> Markdown version of [/jobs/ext/1605240-soc-technical-lead-threat-hunting-incident-response](https://www.wearedevelopers.com/jobs/ext/1605240-soc-technical-lead-threat-hunting-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Soc Technical Lead - Threat Hunting & Incident Response - **Company:** Thales - **Location:** Málaga, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Networks, Distributed Systems, Identity and Access Management, Network Forensics, Security Information and Event Management, Mitre Att&ck, Cybercrime - **Published:** July 27, 2026 - **Apply:** https://www.buscojobs.com.es/soc-technical-lead-threat-hunting-incident-response-en-malaga-ID-364530011 ## About the Role 4+ years of experience in cybersecurity to join our central services team. We are seeking a highly motivated professional with strong expertise in cybersecurity infrastructures , capable of supporting and managing complex technological environments across leading security vendors. Join the Team Defending Thales' Future At Thales, we don't just respond to threats-we anticipate them. We are looking for a visionary SOC Technical Lead who thrives at the intersection of advanced threat hunting, rapid incident response, and team mentorship. If you are passionate about building resilient security architectures and want to lead a team that is defining the next generation of SOC services, this is your opportunity to make a lasting impact., Minimum 2?5 years of experience in Cybersecurity, with a strong focus on Security Operations, Incident Response, or Threat Hunting. Demonstrated experience in a technical lead or senior?level advisory role, guiding teams through complex technical challenges. Proven background in managing security operations within high?scale, distributed environments (Cloud or Hybrid). Advanced understanding of attacker TTPs (Tactics, Techniques, and Procedures) and the MITRE ATT&CK framework. Deep expertise in SIEM/SOAR platforms, EDR/XDR tools, and network traffic analysis. Experience with Cloud security (AWS, Azure, or GCP) and understanding of shared responsibility models. Experience leading large-scale incident investigations and performing root?cause analysis. Familiarity with forensic analysis tools and procedures. ## Description Location: Madrid Emilio Vargas, SpainThales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billions of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more. More than 30,000 organizations already rely on us to verify the identities of people and things, grant access to digital services, analyze vast quantities of information and encrypt data to make the connected world more secure.Thales in Spain is a leader in technological solutions applied to Defence, Aeronautics, Security, Transportation and Space and, furthermore, is a global centre for excellence in Space, Security of Critical Infrastructures and Transportation. With a turnover of €320 million and a staff of 1,200, it exports approximately 40% of its total production principally to the Middle East, North Africa and Latin America.AtThales S21sec Spain, we are looking for aSOC Technical Lead - Threat Hunting & Incident Responsewith4+ years of experience in cybersecurityto join our central services team.We are seeking a highly motivated professional with strong expertise incybersecurity infrastructures, capable of supporting and managing complex technological environments across leading security vendors.Join the Team Defending Thales' Future At Thales, we don't just respond to threats-we anticipate them. We are looking for a visionary SOC Technical Lead who thrives at the intersection of advanced threat hunting, rapid incident response, and team mentorship. If you are passionate about building resilient security architectures and want to lead a team that is defining the next generation of SOC services, this is your opportunity to make a lasting impact.Key ResponsibilitiesDrive Proactive Defense: spearhead our threat hunting strategy, utilizing advanced telemetry and intelligence to uncover sophisticated attacker patterns before they impact our infrastructure.Lead Through Crisis: be the technical force behind our Incident Response, guiding the team through high-pressure situations, conducting deep-dive forensics, and refining our defense playbook to stay ahead of the adversary.Mentor and Innovate: elevate the talent around you through hands?on mentorship, technical workshops, and collaboration, cultivating a culture of continuous improvement and technical excellence.Architect the Future: partner with our cloud and product teams to integrate security into every stage of the lifecycle. Champion \"Security?as?Code\" and automation, transforming how we monitor and protect our global ecosystem.RequirementsMinimum 2?5 years of experience in Cybersecurity, with a strong focus on Security Operations, Incident Response, or Threat Hunting.Demonstrated experience in a technical lead or senior?level advisory role, guiding teams through complex technical challenges.Proven background in managing security operations within high?scale, distributed environments (Cloud or Hybrid).Advanced understanding of attacker TTPs (Tactics, Techniques, and Procedures) and the MITRE ATT&CK framework.Deep expertise in SIEM/SOAR platforms, EDR/XDR tools, and network traffic analysis.Experience with Cloud security (AWS, Azure, or GCP) and understanding of shared responsibility models.Experience leading large-scale incident investigations and performing root?cause analysis.Familiarity with forensic analysis tools and procedures.Why Join Thales S21sec Spain?At Thales S21sec, we pride ourselves on beinginnovative and flexiblein how we work. We continuously evolve our policies to ensure a truework?life balance.100% Flexible Hybrid WorkWork from home or come to the office whenever you choose.Up to 41 Days Off Per Year24 vacation days + additional flexible daysOption to enjoy one free Friday per month (12 per year)Choose between summer reduced hours or extra days of leaveFlexible Compensation PackageOptimize your net salary with benefits such as meal vouchers, transport cards, childcare vouchers, and training support.Continuous Learning & CertificationsAccess to anannual training planincluding technical certifications, languages, and soft skills.Knowledge Sharing CultureParticipate in our voluntarySpeakers Programand share your expertise.Performance-Based BonusesClear and transparent objectives aligned with KPI-based annual bonuses.Career Growth Your WayChoose your path:Leadership and team managementDeep technical specialization with top expertsJoin UsIf you are passionate about cybersecurity and want to make an impact,we are your company.We're looking forward to meeting you!At Thales we provide CAREERS and not only jobs. With Thales employing 80,000 employees in 68 countries our mobility policy enables thousands of employees each year to develop their careers at home and abroad, in their existing areas of expertise or by branching out into new fields. Together we believe that embracing flexibility is a smarter way of working. Great journeys start here, apply now!#J-*****-Ljbffr ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Jobs in Tech: The State of the European Market](https://www.wearedevelopers.com/magazine/575-jobs-in-tech-the-state-of-the-european-market) - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette)