> Markdown version of [/jobs/ext/1480840-tier-2-soc-analyst](https://www.wearedevelopers.com/jobs/ext/1480840-tier-2-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Tier 2 SOC Analyst - **Company:** Kudelski Security - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Data Analysis, Microsoft Azure, Bash Shell, Cloud Computing Security, Cyber Security, Intrusion Detection Systems, Python (Programming Language), Network Security, Network Monitoring, Windows PowerShell, Security Information and Event Management, Scripting, Google Cloud, Mitre Att&ck, QRadar, Firewalls (Computer Science), Containerization, Information Technology, Process Control Systems, Splunk, SentinelOne Expertise, Service Stack - **Published:** July 29, 2026 - **Apply:** https://www.jobleads.com/es/job/eee044803a44683ffc11fd3e309da60a1 ## About the Role * A team-player willing to iterate on our internal processes to improve the team's efficiency Experience in international/global environment * At ease with solving complex problems * Dynamic, with strong interpersonal and communication skills * Autonomous, self-taught and transparent * Able to handle and prioritize parallel tasks with multiple interfaces You have * Minimum 4 years of hands-on experience in cybersecurity operations, incident response, or threat analysis, bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience and * Proven track record in a SOC and international/global environment * Advanced proficiency with SIEM platforms (Splunk, QRadar, Sentinel, etc.) * Extensive experience with EDR/XDR solutions (CrowdStrike, SentinelOne, Microsoft Defender, etc.) * Deep understanding of network security technologies (firewalls, IDS/IPS, network monitoring) * Strong knowledge of Windows and Linux/Unix operating systems and forensics * Experience with cloud security (AWS, Azure, GCP) and containerization technologies * Familiarity with OT/ICS environments and industrial control systems security * Proficiency in scripting languages (Python, PowerShell, Bash) for automation * Understanding of threat intelligence platforms and MITRE ATT&CK framework * Spanish or any other language ## Description As a Tier 2 SOC Analyst, you will serve as a subject matter expert in our technology stack while optimizing security tools and detection workflows, mentoring junior analysts on complex investigation techniques, and driving continuous improvement initiatives across our multi-client SOC environment.This role demands advance analytical skills to conduct in-depth analysis of escalated security incidents from Tier 1 analysts, performing advanced threat investigations to determine attack vectors, assess impact scope, and develop comprehensive remediation strategies., * General responsibilities + Use AI to support continuous improvement work: refining incident templates, proposing workflow enhancements, and contributing to SOP updates. + Propose enhancement on tools and workflow + Respond in a timely manner (within documented SLA) to support tickets. + Document actions in tickets to effectively communicate information internally and to customers. + Adhere to policies, procedures, and security best practices. + Take responsibility for customer satisfaction and overall success of managed services. + Be available, ready, and able to accept incoming clients calls + Mentor fellow Security Engineers and Security Analysts. * Service improvement + Optimize SIEM rules and detection logic to reduce false positives and improve detection accuracy Support rules factory program in improving the global set of detection + Validate Go-to-Active and Go-to-Prod gates of our new clients to ensure a smooth transition to operation + Continuously improve incident templates in terms of content for the clients and in terms of + automation to best support the operation + Support rollout of new set of rules for our clients + Qualify, analyze, and provide recommendations for new standard data source requests + Support Product teams to build best new services to fit with Operations capabilities (needs, + scalability, efficiency) * Threat Monitoring + Manage escalated cases from T1 Analysts + Analyze and respond to security events from SIEM, EDR, FWs, IDS, IPS, AV and other security data + Use approved AI tools to summarize complex incident timelines and consolidate evidence across sources (SIEM/EDR/network) to speed up escalated investigations. + Use AI-assisted analysis to identify patterns, likely attack paths, and investigation hypotheses, supporting deeper incident scoping and threat hunting activities. + Deliver high quality Incident Handling and investigation + Conduct threat hunting activities using advanced analytics and threat intelligence + Provide 24/7 on-call support for critical security incidents outside business hours ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Jobs in Tech: The State of the European Market](https://www.wearedevelopers.com/magazine/575-jobs-in-tech-the-state-of-the-european-market)