Cyber Security Services Incident Response Engineer (España)

Cyber Security Services Incident Response Engineer (España)

03 oct
|
Stefanini Emea
|
España

03 oct

Stefanini Emea

España

Stefanini Group is seeking a skilled Cyber Security Services (CSS) Incident Response (IR) Engineer to join our Security Operations Center (SOC), which operates as a Managed Security Service Provider (MSSP).

Por favor, lea detenidamente la siguiente descripción del puesto para asegurarse de que encaja con el perfil antes de enviar su solicitud.

As a CSS IR Engineer, you will manage security incidents, develop incident response processes, and enhance security configurations tailored to client needs. Your expertise will be crucial in reducing false positives and identifying security gaps within the client's IT infrastructure.

Work Schedule: Two rotating 8.5-hour shifts within the 7:00 a.m.-7:00 p.m. CET coverage window.

Job responsibilities:

- Own assigned security alerts, incidents, and escalated tickets, providing technical guidance and resolving investigation or response issues.
- Review and interpret investigations generated by the internal AI tool, determining whether alerts should be closed, investigated further, escalated, or converted into formal cases.
- Lead investigations across endpoint, identity, email, network, cloud, and other available telemetry sources.
- Analyze endpoint and Microsoft Entra ID activity to identify indicators of compromise, suspicious access, malicious execution, persistence, privilege escalation, lateral movement, and other adversary techniques.
- Interpret correlated investigation results from SentinelOne Singularity Data Lake, PowerQuery, Microsoft Entra ID, and other security platforms.
- Analyze patterns across automatically closed and manually reviewed alerts to identify incorrect closures, missed threats, false positives, investigation gaps, and overly aggressive automated actions.
- Propose and document corrected response logic for specific alert types, including enrichment, investigation, containment, escalation, and case creation.
- Execute or coordinate containment, eradication, and recovery activities in accordance with approved procedures and incident-response playbooks.
- Prepare P1 and P2 incident reports and maintain investigation records, including evidence, timelines, root cause, impact, actions taken, lessons learned, and recommended improvements.
- Produce operational reporting covering alert volumes, case status, investigation outcomes, false positives, detection and automation performance, service-level results, tool and log-source health, and MTTR.
- Conduct forensic analysis and support structured threat hunting and proactive detection initiatives based on emerging threats, vulnerabilities, TTPs, and observed attack patterns.
- Contribute to security improvements by maintaining procedures, playbooks, workflows, investigation guides, and technical documentation, and by recommending improvements to detection, monitoring, and response processes.




- Present incident findings and recommendations to security teams and stakeholders; collaborate across teams and time zones.

Role Requirements:

Education:

- Preferred: Bachelor's degree in computer science, Information Technology, Engineering, or a related field.
- Minimum education requirement: High school studies completed with Baccalaureate diploma.
- Excellent English communication skills, both verbal and written, for professional communication and documentation.

Experience:

- Minimum 5 years of experience in cybersecurity operations, including hands‐on experience investigating and responding to security incidents across endpoints, network, cloud, and other technology environments.
- Practical experience reviewing, designing, correcting, or improving security automation, SOAR workflows, detection logic, or automated incident‐response processes. Experience merely using a SOAR platform is not sufficient on its own.
- Demonstrated experience working in a Security Operations Center, General Security Operations Center, Managed Security Service, or similar 24/7 operational environment.

Mandatory Technical Skills:

- Strong understanding of cybersecurity principles, incident response methodologies, structured threat hunting and basic digital forensics.
- Strong knowledge of industry frameworks and best practices, including NIST incident response guidance and structured threat hunting methodologies.
- Strong experience with incident investigation and alert analysis using SIEM, EDR, XDR, NDR, or similar technologies. SentinelOne and PowerQuery experience are desirable but not mandatory.
- Proficiency with Microsoft Entra ID.
- Ability to assess AI‐generated investigation results, review automatically closed alerts and alerts requiring manual review, and determine whether cases should be closed, investigated further, or escalated.
- Strong skill in identifying weaknesses in automated detection and response logic, including incorrect alert closures, missed threats, and overly aggressive actions.
- Ability to translate investigation findings and alert patterns into clear recommendations for improving operational processes, response logic, and decision‐making approaches, including enrichment, containment, escalation, and case creation.
- Ability to develop and maintain standard operating procedures, incident response playbooks, workflows, and technical documentation.





Preferred / Nice‐to‐Have Qualifications:

- Hands‐on certifications in incident response, forensics, threat hunting, or malware analysis - for example GCIH, GCFA, GCDA, GREM, ECIH, CySA+, eCTHP, CDSA, or OSCP. Equivalent practical evidence (published research, open‐source detection contributions) is weighted equally.

Professional Skills:

- Ability to perform effectively during crises, make sound decisions, recommend effective solutions, and manage competing priorities during security incidents.
- Ability to work effectively in a complex global environment involving multiple entities, varying levels of IT maturity, and diverse regulatory requirements.
- Strong communication and collaboration skills, enabling effective interaction with a diverse range of technical and non‐technical stakeholders and internal teams.
- A customer‐focused mindset dedicated to delivering exceptional service.
- A collaborative mindset with an interest in internal operations and process improvement.
- Strong organizational, attention to detail, analytical thinking and a proactive approach to problem‐solving.
- Ability to quickly adapt to changes, new requirements, or sudden shifts in direction.
- A commitment to continuous learning and improvement, staying abreast of industry best practices, emerging technologies, and methodologies.
- Absolute discretion and integrity in handling sensitive customer information and critical infrastructure data.

Diversity & Inclusion

Here at the Stefanini Group, we value plurality and equity, regardless of race, sexual orientation, disability, age, ancestry, religion, gender, and nationality. We understand and encourage the importance of being you!

About us

We are the Stefanini group, a global tech consulting company of Brazilian origin that believes in the power of people to transform businesses through technology.

We are present in over 40 countries and operate with the purpose of co‐creating solutions together with our clients that accelerate results and improve the experience of people and organizations.

Here, we like to say that technology is not the end, but the means: what really matters are the people who drive it all.

Our mindset is AI First, meaning we invest in cutting‐edge technology in everything we do, focusing on results for our clients.

We are a company, a group, that breathes collaboration and offers a dynamic environment where you will learn by doing, grow alongside the team, and have space to contribute with ideas and projects.

More than just talking about digital transformation, we believe in real transformation that starts with people and impacts real businesses. xcskxlj

If you are looking for a place to develop, innovate, and be part of something bigger, the Stefanini Group is your place.

📌 Cyber Security Services Incident Response Engineer (España)
🏢 Stefanini Emea
📍 España

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cyber security services incident response engineer (españa) / españa

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cyber security services incident response engineer (españa) / españa