L2 Soc Analyst - Madrid

Integrity360
Torrejón de Ardoz, Spain
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours

Tech stack

Cloud Computing Security Cyber Security PM2 Security Information and Event Management Mitre Att&ck Cybercrime Drilldown Microsoft Sentinel ArcSight Event Correlation Splunk

Job description

Level 2 SOC AnalystTitle: Level 2 SOC AnalystLocation: Madrid, on siteJob type: Full-Time PermanentSalary: Negotiable / DOEAbout UsIntegrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres (SOCs)-including locations in Dublin, Sofia, Stockholm, Madrid, Rome and Cape Town-we support more than 2,500 clients across a wide range of industries.Over 80% of our team are technical experts, focused on helping clients proactively identify, protect, detect and respond to threats in an ever-evolving cyber landscape. Our security-first approach positions cyber resilience as a business enabler, empowering organisations to operate with confidence.At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you’re ready to take your cyber security career to the next level, we’d love to hear from you.Job Role / ResponsibilitiesAs aL2SOC Analyst, you will act as a core investigator responsible for deep-dive analysis, incident ownership, and advanced threat handling. You will mentor L1 SOC analysts within the team.This role is part of a dedicated SOC team , providing analysts with the opportunity to operate within a highly mature security environment, gain exposure to advanced technologies and complex threat scenarios, and develop deep domain expertise in financial services security operations.Primary Duties/Responsibilities include:Leadinvestigationof confirmed andhigh-risk security incidentsPerformdeep-dive analysisusing:Microsoft SentinelMicrosoft Defender SuiteTrellixZscalerApplythreat intelligenceand attackerTTPanalysis using:MITRE ATT&CKCyber Kill ChainNIST IR LifecycleProducehigh-quality incident reportswith actionable recommendationsCoordinatecontainmentandremediationactions with engineering, infrastructure, and client teamsProvide technicalguidanceandmentorshipto Tier 1 analystsParticipate incontinuous improvementof SOC processes, playbooks, and detection qualityMaintain exceptionalcommunicationwith client stakeholders during active incidentsPerform ad-hoc analysis of varied logs, identifying anomalies in customer environments.Desired SkillsMinimum1 year experiencein a SOC Tier 1 or security analyst roleAdvanced investigative and analytical capabilityStrong understanding of modern attack techniques, threat actors, and detection methodologiesProven experience with SIEM, EDR/XDR, identity, email and cloud security toolingExcellent technical documentation and communication skillsAbility to manage multiple complex incidents simultaneouslyAbility to perform event correlation, host/ network threat analysis.Ability to manage multiple incidents and make effective decisions under high pressure environment.Certifications/Qualifications (preferred but not required)Security industry certifications: SEC+, CYSA+, Net+, SC-200,AZ-500,AZ-900,Splunk Power userA working knowledge of Intrusion Prevention System (IPS), SIEM, SOAR & DLP is a nice to have.Experience working with threat hunting tools is nice to have.#LI-PM2

Requirements

in a SOC Tier 1 or security analyst role Advanced investigative and analytical capability Strong understanding of modern attack techniques, threat actors, and detection methodologies Proven experience with SIEM, EDR/XDR, identity, email and cloud security tooling Excellent technical documentation and communication skills Ability to manage multiple complex incidents simultaneously Ability to perform event correlation, host/ network threat analysis. Ability to manage multiple incidents and make effective decisions under high pressure environment. Certifications/Qualifications (preferred but not required) Security industry certifications: SEC+, CYSA+, Net+, SC-200,AZ-500,AZ-900,Splunk Power user A working knowledge of Intrusion Prevention System (IPS), SIEM, SOAR & DLP is a nice to have. Experience working with threat hunting tools is nice to have.

About the company

Integrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres (SOCs)-including locations in Dublin, Sofia, Stockholm, Madrid, Rome and Cape Town-we support more than 2,500 clients across a wide range of industries. Over 80% of our team are technical experts, focused on helping clients proactively identify, protect, detect and respond to threats in an ever-evolving cyber landscape. Our security-first approach positions cyber resilience as a business enabler, empowering organisations to operate with confidence. At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you’re ready to take your cyber security career to the next level, we’d love to hear from you. Job Role / Responsibilities

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

2:14 min

Securing analysis platforms via network access controls

Jennifer Reif · LIVE

Videos

See all

Related articles

See all