SIEM Content Development Specialist

LISBOA, PortugalPosted Jul 8, 2026
## Join Us At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact. The SIEM Content Development Specialist plays a critical role in advancing the Cyber Security Operations Center’s ability to detect and respond to cybersecurity incidents. This role focuses on designing and developing cutting-edge detection content leveraging a wide array of security technologies and telemetry to identify malicious activity and guide security analysts through effective response playbooks. Working within a threat-led framework, the specialist collaborates across teams to translate threat intelligence into actionable detection logic and response workflows. The position demands strong technical acumen, analytical thinking, and problem-solving capabilities, along with the ability to communicate clearly with peers, leadership, and cross-functional stakeholders. ## What you’ll do * Contribute to continuous improvement initiatives across multiple technologies and telecoms devices by developing and refining content that enhanced threat detection and response capabilities; * Contribute to the development and optimisation of threat detection content, including the tuning of threat and vulnerability management technologies and the continual refinement of SIEM rules and logic to enhance detection accuracy and operational performance; * Lead and contribute to the optimisation and modernisation of SIEM content, supporting the adoption of next-generation SIEM technologies and cloud-native security tools; * Manage the lifecycle of detection content, including development, testing, release, and retirement, using version control and documentation best practices; * Collaborate with DevOps/SecOps teams to integrate security content into broader CI/CD workflows; * Collaborate with the CSOC Manager to support improvements in security operations through effective content contributions; * Support security event analysis by participating in and may drive security event analysis activities to address current cyber threats; * Assist in threat response activities, providing analytical input from a blue team perspective to help identify potential threat group behaviours; * Contribute to the creation of cyber security reports and advisories, ensuring timely and accurate dissemination to key stakeholders; * Participate in residual risk assessments, supporting post-incident analysis and the documentation of operational and technical lessons learned; * Collaborating with data owners and customers on understanding data sources and use cases and successfully translating requirements to actionable content; * Track and report on the effectiveness of deployed content, using metrics and stakeholder feedback to drive improvements. ## Who you are * Bachelor/Master's Degree in related field; 3 years or above related experience; * Minimum of 2-5 years’ experience in SIEM content (rule logic and code) development role; * Minimum of 2 years of SOC analyst experience (Level2 or above) required; * In depth and extensive hands-on experience in security event analysis, create and refine SIEM/EDR rules and deliver efficiency within the SIEM and all other technologies used within the team; * Demonstrate deep understanding of telecoms equipment, protocols, and network architecture to develop accurate and effective SIEM content; * Proven experience working with telecommunications network protocols (e.g. SS7, Diameter, GTP-C); * Deep Knowledge of telecoms protocols and equipment (e.g., Routers, Switches, VoIP systems,IOT,NAS); * Deep knowledge of networking protocols and...

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free