Security Monitoring & Incident Response Product Owner

Tamarind Intelligence
Madrid, Spain
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
7 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Cyber Security Working Model 2D Mitre Att&ck Information Technology Cybercrime

Job description

We are expanding our Global Corporate Information Security team and are looking for a Security Monitoring & Incident Response Product Owner (m/f/d) to establish and scale our global security operations.Creating passion: your responsibilitiesSOC Operations & Service Management- Own the end-to-end operations of the global SOC, ensuring effective collaboration between internal analysts and the MSSP (L1/L2).- Monitor, manage, and optimize processes, including alert triage, escalation flows, and incident response handovers.- Ensure all services related to Security Monitoring and Incident Response perform against defined SLAs and KPIs, and drive actions when service quality deviates.- Implement the SOC “product” roadmap related to Security Monitoring & Incident Response, including implementation of the strategic vision, backlog, and prioritization of improvements.Vendor & MSSP Management- Act as the primary liaison between the organization and the MSSP to deliver SOC services.- Conduct recurring service governance meetings (operational and tactical).- Track and validate MSSP deliverables, including detection operations, case handling quality, and runbook adherence.- Coordinate improvements to MSSP workflows, communication channels, and response processes.Incident Response Alignment- Align with the internal incident response team to ensure seamless escalation.- Support the refinement of incident response procedures, playbooks, and communication guidelines.- Ensure major incidents are appropriately handled, documented, and followed by lessons learned sessions.- Guide the continuous evolution of incident management maturity and readiness.Governance, Compliance & Documentation- Maintain alignment with internal security frameworks, standards, and regulatory requirements.- Produce regular reports on operational performance, risks, coverage, and incident trends.- Ensure processes, runbooks, service definitions, and operating procedures are consistently documented and kept up to date.- Support audits, assessments, and readiness activities related to detection and response.Contributing your strengths: your qualifications- Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field.- 7+ years of operational experience in SOC environments (L2/L3, threat hunting, incident response, service delivery, operational delivery).- Exposure to global organizations and distributed security functions.- Knowledge of modern security frameworks (MITRE ATT&CK, NIST CSF, ISO **).- Experience implementing KPIs and running continual service improvement processes.- Relevant certifications (e.G., CISSP, GCIH, CCSP, GCIA, GMON) are a plus, but not mandatory.- Fluency in English (written and spoken).- Willingness and ability to travel to Liebherr sites worldwide up to 10% of the time.Our commitment to you: your benefits- Competitive compensation and benefits package that recognizes your expertise.- Flexible and hybrid working model.- Creative freedom and responsibility to shape processes and solutions in our global transformation.- Continuous learning and development with tailored training and certification opportunities.- Meal vouchers.- Life and accident insurance.- Option to include a premium private health insurance package as part of the flexible remuneration.- A safe, stable and international workplace within a trusted family business that invests in people.LocationLiebherr IT Shared Service Centre Ibérica, S.L.Parque Norte.Alamo building Serrano Galvache, **** MadridSpain (ES)#J-*****-Ljbffr

Requirements

Support audits, assessments, and readiness activities related to detection and response.Contributing your strengths: your qualifications- Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field.

  • 7+ years of operational experience in SOC environments (L2/L3, threat hunting, incident response, service delivery, operational delivery).
  • Exposure to global organizations and distributed security functions.
  • Knowledge of modern security frameworks (MITRE ATT&CK, NIST CSF, ISO *****).
  • Experience implementing KPIs and running continual service improvement processes.
  • Relevant certifications (e.G., CISSP, GCIH, CCSP, GCIA, GMON) are a plus, but not mandatory.
  • Fluency in English (written and spoken).

Benefits & conditions

Willingness and ability to travel to Liebherr sites worldwide up to 10% of the time.Our commitment to you: your benefits- Competitive compensation and benefits package that recognizes your expertise.

  • Flexible and hybrid working model.
  • Creative freedom and responsibility to shape processes and solutions in our global transformation.
  • Continuous learning and development with tailored training and certification opportunities.
  • Meal vouchers.
  • Life and accident insurance.
  • Option to include a premium private health insurance package as part of the flexible remuneration.
  • A safe, stable and international workplace within a trusted family business that invests in people.LocationLiebherr IT Shared Service Centre IbĂŠrica, S.L.Parque Norte. Alamo building Serrano Galvache, *** MadridSpain (ES)#J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber ¡ World Congress 2026 Europe

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa ¡ LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady ¡ World Congress 2026 Europe

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 ¡ World Congress 2026 Europe

1:32 min

Pairing with teams for continuous threat modeling

Nazneen Rupawalla ¡ World Congress 2022

Videos

See all

Related articles

See all