> Markdown version of [/jobs/ext/1673191-threat-detection-response-operations-manager](https://www.wearedevelopers.com/jobs/ext/1673191-threat-detection-response-operations-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Detection & Response Operations Manager - **Company:** Ey Gds Spain - **Location:** Spain - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Perl (Programming Language), Network Monitoring, Regular Expressions, Sherwood Applied Business Security Architecture, Security Information and Event Management, SQL Databases, Togaf - **Published:** July 2, 2026 - **Apply:** https://www.jobleads.com/es/job/eb382a91927a3c3e9860021d7e63401f4 ## About the Role * Hands-on expertise of SIEM technologies such as Microsoft Sentinel, Splunk from an security analyst's point of view. * Expert knowledge and experience in Security Monitoring. * Expert knowledge and experience in Cyber Incident Response. * Knowledge in cloud security and IOT/OT is a value add. * Knowledge in Network monitoring technology platforms such as Fidelis XPS and ExtraHop. * Knowledge in endpoint protection tools, techniques, and platforms such as Carbon Black, Defender, CrowdStrike. * Ability to work with minimal levels of supervision or oversight. * Customer Service oriented - Meets commitments to customers; Seeks feedback from customers to identify improvement opportunities., * 8-10 years of hands-on experience of operating/implementing/designing SIEM solutions and proven experience in Project Management. * Strong command on verbal and written English language. * B. Tech./ B.E. with sound technical skills. * Ability to work in client time zone. * Demonstrate both technical acumen and critical thinking abilities. * Strong interpersonal and presentation skills. * Certification in any of the SIEM platforms. * Knowledge of RegEx, Perl scripting and SQL query language is a value add. * Nice to have: Certification - CISM, CEH, CISSP, GCIH, GIAC, SABSA, TOGAF., Who has proven experience in leading operations for SOC projects, with hands-on experience in SIEM configuration and setup. ## Description As part of our EY-Cyber Security team, Threat Detection & Response Operations Manager will lead Operations/Delivery for TDR engagements with end-to-end security incident investigation support ensuring client SLAs and KPIs leveraging multiple SIEM/EDR/NSM solutions., * Oversee the process of detecting, reporting, and responding to security incidents, ensuring that the SOC team is able to effectively manage incidents when they occur. * Responsible for managing the security tools and technologies used by the SOC team, ensuring that they are properly configured and maintained, and that they are able to effectively monitor and detect security threats. * Lead and manage the Security operation center primarily responsible for security event monitoring of client's network. * Ensure that Service Level Agreements are defined, tracked and met for all clients. * Provide technical leadership and advise to junior team members on SOC activities. * Revise Standard operation policies & procedures as required and ensure it is followed by the team. * Identify opportunities to improve security monitoring and operational tasks. * Convey complex technical security concepts to technical and non-technical audiences including executives. * Develop and maintain productive working relationships with client personnel. * Oversee the daily SOC task that can be automated. * Provide both strategic view and benefits to client and work with limited resource to achieve it. ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1520-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)