27 sep
|
Talan
|
Valencia
Overview
In this role you will join a global Security Operations Centre to protect critical environments and support international clients against evolving threats. You will work hands-on with a cross‑border team to monitor, detect, investigate and respond to security incidents, improving threat detection and incident handling. You’ll engage with clients to understand their environments and tailor monitoring, reporting and remediation. This role offers meaningful impact in a fast-paced, technologically diverse setting.
Compensaciones / Beneficios
- remote work capability
- professional growth opportunities
- multicultural international team
- private medical insurance
- life insurance
- lunch and transport card
Responsabilidades
- Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft Security and cloud environments
- Investigate threats and incidents, determine root causes and remediation actions
- Analyze logs from Windows, Linux, databases, applications, web servers, firewalls and network systems
- Collaborate with Incident Response teams to contain and resolve threats
- Use and maintain security monitoring/detection tools to improve detection and reduce false positives
- Prepare security reports, incident summaries and technical findings for clients
- Manage security-related tickets and documentation
- Contribute to SOC processes, documentation, and knowledge bases
- Engage with clients to understand environments and optimize monitoring
- Stay updated on threats, technologies and best practices
Requisitos principales
- 5+ years in IT, Cybersecurity or Security Operations
- Hands-on SOC experience with alert triage and incident investigation
- Strong knowledge of SIEM and EDR technologies
- Experience with Microsoft Sentinel, Splunk, QRadar, ArcSight or ELK
- Experience with Microsoft security technologies (Defender for Endpoint, M365, Sentinel, Azure Security and XDR)
- Strong understanding of Azure, AWS and/or GCP
- Experience with at least one EDR (e.g., Defender for Endpoint or CrowdStrike)
- Strong networking knowledge (TCP/IP)
- Excellent experience analyzing logs across Windows and Linux
- Knowledge of email security, network monitoring and incident response
- Experience managing and processing security tickets
- Excellent spoken and written English
- Desirable: Incident Response tier I/II experience
- Desirable: AWS monitoring (IaaS/PaaS/SaaS) experience
- Desirable: Scripting (Python/PowerShell/Bash/Ruby)
- Desirable: Cybersecurity certifications (SC-200, GCIH, CEH, GCFA, GIAC, CCNA, MCSE)
- Desirable: Integral, distributed SOC experience
- Proactive mindset
- Collaborative/team-oriented
- Strong communication and client-facing skills
- SIEM
- EDR
- Microsoft Sentinel
📌 Senior Cybersecurity Analyst - (Cyber Defense Operations) - valència (Valencia)
🏢 Talan
📍 Valencia