L1 Soc Analyst - Madrid

Integrity360
Torrejón de Ardoz, Spain
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Languages
English

Tech stack

Cloud Computing CompTIA Security+ Cyber Security Log Analysis Microsoft Security Essentials PM2 Security Information and Event Management Office365 Mitre Att&ck Azure Security Center Microsoft Sentinel Servicenow
+1 more
Vulnerability Analysis

Job description

Level 1 SOC AnalystTitle: Level 1 SOC AnalystLocation: Madrid, on siteJob type: Full-Time PermanentSalary: Negotiable / DOEAbout UsIntegrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres (SOCs)-including locations in Dublin, Sofia, Stockholm, Madrid, Rome and Cape Town-we support more than 2,500 clients across a wide range of industries.Over 80% of our team are technical experts, focused on helping clients proactively identify, protect, detect and respond to threats in an ever-evolving cyber landscape. Our security-first approach positions cyber resilience as a business enabler, empowering organisations to operate with confidence.At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you’re ready to take your cyber security career to the next level, we’d love to hear from you.Job Role / ResponsibilitiesAs a Level 1 SOC Analyst, you will act as the first line of defense, responsible for continuous monitoring, triage, and initial investigation of security events. This role is critical in maintaining security posture and ensuring only high-quality, actionable alerts progress through the SOC pipeline.Primary Duties/Responsibilities include:Monitor security events across oursecurity ecosystem, including:Microsoft SentinelMicrosoft Defender for EndpointDefender for IdentityDefender for Office365Defender for Cloud AppsPerformalert triagewith clear analytical judgement:Validate alertsAssign appropriate severityProvide full investigative context before escalationConductpreliminary investigations:Identify IOCs, affected systems, attack vectors and potential business impactApply frameworks such as MITRE ATT&CK, Cyber Kill Chain, and NIST IR lifecycleMaintain high-qualitydocumentationand case notes within ServiceNow SIRCommunicateeffectively with internal teams and client stakeholdersContribute tocontinuous improvementthrough feedback, tuning suggestions, and knowledge sharingDemonstrate strong commitment to ongoing professional developmentSLA handling/management- Aspire to manage security events in accordance with applicable (response and resolution) SLA’s.Desired SkillsDemonstrable experience in IT or cybersecurity support, ideally within a SOC or monitoring environmentSolid understanding of cybersecurity fundamentals and CIA principlesFamiliarity with SIEM, EDR/XDR, log analysis, and security monitoring workflowsWorking knowledge of MITRE ATT&CK and NIST IR processesStrong analytical and investigative thinkingExcellent written and verbal communication skillsAbility to operate independently within Tier 1 scopeFluent in EnglishAbility to work effectively in a fast-paced environment and prioritize tasks accordinglyCertifications/Qualifications (preferred but not required)CompTIA Security+, ISC2, ISACA, SANS or equivalentGIAC Security essentials (GSEC)Blueteam security level 1#LI-PM2

Requirements

Demonstrable experience in IT or cybersecurity support, ideally within a SOC or monitoring environment Solid understanding of cybersecurity fundamentals and CIA principles Familiarity with SIEM, EDR/XDR, log analysis, and security monitoring workflows Working knowledge of MITRE ATT&CK and NIST IR processes Strong analytical and investigative thinking Excellent written and verbal communication skills Ability to operate independently within Tier 1 scope Fluent in English Ability to work effectively in a fast-paced environment and prioritize tasks accordingly Certifications/Qualifications (preferred but not required), CompTIA Security+, ISC2, ISACA, SANS or equivalent GIAC Security essentials (GSEC)

About the company

Integrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres (SOCs)-including locations in Dublin, Sofia, Stockholm, Madrid, Rome and Cape Town-we support more than 2,500 clients across a wide range of industries. Over 80% of our team are technical experts, focused on helping clients proactively identify, protect, detect and respond to threats in an ever-evolving cyber landscape. Our security-first approach positions cyber resilience as a business enabler, empowering organisations to operate with confidence. At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you’re ready to take your cyber security career to the next level, we’d love to hear from you. Job Role / Responsibilities As a Level 1 SOC Analyst, you will act as the first line of defense, responsible for continuous monitoring, triage, and initial investigation of security events. This role is critical in maintaining security posture and ensuring only high-quality, actionable alerts progress through the SOC pipeline.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

2:14 min

Securing analysis platforms via network access controls

Jennifer Reif · LIVE

Videos

See all

Related articles

See all