04 oct
|
United ITs
|
Valencia
04 oct
United ITs
Valencia
Full Time | Valencia, Spain or Remote on EMEA (CET +/-2 hours)Location: Valencia, Spain or Remote on EMEA (CET +/-2 hours)Teleworking option: YesRequired Technical SkillsSCOPE OF WORK:- Contribute to the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.- Support the operation, maintenance, optimization, and continuous improvement of security monitoring and threat detection services.- Participate in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities.- Contribute to security content management activities, including use case lifecycle management, rule reviews, testing, tuning, and content quality assurance.- Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities.- Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and provide recommendations to enhance security monitoring and detection effectiveness.- Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs, and service performance reports.- Review, validate, and assess the effectiveness of detections, monitoring configurations, operational processes, and service deliverables, identifying opportunities for improvement.- Gather and analyze operational feedback to identify opportunities for tuning, optimization, reduction of false positives, and improvement of overall detection quality.- Contribute to quality assurance activities, including process reviews, control validation, service quality assessments, and implementation of corrective actions.- Support the development, review, and maintenance of CSOC procedures, standards, documentation, knowledge base articles, and operational guidance materials.- Prepare and present technical reports, summaries, findings,
and recommendations to internal and external stakeholders.- Provide other ad hoc support as requiredThe resource MUST have the following skills and experience:- A minimum of five (5) years of relevant experience in information technology field, including triage of alerts and supporting security incidents.- Proven experience on administering a SIEM platform, preferably either Splunk or Microsoft Sentinel SIEM.- Proven experience with the usual toolbox available in a SOC (e.G., SIEMs, EDRs) and being able to autonomously perform technical analysis of security threats and collaborate with Incident Response team- Deep knowledge of Microsoft Security Tools (e.G. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR- Deep Knowledge of Cloud technologies (e.G. Azure, AWS and GCP)- Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack- Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)- Knowledge of email security, network monitoring, and incident response- Knowledge of Linux/Mac/Windows- Expert knowledge of English, both written and spoken, is requiredThe resource SHOULD have the following skills and experience:- Experience in building SIEM architectures from initial design to implementation, including designing data ingestion pipelines for diverse log sources across cloud and on-prem environments- Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)- Knowledge of at least one general-purpose or shell scripting language (e.G. Ruby, Bash, PowerShell, Python, etc.)- Excellent communication skills- Customer-facing experience and oral communication skills- Ability to write documentation & reports- Creativity/ability to find innovative solutions- Willingness to learn on the job- Conflict management & cooperationDesirable certifications:- Technical certifications: MCSE, CCNA, Microsoft Azure (e.G., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification- Relevant industry certificationsTeleworking Option:- Yes, up to 4 days per week for consultants working from Valencia#J-18808-Ljbffr
📌 Security Operations Analyst (Valencia)
🏢 United ITs
📍 Valencia