Cyber SOC - Senior - EY GDS Spain - Hybrid
Role details
Job location
Tech stack
Job description
· Operational support using SIEM solutions (Splunk, Sentinel), EDR (CrowdStrike, Defender, Carbon Black), and NSM (Fidelis, ExtraHop) for multiple customers
· Specialized in second-level incident validation and more detailed investigation
· Performs incident coordination and communication with the client to ensure effective containment, eradication, and recovery
· SIEM support activities which include ad hoc reporting and basic troubleshooting
· Advise customers on best practices and use cases on how to use this solution to achieve customer end-state requirements
· Provide near real-time analysis, investigating, reporting, remediation, coordinating, and tracking of security-related activities for customer
Requirements
· Excellent knowledge of SIEM technologies such as Splunk, and Azure Sentinel from a Security analyst's point of view
· People and/or Project management skills
· Strong interpersonal and presentation skills
To qualify for the role, you must have
· B2/C1 English language level
· Minimum of 3 years of hands-on experience in SIEM/EDR/NSM solutions
· Knowledge of RegEx, Perl scripting and SQL query language
· Previous exposure to IOT/OT monitoring (Claroty, Nozomi Networks, etc.)
· Understanding of endpoint protection tools, techniques, and platforms such as Carbon Black, Tanium, CrowdStrike, Defender, etc.
· Familiarity with Network monitoring technology platforms such as Fidelis XPS and ExtraHop
*Availability to work on shifts 24x7.
Ideally, you'll also have
· Certifications such as CCSA, CEH, CISSP, GCIH, GIAC
What we look for
We look for highly motivated individuals with excellent problem-solving skills and the ability to adapt in a rapidly changing industry. If you are a confident team player willing to develop your career in a dynamic organization, this is your opportunity!