
Security Operations Center Engineer
- Lisboa
- Permanente
- Horário completo
- Monitor and investigate the alerts to identify attacks
- Work with Engineering and Operations teams to mitigate attacks, suggest steps to mitigate, and apply the appropriate mitigation, when applicable
- Work with Engineering and Product teams to improve the products and tools
- Communicate with customers via chat, email, and phone
- Review the latest alerts to determine relevancy and urgency. Create new tracking tickets for alerts that signal an incident and require review or escalation
- Configure / Manager security monitoring rules and contribute to tool improvements
- Compare traffic signatures and attributes including IP addresses, cookie variations, HTTP headers, and JavaScript footprints to determine what is good traffic and what is malicious
- DDoS mitigation for OSI layers 3,4, & 7: filter malicious traffic using Cloudflare tools like Magic Transit, Network Firewall, WAF, IP reputation lists, packet inspection, blacklisting, whitelisting, and/or rate limiting.
- Modern internet protocols like UDP, TCP, etc.
- Advanced understanding of iptables
- Analysis of traffic for attack anomaly detection and creation of mitigation rules
- Experience in handling attack mitigation and thorough knowledge of various attacks (L3/4 and L7)
- Knowledge of Cloudflare Security Products & Features
- Technical Support experience
- Good communication skills with high-value VIP customers under attack
- Computer Networking fundamentals
- Command line / Bash shell
- Sysadmin skills (Linux/Mac/Windows) & Programming skills (Python, Ruby, PHP, C, C#, Java, Perl, Git etc.)
- Security skills and certifications: CISSP, GCIA GCIH, GCFA, GCFE, etc.
- Calm under pressure