Full Time | Valencia, Spain or Remote on EMEA (CET +/-2 hours)
If you like this offer, please send your CV mentioning the job title to:
[email protected]
Location: Valencia, Spain or Remote on EMEA (CET +/-2 hours)
Teleworking option: Yes
Required Technical Skills
SCOPE OF WORK:
- Contribute to the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
- Support the operation, maintenance, optimization, and continuous improvement of security monitoring and threat detection services.
- Participate in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities.
- Contribute to security content management activities, including use case lifecycle management, rule reviews, testing, tuning, and content quality assurance.
- Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities.
- Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and provide recommendations to enhance security monitoring and detection effectiveness.
- Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs, and service performance reports.
- Review, validate, and assess the effectiveness of detections, monitoring configurations, operational processes, and service deliverables,
identifying opportunities for improvement.
- Gather and analyze operational feedback to identify opportunities for tuning, optimization, reduction of false positives, and improvement of overall detection quality.
- Contribute to quality assurance activities, including process reviews, control validation, service quality assessments, and implementation of corrective actions.
- Support the development, review, and maintenance of CSOC procedures, standards, documentation, knowledge base articles, and operational guidance materials.
- Prepare and present technical reports, summaries, findings, and recommendations to internal and external stakeholders.
- Provide other ad hoc support as required
The resource MUST have the following skills and experience:
- A minimum of five (5) years of relevant experience in information technology field, including triage of alerts and supporting security incidents.
- Proven experience on administering a SIEM platform, preferably either Splunk or Microsoft Sentinel SIEM.
- Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs) and being able to autonomously perform technical analysis of security threats and collaborate with Incident Response team
- Deep knowledge of Microsoft Security Tools (e.g. M365,
Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR
- Deep Knowledge of Cloud technologies (e.g. Azure, AWS and GCP)
- Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack
- Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)
- Knowledge of email security, network monitoring, and incident response
- Knowledge of Linux/Mac/Windows
- Expert knowledge of English, both written and spoken, is required
The resource SHOULD have the following skills and experience:
- Experience in building SIEM architectures from initial design to implementation, including designing data ingestion pipelines for diverse log sources across cloud and on-prem environments
- Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)
- Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.)
Soft skills:
- Excellent communication skills
- Customer-facing experience and oral communication skills
- Ability to write documentation & reports
- Creativity/ability to find innovative solutions
- Willingness to learn on the job
- Conflict management & cooperation
Desirable certifications:
- Technical certifications: MCSE, CCNA, Microsoft Azure (e.g., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification
- Relevant industry certifications
Teleworking Option:
- Yes, up to 4 days per week for consultants working from Valencia
On-call requirements:
- Not required
📌 Security Operations Analyst (SIEM) (España)
🏢 United ITs
📍 España