> Markdown version of [/jobs/ext/1611625-security-monitoring-incident-response-product-owner](https://www.wearedevelopers.com/jobs/ext/1611625-security-monitoring-incident-response-product-owner). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Monitoring & Incident Response Product Owner - **Company:** Tamarind Intelligence - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Cyber Security, Working Model 2D, Mitre Att&ck, Information Technology, Cybercrime - **Published:** July 27, 2026 - **Apply:** https://www.buscojobs.com.es/security-monitoring-incident-response-product-owner-m-f-d-en-madrid-ID-364719027 ## About the Role Support audits, assessments, and readiness activities related to detection and response.Contributing your strengths: your qualifications- Bachelor's/Master's in Cybersecurity, Computer Science, or related field. - 7+ years of operational experience in SOC environments (L2/L3, threat hunting, incident response, service delivery, operational delivery). - Exposure to global organizations and distributed security functions. - Knowledge of modern security frameworks (MITRE ATT&CK, NIST CSF, ISO *****). - Experience implementing KPIs and running continual service improvement processes. - Relevant certifications (e.G., CISSP, GCIH, CCSP, GCIA, GMON) are a plus, but not mandatory. - Fluency in English (written and spoken). ## Description We are expanding our Global Corporate Information Security team and are looking for a Security Monitoring & Incident Response Product Owner (m/f/d) to establish and scale our global security operations.Creating passion: your responsibilitiesSOC Operations & Service Management- Own the end-to-end operations of the global SOC, ensuring effective collaboration between internal analysts and the MSSP (L1/L2).- Monitor, manage, and optimize processes, including alert triage, escalation flows, and incident response handovers.- Ensure all services related to Security Monitoring and Incident Response perform against defined SLAs and KPIs, and drive actions when service quality deviates.- Implement the SOC "product" roadmap related to Security Monitoring & Incident Response, including implementation of the strategic vision, backlog, and prioritization of improvements.Vendor & MSSP Management- Act as the primary liaison between the organization and the MSSP to deliver SOC services.- Conduct recurring service governance meetings (operational and tactical).- Track and validate MSSP deliverables, including detection operations, case handling quality, and runbook adherence.- Coordinate improvements to MSSP workflows, communication channels, and response processes.Incident Response Alignment- Align with the internal incident response team to ensure seamless escalation.- Support the refinement of incident response procedures, playbooks, and communication guidelines.- Ensure major incidents are appropriately handled, documented, and followed by lessons learned sessions.- Guide the continuous evolution of incident management maturity and readiness.Governance, Compliance & Documentation- Maintain alignment with internal security frameworks, standards, and regulatory requirements.- Produce regular reports on operational performance, risks, coverage, and incident trends.- Ensure processes, runbooks, service definitions, and operating procedures are consistently documented and kept up to date.- Support audits, assessments, and readiness activities related to detection and response.Contributing your strengths: your qualifications- Bachelor's/Master's in Cybersecurity, Computer Science, or related field.- 7+ years of operational experience in SOC environments (L2/L3, threat hunting, incident response, service delivery, operational delivery).- Exposure to global organizations and distributed security functions.- Knowledge of modern security frameworks (MITRE ATT&CK, NIST CSF, ISO *****).- Experience implementing KPIs and running continual service improvement processes.- Relevant certifications (e.G., CISSP, GCIH, CCSP, GCIA, GMON) are a plus, but not mandatory.- Fluency in English (written and spoken).- Willingness and ability to travel to Liebherr sites worldwide up to 10% of the time.Our commitment to you: your benefits- Competitive compensation and benefits package that recognizes your expertise.- Flexible and hybrid working model.- Creative freedom and responsibility to shape processes and solutions in our global transformation.- Continuous learning and development with tailored training and certification opportunities.- Meal vouchers.- Life and accident insurance.- Option to include a premium private health insurance package as part of the flexible remuneration.- A safe, stable and international workplace within a trusted family business that invests in people.LocationLiebherr IT Shared Service Centre Ibérica, S.L.Parque Norte.Alamo building Serrano Galvache, ******* MadridSpain (ES)#J-*****-Ljbffr ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)