platform escalations

Are you the one we are looking for?

Advanced knowledge of network protocols, system architectures (Linux/Windows), and cloud environments (AWS, Azure, GCP)

Deep understanding of log sources, normalization, parsing, and enrichment

Strong experience with

Sourced via linkedin · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on LinkedIn ↗