Overview
Join a global SOC team protecting critical environments from evolving threats. In this hands-on role, you’ll monitor, investigate, and respond to security incidents, collaborating with specialists across regions. You’ll enhance threat detection, triage alerts, and drive improvements in processes and documentation. This position offers exposure to leading security tools and a chance to contribute to client security outcomes in a fast-paced environment. You’ll work with cross-functional teams to stay ahead of threats and shape security practices at scale.
Compensaciones / Beneficios
- remote work option in Spain or elsewhere in Europe
- professional growth and learning opportunities
- multicultural, international team
- private medical insurance
- life insurance
- lunch and transport card as part of adaptable remuneration pack
Responsabilidades
- Monitor, triage, and investigate security alerts across SIEM, EDR, and cloud environments
- Investigate threats and incidents, determining root causes and remediation steps
- Analyze logs from Windows, Linux, databases, apps, web servers, firewalls, and network devices
- Collaborate with Incident Response teams to contain and resolve threats
- Maintain security monitoring tools and improve detection quality while reducing false positives
- Prepare security reports, incident summaries,
and technical findings for clients
- Manage security-related tickets and ensure proper incident documentation
- Contribute to SOC process improvements, documentation, and knowledge bases
- Engage with clients to understand environments and optimize monitoring
- Stay current with emerging threats, technologies, and best practices
Requisitos principales
- 5+ years in IT, Cybersecurity, or Security Operations
- Hands-on SOC experience with alert triage and incident investigation
- Strong knowledge of SIEM and EDR technologies
- Experience with Microsoft Sentinel, Splunk, QRadar, ArcSight, or ELK
- Experience with Microsoft security tools (Defender for Endpoint, 365, Sentinel, Azure Security, XDR)
- Solid understanding of Azure, AWS, and/or GCP
- Experience with at least one EDR (e.g., Defender for Endpoint, CrowdStrike)
- Strong networking knowledge and TCP/IP
- Proficient in analyzing security logs in Windows and Linux
- Knowledge of email security, network monitoring, and incident response
- Experience managing and processing security tickets
- Excellent written and spoken English
- proactive and collaborative mindset
- strong communication
- team-oriented
- SIEM
- EDR
- Microsoft Defender for Endpoint
📌 Senior Cybersecurity Analyst - (Cyber Defense Operations) - málaga
🏢 Talan
📍 Málaga