15 sep
|
Tamarind Intelligence
|
Barcelona
15 sep
Tamarind Intelligence
Barcelona
We're Adevinta, a general leader in digital marketplaces. Our household name brands, including Kleinanzeigen and ++mobile.We're all about matchmaking, and our sites help people find whatever they're looking for in their local communities -- whether it's a car, an apartment, a sofa or a new job. Our brands are supported by global Tech Hubs in Barcelona, Amsterdam, Paris and Berlin.
Their goal is to develop common global products and innovation platforms which all of our brands can use. This means using cutting edge technology to create highly scalable, customisable and secure products and components that free up development time and leverage our access to global data. We are looking for an experienced defensive security engineer with hands‐on expertise in incident response and security operations in large enterprise environments.
Comfortable working autonomously across the full incident response lifecycle - preparation, detection, analysis, containment, eradication, recovery and learning - and able to lead or support response efforts under pressure. Should have solid experience operating and enhancing defensive security technologies including EDR, SIEM, DLP, NIDS and threat intelligence solutions. Must be able to develop and refine incident response policies, playbooks, escalation procedures and tabletop exercises, and contribute to post‐mortem analyses that feed back into detection and response improvements.
Skilled at gathering, analysing and operationalising threat intelligence to strengthen detection and prevention Must be aligned with a GitOps and defence‐as‐code approach: managing detection content, security configurations, playbooks and operational tooling as versioned code in Git, with peer reviews, automated testing and repeatable deployments. Good understanding of AWS Cloud technologies, services, security capabilities and controls (SCPs, Security Groups, IAM). Familiar with SDLC and modern tooling and ecosystems such as Kubernetes, GitHub, GitHub Actions, CI/CD pipelines and infrastructure as code.
Experience with security frameworks and methodologies such as MITRE ATT&CK; or NIST. Familiar with Incident Management At Google (IMAG) and Agile methodology. Strong analytical and problem‐solving skills with the ability to synthesise complex data into actionable insights.
Fluent in English. 4+ years in a security engineering, SOC or incident response role. Adevinta's defensive security operates across three tiers: the SOC (MSSP, SCASSI) handles L1 triage, Core Defense provides L2 incident response, and Cloud Defense acts as L3 specialist escalation for cloud and platform‐level investigations. While the SOC is gaining traction into the environment, SIEM coverage and maturity are increasing across marketplaces through the multi‐tenant expansion, and new signals from tools like Wiz are adding scope and depth to the cloud security telemetry flowing into the platform.
Together, these developments are driving a growing volume and complexity of security events that require deep technical investigation at the L3 level.
Cloud
Defense is the team that provides specialist escalation when incidents involve cloud infrastructure, platform‐level systems or require advanced containment and eradication actions. This engineer will strengthen that L3 capability by leading deep investigations into cloud and platform incidents escalated from Core Defense, developing and refining cloud‐specific playbooks and escalation procedures aligned with the priority framework, participating in the on‐call rotation, and contributing to post‐mortem analyses that improve detection and response over time. They will also operationalise threat intelligence by feeding it into the SIEM detection pipeline, and collaborate with Core Defense and SCASSI to ensure escalation paths and coordination channels work effectively across all three tiers.
Participation in our Short‐Term Incentive plan (annual bonus) just make sure you have internet connection! Research suggests that women and individuals from underrepresented groups may self‐select out of opportunities if they don't meet 100% of the job requirements.
📌 Cybersecurity : Security Monitoring Engineer (Barcelona)
🏢 Tamarind Intelligence
📍 Barcelona