> Markdown version of [/jobs/ext/1985736-l2-soc-analyst-madrid](https://www.wearedevelopers.com/jobs/ext/1985736-l2-soc-analyst-madrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # L2 Soc Analyst - Madrid - **Company:** Integrity360 - **Location:** Torrejón de Ardoz, Spain - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, PM2, Security Information and Event Management, Mitre Att&ck, Cybercrime, Drilldown, Microsoft Sentinel, ArcSight Event Correlation, Splunk - **Published:** August 8, 2026 - **Apply:** https://www.buscojobs.com.es/l-2-soc-analyst-madrid-en-torrejon-de-ardoz-ID-365900117 ## About the Role in a SOC Tier 1 or security analyst role Advanced investigative and analytical capability Strong understanding of modern attack techniques, threat actors, and detection methodologies Proven experience with SIEM, EDR/XDR, identity, email and cloud security tooling Excellent technical documentation and communication skills Ability to manage multiple complex incidents simultaneously Ability to perform event correlation, host/ network threat analysis. Ability to manage multiple incidents and make effective decisions under high pressure environment. Certifications/Qualifications (preferred but not required) Security industry certifications: SEC+, CYSA+, Net+, SC-200,AZ-500,AZ-900,Splunk Power user A working knowledge of Intrusion Prevention System (IPS), SIEM, SOAR & DLP is a nice to have. Experience working with threat hunting tools is nice to have. ## Description Level 2 SOC AnalystTitle: Level 2 SOC AnalystLocation: Madrid, on siteJob type: Full-Time PermanentSalary: Negotiable / DOEAbout UsIntegrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres (SOCs)-including locations in Dublin, Sofia, Stockholm, Madrid, Rome and Cape Town-we support more than 2,500 clients across a wide range of industries.Over 80% of our team are technical experts, focused on helping clients proactively identify, protect, detect and respond to threats in an ever-evolving cyber landscape. Our security-first approach positions cyber resilience as a business enabler, empowering organisations to operate with confidence.At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you're ready to take your cyber security career to the next level, we'd love to hear from you.Job Role / ResponsibilitiesAs aL2SOC Analyst, you will act as a core investigator responsible for deep-dive analysis, incident ownership, and advanced threat handling. You will mentor L1 SOC analysts within the team.This role is part of a dedicated SOC team , providing analysts with the opportunity to operate within a highly mature security environment, gain exposure to advanced technologies and complex threat scenarios, and develop deep domain expertise in financial services security operations.Primary Duties/Responsibilities include:Leadinvestigationof confirmed andhigh-risk security incidentsPerformdeep-dive analysisusing:Microsoft SentinelMicrosoft Defender SuiteTrellixZscalerApplythreat intelligenceand attackerTTPanalysis using:MITRE ATT&CKCyber Kill ChainNIST IR LifecycleProducehigh-quality incident reportswith actionable recommendationsCoordinatecontainmentandremediationactions with engineering, infrastructure, and client teamsProvide technicalguidanceandmentorshipto Tier 1 analystsParticipate incontinuous improvementof SOC processes, playbooks, and detection qualityMaintain exceptionalcommunicationwith client stakeholders during active incidentsPerform ad-hoc analysis of varied logs, identifying anomalies in customer environments.Desired SkillsMinimum1 year experiencein a SOC Tier 1 or security analyst roleAdvanced investigative and analytical capabilityStrong understanding of modern attack techniques, threat actors, and detection methodologiesProven experience with SIEM, EDR/XDR, identity, email and cloud security toolingExcellent technical documentation and communication skillsAbility to manage multiple complex incidents simultaneouslyAbility to perform event correlation, host/ network threat analysis.Ability to manage multiple incidents and make effective decisions under high pressure environment.Certifications/Qualifications (preferred but not required)Security industry certifications: SEC+, CYSA+, Net+, SC-200,AZ-500,AZ-900,Splunk Power userA working knowledge of Intrusion Prevention System (IPS), SIEM, SOAR & DLP is a nice to have.Experience working with threat hunting tools is nice to have.#LI-PM2 ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) ## Related Articles - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)