Full Time | Valencia, Spain or Remote (CET, LATAM, or IST time zones)
If you like this offer, please send your CV mentioning the job title to:
[email protected]
Location: Valencia, Spain or remote (EMEA, LATAM, or IST)
Teleworking option: Yes
Required Technical Skills
SCOPE OF WORK:
- Monitor, triage, and investigate alerts across Microsoft security tools, AWS, SIEM platforms, and EDR solutions
- Analyze network and host-based logs (firewalls, NIDS/HIDS, syslog, etc.) to determine appropriate remediation and escalation
- Identify root causes, direct remediation and recovery actions, and support incident response efforts
- Follow structured analytical processes and collaborate with other analysts and teams to ensure effective threat management
- Prepare and present security reports, summaries, and findings to clients
- Contribute to the improvement of CSOC processes and procedures, including quality control procedures, documentation and knowledge base updates
- Gather the necessary information from the client to identify opportunities for whitelist tuning and optimization to reduce false positives and enhance detection quality
- Reviewing feedback and implementing corrective actions to maintain service excellence
- Provide other ad hoc support as required
The resource MUST have the following skills and experience:
- A minimum of five (5) years of relevant experience in information technology field, including triage of alerts and supporting security incidents
- Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs), able to autonomously perform technical analysis of security threats and collaborate with Incident Response team
- Trouble ticket generation and processing experience
- Expert knowledge of Windows, Linux, Database, Application, Web server, etc. log analysis
- Knowledge of Transmission Control Protocol / Internet Protocol (TCP/IP) protocols
- Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR
- Deep knowledge of Cloud technologies (e.g. Azure, AWS and GCP)
- Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack
- Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)
- Knowledge of email security, network monitoring, and incident response
- Knowledge of Linux/Mac/Windows
- Expert knowledge of English, both written and spoken, is required
The resource SHOULD have the following skills and experience:
- Experience on an Incident Response team performing Tier I/II initial incident triage.
- Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)
- Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.)
Soft skills:
- Excellent communication skills
- Customer-facing experience and oral communication skills
- Ability to write documentation & reports
- Creativity/ ability to find innovative solutions
- Willingness to learn on the job
- Conflict management & cooperation
Desirable certifications:
- Technical certifications: MCSE, CCNA, Microsoft Azure (e.g., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification
- Relevant industry certifications
Teleworking Option:
- Yes
On-call requirements:
- Not required
📌 Security Operations Analyst (España)
🏢 United ITs
📍 España