> Markdown version of [/jobs/ext/1934414-soc-technical-lead](https://www.wearedevelopers.com/jobs/ext/1934414-soc-technical-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Soc Technical Lead - **Company:** Squad - Cabinet De Conseils Et D'Expertises - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Information Systems, Digital Assets, Intrusion Detection and Prevention, Network Intrusion Detection Systems, Security Information and Event Management, Security Orchestration, Automation & Response - **Published:** August 5, 2026 - **Apply:** https://www.buscojobs.com.es/soc-technical-lead-en-barcelona-ID-365530140 ## About the Role 10+ years of SOC or cybersecurity experience with leadership responsibilities. Deep expertise across SIEM, EDR, and SOAR technologies (preferably Elastic & CrowdStrike). Strong background in threat detection, automation, and incident response architecture. Excellent communication and stakeholder management skills. Preferred Certifications: BTL2, GIAC GCIH, Elastic Certified Engineer, CrowdStrike Certified Falcon Administrator ## Description Since ****, SQUAD Group has been a key player in the cybersecurity landscape.We partner with leading organizations to protect their information systems through a comprehensive 360° offering of consulting, integration, expertise, and managed services.Our mission:Securing Together!We believe in a collaborative approach to cybersecurity, where experts and clients work hand-in-hand to anticipate threats and protect critical infrastructure.As part of our growing team, we're seeking aSOC Technical Engineer.Based in Barcelona, this role will put you at the core of a top-tier Incident Response team, defending the digital assets of a company that connects hundreds of millions of people every month.Your RoleYou are the cornerstone of our Security Operations Center engagement, providing technical leadership, architectural direction, and operational oversight.You'll ensure the design, optimization, and integration of the SOC's security stack, including SIEM, EDR, DLP, and NIDS technologies.You'll coordinate daily operations, guide analysts across all tiers, and serve as the primary bridge between your SOC team and internal leadership.Your role ensures operational excellence, effective incident management, and continuous enhancement of detection and response capabilities.Your ResponsibilitiesLead environment assessments, including Elastic SIEM audits and detection rule gap analysis.Define escalation workflows, playbooks, and operational documentation.Oversee SOAR automation and orchestration, driving efficiency across response processes.Coordinate and mentor SOC members (L1-L3), ensuring high-quality investigations and continuous improvement.Act as the senior escalation point for complex security incidents and client communications.Align SOC strategy with the client's objectives, maintaining performance metrics and operational KPIs.What You Bring10+ years of SOC or cybersecurity experience with leadership responsibilities.Deep expertise across SIEM, EDR, and SOAR technologies (preferably Elastic & CrowdStrike).Strong background in threat detection, automation, and incident response architecture.Excellent communication and stakeholder management skills.Preferred Certifications:BTL2, GIAC GCIH, Elastic Certified Engineer, CrowdStrike Certified Falcon AdministratorWhy Join Squad?Personalized Growth:We help you build a training and certification plan aligned with your professional goals through ourSquadeXpérience.Expertise Development:Participate in internal events like ourMixYourTalentwebinars and monthly CTF sessions.Visibility:Attend major industry conferences and contribute to our#TheExperttechnical blog.Culture:Enjoy a dynamic and close-knit environment with after-work events and team gatherings that foster great camaraderie.#J-*****-Ljbffr ## Related Videos - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Tokenization of Everything: Where the Real World Meets Blockchain](https://www.wearedevelopers.com/videos/1035-tokenization-of-everything-where-the-real-world-meets-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)