> Markdown version of [/jobs/ext/1431333-soc-analyst](https://www.wearedevelopers.com/jobs/ext/1431333-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst - **Company:** Ey Gds Spain - **Location:** Málaga, Spain - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, Identity and Access Management, Issue Tracking Systems, Networking Basics, Azure Active Directory, Security Information and Event Management, Mitre Att&ck, Servicenow - **Published:** July 25, 2026 - **Apply:** https://www.jobleads.com/es/job/ee8e18635e1787e4d3b5411526d0d2476 ## About the Role * Structured, process-driven working style with high attention to detail * Solid understanding of OS, networking fundamentals, and core security concepts * Ability to prioritize and work reliably under time pressure * Clear written communication for ticket documentation and handovers * Strong customer orientation and teamwork in a distributed SOC environment * Fluent German (client-facing) and professional working proficiency in English Curiosity on new technologies and approaches and readiness to constantly develop and reinvent the way we work To qualify for the role, you must have * First practical experience in SOC operations, IT security monitoring, or incident triage * Hands-on exposure to SIEM and/or EDR tooling and basic log analysisExperience with ticketing systems and disciplined documentation practices * Willingness to work in a shift-based environment (depending on account model) * German (fluent) and English (professional working proficiency) Ideally, you'll also have * Familiarity with structured investigation frameworks (e.g., MITRE ATT&CK) * Basic understanding of cloud and identity security (e.g., Azure AD / Entra ID, M365) * Experience in regulated or critical environments (public sector, healthcare, infrastructure), We are looking for reliable SOC professionals who work consistently within defined processes, communicate clearly, and escalating responsibly. You combine technical curiosity with disciplined execution and contribute to stable, high-quality security operations. ## Description As a SOC Analyst at EY GDS Spain, you are the first line of defense in a 24/7 Security Operations Center supporting German-speaking clients You monitor and triage security alerts, ensure consistent handling according to defined procedures, and document actions in an audit-ready manner. You work in an international delivery setup while communicating clearly with German-speaking stakeholders and ensuring disciplined escalations. As a member of our team in the EY GDS Spain office in Malaga, you'll have a chance to extend your knowledge & experience by working on interesting projects with the newest technologies and approaches. You'll support clients in choosing the most suitable business solution and take part in digital transformation., * Monitor and triage security alerts across security platforms (e.g., SIEM, EDR/XDR, email security) * Perform initial validation of alerts: check context, relevance, and basic indicators of compromise * Conduct first-level analysis: verify entities (user, host, IP, timeframe), review key logs, perform plausibility checks * Classify outcomes (security incident, false positive, operational event) according to SOPs * Create, update, and maintain incident tickets in a ticketing system (e.g., ServiceNow) with clear documentation * Escalate suspicious, unclear, or complex cases to Level 2 with structured handover notes * Support shift handovers and ensure continuity of investigations through high-quality documentation ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [Data Analyst Salary Germany](https://www.wearedevelopers.com/magazine/277-data-analyst-salary-germany) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)