Are you ready to join our digital revolution journey? At Aleph, we're not just part of the digital advertising landscape—we're shaping its future. Representing the world's leading platforms, including TikTok, Amazon, Google, and nearly 55 others, we operate in 130+ markets across new and existing geographies.
Our mission is to empower advertisers and brands to unlock the full potential of these platforms' advertising capabilities. By fostering long-lasting partnerships, we create limitless opportunities for people and businesses to advertise effectively at both local and global levels. If you're ambitious, forward-thinking, and eager to thrive in a dynamic, global environment, Aleph is the perfect place to build your career.
We are looking for an experienced and operationally sharp Security Operations & Incident Response Analyst (L3) to join Aleph's global IT Security team. Reporting to the General CISO, you will be the first line of defence when incidents occur and the engine behind the team's threat detection and response capabilities. Serve as the primary point of contact for security incidents escalated from IT Operations, the Security Engineer, and external sources.
Maintain and continuously improve incident response playbooks for the most relevant threat scenarios (ransomware, phishing, account compromise, data breach, insider threat, etc.).
Manage the security incident log and register : track all incidents, document timelines and actions,
and produce trend analysis and reporting for the CISO. Coordinate with external SOC or MDR providers where applicable: review daily reports, validate alert quality, and manage escalation workflows.
Data Breach Management
Lead data breach investigations : scope the breach, gather and preserve evidence, assess PII exposure, and coordinate response with Legal, Privacy, and HR.
Own the vulnerability management programme : schedule and execute periodic vulnerability scans across infrastructure, endpoints, and cloud environments. Identity & Access Management (IAM) ~ 3–5 years in a SOC analyst, incident response, or security operations role, with at least 1–2 years at L3 level is a plus. ~ Experience implementing or managing IAM and PAM solutions ~ Strong hands‐on experience with SIEM platforms (alert triage, rule writing, query development) and EDR/XDR tools. ~ Familiarity with IAM and PAM concepts and platforms (e.CyberArk, BeyondTrust, Azure PIM, or equivalent). ~ Experience with digital forensics and incident response (DFIR) methodologies: evidence collection, log analysis, and timeline reconstruction. ~ Understanding of ISO 27001 incident management controls, NIS2 incident reporting obligations, and PCI DSS requirement 12.10. ~ English: full professional proficiency (C1/C2) — primary working language.
Spanish: professional proficiency is a plus.
📌 Security Operations & Incident Response Analyst (Madrid)
🏢 Aleph
📍 Madrid