747,188open jobs
44,848companies
107,947added this week
Browse all
Location
Hybrid (Lisbon, Portugal)
Seniority
Junior · 2+ years exp

Confirmed on the employer's own hiring board on Sep 25, 2026. First seen by Alion on Sep 21, 2026.

Overview
Company
Impact
Profile match
Vodacom Moçambique is a telecommunications operator and mobile financial services provider. The company offers prepaid and postpaid mobile voice and data connectivity, broadband services, enterprise IT and telecom solutions, and the M-Pesa mobile money platform for digital payments, transfers, and financial inclusion services. Headquartered in Maputo, Mozambique, the enterprise serves individual consumers, small businesses, and corporate clients across the country.

Join Us

At Vodafone, we’re not just shaping the future of connectivity for our customers - we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.

The SIEM Content Development Specialist plays a critical role in advancing the Cyber Security Operations Center’s ability to detect and respond to cybersecurity incidents. This role focuses on designing and developing cutting-edge detection content leveraging a wide array of security technologies and telemetry to identify malicious activity and guide security analysts through effective response playbooks.

Working within a threat-led framework, the specialist collaborates across teams to translate threat intelligence into actionable detection logic and response workflows. The position demands strong technical acumen, analytical thinking, and problem-solving capabilities, along with the ability to communicate clearly with peers, leadership, and cross-functional stakeholders.

What you’ll do

  • Contribute to continuous improvement initiatives across multiple technologies and telecoms devices by developing and refining content that enhanced threat detection and response capabilities;
  • Contribute to the development and optimisation of threat detection content, including the tuning of threat and vulnerability management technologies and the continual refinement of SIEM rules and logic to enhance detection accuracy and operational performance;
  • Lead and contribute to the optimisation and modernisation of SIEM content, supporting the adoption of next-generation SIEM technologies and cloud-native security tools;
  • Manage the lifecycle of detection content, including development, testing, release, and retirement, using version control and documentation best practices;
  • Collaborate with DevOps/SecOps teams to integrate security content into broader CI/CD workflows; Collaborate with the CSOC Manager to support improvements in security operations through effective content contributions;
  • Support security event analysis by participating in and may drive security event analysis activities to address current cyber threats;
  • Assist in threat response activities, providing analytical input from a blue team perspective to help identify potential threat group behaviours;
  • Contribute to the creation of cyber security reports and advisories, ensuring timely and accurate dissemination to key stakeholders;
  • Participate in residual risk assessments, supporting post-incident analysis and the documentation of operational and technical lessons learned;
  • Collaborating with data owners and customers on understanding data sources and use cases and successfully translating requirements to actionable content;
  • Track and report on the effectiveness of deployed content, using metrics and stakeholder feedback to drive improvements.

Who you are

  • Bachelor/Master's Degree in related field; 3 years or above related experience;
  • Minimum of 2-5 years’ experience in SIEM content (rule logic and code) development role;
  • Minimum of 2 years of SOC analyst experience (Level2 or above) required;
  • In depth and extensive hands-on experience in security event analysis, create and refine SIEM/EDR rules and deliver efficiency within the SIEM and all other technologies used within the team;
  • Demonstrate deep understanding of telecoms equipment, protocols, and network architecture to develop accurate and effective SIEM content;
  • Proven experience working with telecommunications network protocols (e.g. SS7, Diameter, GTP-C);
  • Deep Knowledge of telecoms protocols and equipment (e.g., Routers, Switches, VoIP systems,IOT,NAS);
  • Deep knowledge of networking protocols and addressing schemes, i.e., TCP/IP functions, CIDR blocks, subnets, addressing, communications, etc;
  • Deep knowledge of Windows/Linux operating systems;
  • Exceptional working knowledge of security technologies such as SIEM (ArcSight, Sentinel, QRadar, LogRhythm, Splunk), EDR (Microsoft Defender, FireEye, Tanium), IDS/IPS, firewalls, proxies, web application firewalls, anti-virus, etc;
  • Understanding of cloud and IoT security in telecoms;
  • Comprehensive understanding of Window Security Event logs and Syslog; Excellent familiarity with endpoint/perimeter security attack vectors and detection (blue/purple teaming);
  • Excellent familiarity with standard security frameworks such as MITRE, cyber kill chain and APT campaign strategies;
  • Outstanding knowledge of cloud platforms such as Azure, O365, Google cloud, AWS, Oracle;
  • Experience with modern SIEM platforms, including cloud-native or hybrid solutions;
  • Hands-on experience with CI/CD pipelines and automation tools for security content deployment;
  • Proficiency in version control systems (e.g., Git) for managing SIEM content; Excellent working knowledge of regular expression development; Scripting and programming experience is highly desirable;
  • Kusto or SQL knowledge, including rule/query optimisation;
  • Proven ability to prioritise workload, meet deadlines and utilise time effectively;
  • Good interpersonal and communication skills, works effectively as a team leader and the ability;
  • Experience in security event analytics, for example Elastic, Azure Sentinel or Splunk;
  • Excellent verbal and written communication skills;
  • Highly disciplined and motivated, able to work independently or under direction; Deep understanding of threat actor techniques and tools;
  • Fluency in English.

Not a perfect fit?

Worried that you don’t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you’re excited about this role but your experience doesn’t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.

What's in it for you

  • Hybrid Work Model - Flexible hybrid work model with 8-10 in-office days per month, managed by team leaders;
  • Vodafone Products and Services - Employees get a mobile phone, free communication plan, data card, and various discounts on services and products;
  • Recognition - Recognition programs for innovative, creative, high-potential employees and exemplary behaviors;
  • Health and Well-being - Well-being Program offers nutrition and psychological consultations, webinars, workshops, and discounts on various services and products;
  • Learning - Access to Communities of Practice and a customizable digital training platform with high-quality content (namely Harvard Business Publishing, Skillsoft and Speexx);
  • Local and International Mobility - Internal recruitment with local and international rotation opportunities across departments and roles.

Who we are

We are a leading international Telco, serving millions of customers. At Vodafone, we believe that connectivity is a force for good. If we use it for the things that really matter, it can improve people's lives and the world around us. Through our technology we empower people, connecting everyone regardless of who they are or where they live and we protect the planet, whilst helping our customers do the same.

Belonging at Vodafone isn't a concept; it's lived, breathed, and cultivated through everything we do. You'll be part of a global and diverse community, with many different minds, abilities, backgrounds and cultures. ;We're committed to increase diversity, ensure equal representation, and make Vodafone a place everyone feels safe, valued and included.

If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, please refer to https://careers.vodafone.com/application-adjustments/ for guidance.

Together we can.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
747,188 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Marketing
Similar stack
Same company
Lisbon
≈ $14k – $28k per year (Estimated) • Remote (EAEU) • Contractor • Moscow
Apply
≈ $68k – $142k per year (Estimated) • Remote (Germany) • Full-Time
Apply
≈ $78k – $150k per year (Estimated) • Remote (United States) • Full-Time • 4+ years exp • Bachelor's Degree
Apply
≈ $79k – $199k per year (Estimated) • Hybrid • Bachelor's Degree • New York
Analytics
Microsoft Excel
Apply
≈ $67k – $168k per year (Estimated) • In office • Part-Time • High School Diploma • Birmingham
Apply
SR IS Data Architect 10 hours ago
≈ $54k – $123k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Mexico City
Python
JavaScript
Java
Kotlin
TypeScript
Node JS
Databases
RabbitMQ
ActiveMQ
Apache Kafka
Frontend
Angular
React.js
DevOps
Azure
CI/CD
AWS
Management
Agile
Scrum
Apply
≈ $20k – $51k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Noida
SQL
AI/ML
Copilot
Claude
DevOps
Azure DevOps
Azure
CI/CD
Jenkins
Management
Jira
QA
Selenium
Postman
SoapUI
Apply
≈ $32k – $69k per year (Estimated) • In office • Full-Time • 9+ years exp • Bengaluru
Java
Java
Spring Boot
AI/ML
Copilot
DevOps
CI/CD
AWS
Docker
Kubernetes
Apply
$381k – $762k per year • In office • Full-Time • Tokyo
PHP
TypeScript
Perl
DevOps
AWS CDK
AWS
GitLab
Apply
$220k – $325k per year • Hybrid • Full-Time • 10+ years exp • New York
AI/ML
AI Agents
LLM
DevOps
CI/CD
Apply
≈ $44k – $98k per year (Estimated) • Hybrid • 15+ years exp • Madrid
Apply
Hybrid
Cybersecurity
GDPR
Marketing
Salesforce
Marketo
Apply
≈ $59k – $133k per year (Estimated) • In office • 5+ years exp • Cairo
Management
Asana
Marketing
LinkedIn
Instagram
Apply
Hybrid • Lisbon
Apply
≈ $54k – $127k per year (Estimated) • Hybrid • Master's Degree • Lisbon
Analytics
Microsoft Excel
Management
ITIL
Apply
Hybrid • Full-Time • Lisbon
Management
Service Desk
Apply
≈ $20k – $45k per year (Estimated) • Hybrid • Full-Time • Lisbon
Management
Slack
Marketing
Salesforce
Apply
≈ $22k – $53k per year (Estimated) • Remote (Portugal) • Full-Time • 2+ years exp • Bachelor's Degree • Lisbon
Apply
Hybrid • Full-Time • Bachelor's Degree • Lisbon
Management
Microsoft Office
Apply
Hybrid • Full-Time • 1+ year exp • Lisbon
AI/ML
Aider
Design
Figma
Management
Miro
Agile
Apply
See all jobs
This is one of many
747,188 more open roles from verified company boards, updated every day.