About The Role
You work in the Security Operations Centre on a rotating shift, reviewing alerts raised by the monitoring tools. For each one you check the surrounding activity, decide whether it is a false positive or a genuine incident, and escalate the genuine ones to the response team with the evidence you gathered. It is a common entry point into security: you learn the company's systems quickly because you see every part of them.
What you will do
Triage alerts against the runbook and escalate what does not fit it
Write the timeline of what happened while it is still fresh
Flag detections that fire constantly and are worth tuning
What they ask for
Understands TCP/IP, DNS and HTTP well enough to read a packet capture
Can explain the difference between a scan and an intrusion
Writes clearly under time pressure
Nice to have
Home lab
Any SIEM exposure
Scripting in Python or PowerShell
📌 SOC Analyst (Madrid)
🏢 Rooted
📍 Madrid