10 ago
|
Six Group
|
Madrid
Remoto: Trabajo híbrido
Experteer Overview In this role, you will strengthen SIX’s security posture as part of the SOC, detecting, investigating, and responding to cyber threats across diverse environments. You will craft and tune detection rules, lead incident containment, and drive automation and playbook improvements. You’ll perform proactive threat hunting using MITRE ATTu0026amp;CK and mentor junior analysts. This position offers hybrid work and a chance to shape security at a major market operator.Compensaciones / Ventajas• Develop, tune, and maintain threat detections and SIEM use cases across endpoint, network, identity, cloud, mail, and M365 environments• Investigate complex security incidents, lead threat analysis, and coordinate containment and remediation activities• Design and improve detection content, SOC automation, SOAR workflows,
and incident response playbooks• Conduct proactive threat hunting using threat intelligence and the MITRE ATTu0026CK framework• Identify detection gaps and continuously enhance SOC capabilities and security posture• Mentor junior analysts and contribute to SOC process improvements and knowledge sharingResponsabilidades• 5+ years of experience in SOC operations, detection engineering, threat hunting, and incident response• Hands-on experience with SIEM, EDR, and SOAR platforms (preferably Sentinel, Elastic, Defender for Endpoint, and Cortex XSOAR)• Strong background in detection rule development, security investigations, and threat hunting across multiple telemetry sources• Experience with scripting, automation, APIs, and tools such as Python, GitLab, Azure DevOps, and CI/CD practices• Knowledge of security query languages and frameworks, including MITRE ATTu0026CK• Strong analytical, communication, collaboration, and mentoring skillsRequisitos principales• remote/hybrid work up to 40%• flexible work models• personal development• extensive learning opportunities• agile working methods
📌 Security Incident Responder (Madrid)
🏢 Six Group
📍 Madrid