L2 SOC Analyst

Integrity360
Madrid, Spain
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Security Cyber Security Security Information and Event Management Mitre Att&ck Cybercrime Drilldown Microsoft Sentinel ArcSight Event Correlation Splunk

Job description

As a L2 SOC Analyst, you will act as a core investigator responsible for deep-dive analysis, incident ownership, and advanced threat handling. You will mentor L1 SOC analysts within the team. This role is part of a dedicated SOC team , providing analysts with the opportunity to operate within a highly mature security environment, gain exposure to advanced technologies and complex threat scenarios, and develop deep domain expertise in financial services security operations. Primary Duties/Responsibilities include: Lead investigation of confirmed and high-risk security incidents Perform deep-dive analysis using: Microsoft Sentinel Microsoft Defender Suite Trellix Zscaler Apply threat intelligence and attacker TTP analysis using: MITRE ATT&CK Cyber Kill Chain NIST IR Lifecycle Produce high-quality incident reports with actionable recommendations Coordinate containment and remediation actions with engineering, infrastructure, and client teams Provide technical guidance and mentorship to Tier 1 analysts Participate in continuous improvement of SOC processes, playbooks, and detection quality Maintain exceptional communication with client stakeholders during active incidents Perform ad-hoc analysis of varied logs, identifying anomalies in customer environments. Desired Skills

Requirements

Minimum 1 year experience in a SOC Tier 1 or security analyst role Advanced investigative and analytical capability Strong understanding of modern attack techniques, threat actors, and detection methodologies Proven experience with SIEM, EDR/XDR, identity, email and cloud security tooling Excellent technical documentation and communication skills Ability to manage multiple complex incidents simultaneously Ability to perform event correlation, host/ network threat analysis. Ability to manage multiple incidents and make effective decisions under high pressure environment. Certifications/Qualifications (preferred but not required) Security industry certifications: SEC+, CYSA+, Net+, SC-200,AZ-500,AZ-900,Splunk Power user A working knowledge of Intrusion Prevention System (IPS), SIEM, SOAR & DLP is a nice to have. Experience working with threat hunting tools is nice to have.

About the company

Integrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres (SOCs)-including locations in Dublin, Sofia, Stockholm, Madrid, Rome and Cape Town-we support more than 2,500 clients across a wide range of industries. Over 80% of our team are technical experts, focused on helping clients proactively identify, protect, detect and respond to threats in an ever-evolving cyber landscape. Our security-first approach positions cyber resilience as a business enabler, empowering organisations to operate with confidence. At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you’re ready to take your cyber security career to the next level, we’d love to hear from you. Job Role / Responsibilities

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 Ā· LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa Ā· LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler Ā· LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 Ā· LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 Ā· WWC Europe 2026

Videos

See all

Related articles

See all