join

our team.

cyber defense engineer - 12556

Full Time
Hybrid

Portugal

Posted within last 24 Hours

Role Title: Cyber Defense Engineer – Global Security Operations Center (SOC)

Location: Portugal

Role Summary

We are hiring a Cyber Defense Engineer to join Randstad’s Global Security Operations Center (SOC) to investigate complex tier-2/3 security threats, optimize detection capabilities, and safeguard our global digital infrastructure. Operating within a 24/7 "Follow-the-Sun" model, this role handles escalated incidents following initial triage by our external partner, while actively contributing to threat intelligence, vulnerability management, and threat modeling programs.

What You Will Achieve 

What is the core focus of this role?

You will serve as an escalation point for complex security alerts across Randstad’s global footprint. Because initial triage and repetitive monitoring tasks are strategically outsourced, your time will be spent on deep-dive incident investigations, advanced threat hunting, and proactive security enhancements.

What are the primary responsibilities?

  • Advanced Incident Investigation: Conduct end-to-end analysis of complex security alerts utilizing enterprise-grade SIEM, EDR, and SOAR platforms.
  • Detection & Threat Modeling: Collaborate with the Continuous Improvement Lead to design, test, and deploy new threat detection rules aligned with the MITRE ATT&CK framework.
  • Operational Integration: Partner with local IT, Information Security Officers (ISOs), and CSIRT teams during critical security incidents to ensure swift threat containment.
  • Cross-Functional Support: Provide expert support to Vulnerability Management and Threat Intelligence leads during available operational bandwidth.

Role Differentiation 

Important Note: Advanced Analysis & Engineering Role

This is an Escalation & Engineering Role, NOT an entry-level tier-1 alert monitoring position. Tier-1 triage and routine filtering are handled by an external partner, allowing you to focus strictly on complex threat analysis, play-book engineering, and continuous detection improvements.

What You Need to Succeed

Technical Qualifications:

  • Strong understanding of cybersecurity principles, modern threat landscapes, and attack vectors.
  • Demonstrated hands-on experience using industry-leading SIEM and EDR tools for security event analysis.
  • Basic understanding of network protocols, traffic analysis, and the MITRE ATT&CK framework.
  • Professional certifications such as CISSP (or equivalent) are considered a strong plus.
  • Basic scripting skills (e.g., Python) are advantageous for automation and detection engineering.

Core Competencies:

  • Analytical Problem Solving: Ability to dissect complex security events, evaluate risk under pressure, and drive incidents to resolution.
  • Communication: Ability to write concise technical reports and communicate clearly with both technical teams and business stakeholders in English.
  • Mindset: Self-starting, pragmatic, and comfortable operating in an international matrix organization.

apply today to join the team:

Reach out to our recruitment business partner, for the full job spec and a confidential discussion.

Company Description:

Randstad is the world’s leading talent company and a partner of choice to clients. We are committed to providing equitable opportunities to people from all backgrounds and help them remain relevant in the rapidly changing world of work. We have a deep understanding of the labor market and help our clients to create the high-quality, diverse and agile workforces they need to succeed. Randstad was founded in 1960 and is headquartered in Diemen, the Netherlands.