Description
Summary:
This role involves monitoring, investigating, and responding to cloud-native security threats within enterprise environments, focusing on Cloud Security Operations and incident response.
Highlights:
1. Focus on cloud-native security threats and incident response
2. Utilize Sysdig CNAPP for Kubernetes runtime security monitoring
3. Collaborate to enhance cloud-native security operations
Accenture CyberSecurity helps organizations prepare, protect, detect, respond and recover across all aspects of the security lifecycle. Cybersecurity challenges are different for every business and industry. Leveraging our global resources and advanced technologies, we create integrated, end‑to‑end solutions tailored to our clients’ needs across their entire value chain, helping them build cyber resilience and grow with confidence.
We are seeking a highly qualified professional to join our team as a **Cloud Security Operations Analyst**. As an essential part of our Security Transformation team, you will be responsible for monitoring, investigating, and responding to cloud\-native security threats across enterprise environments. We are looking for a professional with strong expertise in Cloud Security Operations, Kubernetes security, and incident response, with hands\-on experience in Sysdig CNAPP and cloud\-native technologies.
**Qualifications**
* Minimum of 3 years of experience in **Security Operations, Cloud Security, or SOC** environments
* Hands\-on experience with **Sysdig CNAPP / Sysdig Secure** for security monitoring, alert triage, and incident investigation
* Strong understanding of **Kubernetes, containers, and cloud\-native security concepts**
* Experience with vulnerability management, incident response, and remediation processes
* Knowledge of **Next\-Generation Firewalls (NGFWs), Web Application Firewalls (WAFs), and security monitoring tools**
* Experience working with **incident management and ticketing systems**
* Strong analytical, troubleshooting, and problem\-solving skills
* Experience operating in production environments with critical business services
* Experience with scripting and automation using **Python, Bash, or Terraform**
* **Fluent in English (C1 or above)**, with excellent written and verbal communication skills
**Responsibilities**
* Monitor Kubernetes runtime security across enterprise containerized environments using Sysdig CNAPP
* Investigate, triage, and respond to security alerts affecting containers, pods, and namespaces
* Analyze and optimize runtime detection rules to improve alert quality and reduce false positives
* Escalate security incidents to Application, Platform, and Infrastructure teams, providing remediation guidance and technical recommendations
* Monitor NGFW and WAF security events and support incident response activities
* Identify, analyze, and report security policy violations, misconfigurations, and configuration drift
* Coordinate remediation efforts to ensure timely resolution of identified security risks
* Manage security incidents throughout the full lifecycle, from detection to remediation and closure
* Produce operational reports, security metrics, and activity summaries for internal stakeholders
* Maintain runbooks, technical documentation, and operational procedures
* Identify opportunities for automation and future auto\-remediation capabilities
* Collaborate with Security, Platform, and Infrastructure teams to enhance cloud\-native security operations and runtime protection
* Participate in on\-call support rotations and respond to critical production security incidents
**Nice to Have**
* Google Cloud Associate Cloud Engineer certification
* Kubernetes certifications such as KCNA, CKA, or CKS
* Sysdig Certified Security Analyst certification
**Additional Information**
**Location:** Porto (Hybrid)
**On\-Call Requirement:** Participation in an on\-call rotation is required to support critical security incidents outside business hours
**Travel:** Flexibility for occasional travel across Europe for project deliveries and client meetings is required.