Associate Security Analyst

NCC Group
Madrid, Spain
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Business Process Modeling Content Delivery Networks Cloud Computing Information Leak Prevention Linux Intrusion Detection and Prevention Intrusion Detection Systems Network Protocols Runbook Security Information and Event Management Data Processing
+4 more
Google Cloud Mitre Att&ck Oracle Cloud Infrastructure Vulnerability Analysis

Requirements

Associate SOC Analyst Department: Cyber Services and Capabilities Employment Type: Full Time Location: ESP Madrid Description As an Associate Security Analyst, you will be the first line of defence in the Event Monitoring Centre, responsible for the initial triage of security alerts, basic vulnerability analysis and data loss prevention. Your primary role will be to monitor, analyse, and assess incoming alerts, identifying potential security incidents based on established criteria. You will elevate confirmed or suspicious threats to the R2 analysts, senior analysts, or the shift lead for further investigation and response. This role requires strong analytical skills, attention to detail, and the ability to follow escalation protocols to ensure swift and effective incident management. Ideal candidates will have a foundational understanding of cybersecurity principles, experience with SIEM tools, and a commitment to continuous learning in a fast-paced security environment. Due to being the initial contact for triaging alerts, your expertise will directly support analytic development by suggesting customer tuning rules to ensure the efficient running of the SOC. This role requires strong analytical skills, technical proficiency, and a commitment to continuous learning in a dynamic security environment. Key Responsibilities Threat Detection and Monitoring - Monitor the ITSM platform for new alerts, schemas and tickets - Monitor the SIEM Logs, IDS Logs and Managed Intelligence sources - Identify potential threats, vulnerabilities, and indicators of compromise - Initiate escalation procedures to counteract potential threats and vulnerabilities Incident Remediation and Documentation - Escalate to R2 analysts, Team Lead or senior analyst should further clarification or four eyes be required - Provide incident remediation and prevention recommendations to customers using established procedures and analyst experience - Document and adhere to security monitoring processes - Suggest process and procedure improvement based on working requirements to streamline processes Customer Service and Escalation - Exceed customer expectations by always delivering exceptional customer service - Be the initial point of contact for alerts and schemas triaged - Contribute to the creation and maintenance of security documentation, including incident response playbooks, standard operating procedures, and knowledge base articles Reporting and Continuous Improvement - Compile and review service-focused reports for effective communication - Contribute to the creation and maintenance of security documentation, including incident response playbooks, standard operating procedures, and knowledge base articles - Be susceptible to mentoring from senior analysts Threat Analysis and Collaboration - Contribute practical insights to the analysis of common security incidents - Maintain working relationships with the Analytic Development and Security Engineering teams - Collaborate with shift partners to provide a high quality of service General Duties - Perform additional assigned duties as required - Flexibility to quickly learn and adapt to new security tools, technologies, and processes - Process Data Schema Review data loss prevention alerts - Strong analytical and problem-solving skills - Good communication skills, both written and verbal - Ability to work collaboratively as part of a team - Keep up to date with latest emerging threats and APT groups - Ability to be mentored by senior analysts Skills, Knowledge & Expertise Minimum Requirements Network, Cloud and OS Knowledge: - Understanding of common network protocols and tools - Understanding of Linux operating systems - Understanding of Content Delivery Networks - Understanding of the CIA triad and how it interacts with security - Understanding of cloud technologies - AWS, GCP, OCI Customer interaction: - Experience with documenting both high level and technical customer facing information - Confidence providing critical/sensitive information accurately - Contacting key stakeholders during major incidents Incident Analysis and Response: - Awareness of the MITRE ATT&CK framework - Pedigree in performing in-depth analysis of security alerts - Assess customer impact through investigation and work with senior analy

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on es.trabajo.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · WWC 2024

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · WWC 2022

Videos

See all

Related articles

See all