> Markdown version of [/jobs/ext/2798261-soc-analyst](https://www.wearedevelopers.com/jobs/ext/2798261-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Soc Analyst - **Company:** SIX Group - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Agile Methodology, Microsoft Azure, Cloud Computing, Cyber Security, Continuous Integration, Intrusion Detection and Prevention, Python (Programming Language), Security Information and Event Management, EndPointSecurity, Scripting, Gitlab, Cybercrime, Cortex XSOAR Platform, Security Orchestration, Automation & Response - **Published:** September 8, 2026 - **Apply:** https://www.buscojobs.com.es/soc-analyst-en-madrid-ID-370270429 ## About the Role Compensaciones / Beneficios * Develop, tune, and maintain threat detections and SIEM use cases across multiple environments * Investigate complex security incidents and coordinate containment and remediation * Design and improve detection content, SOC automation, SOAR workflows, and incident response playbooks * Conduct proactive threat hunting using threat intelligence and MITRE ATTu****CK * Identify detection gaps and enhance SOC capabilities and security posture * Mentor junior analysts and contribute to SOC process improvements and knowledge sharing Responsabilidades * 4+ years of experience in SOC operations, detection engineering, threat hunting, and incident response * Hands-on experience with SIEM, EDR, and SOAR platforms (Sentinel, Elastic, Defender for Endpoint, Cortex XSOAR) * Strong background in detection rule development, security investigations, and threat hunting across telemetry sources * Experience with scripting, automation, APIs, and tools such as Python, GitLab, Azure DevOps, and CI/CD practices * Knowledge of security frameworks, including MITRE ATTu****CK * Strong analytical, communication, collaboration, and mentoring skills Requisitos principales * Flexible work models * Personal development and learning opportunities * Agile working methods ## Description Experteer Overview In this role you will be a hands-on security professional driving threat detection, analysis, and response within SIX's SOC.You will develop and tune detections across endpoint, network, cloud, and identity environments, investigate complex incidents, and advance automation and playbooks.You'll lead threat hunting using MITRE ATTu****amp;CK and mentor junior analysts, contributing to a stronger security posture.This opportunity combines operational excellence with proactive security work in a dynamic financial markets setting.Compensaciones / Beneficios * Develop, tune, and maintain threat detections and SIEM use cases across multiple environments * Investigate complex security incidents and coordinate containment and remediation * Design and improve detection content, SOC automation, SOAR workflows, and incident response playbooks * Conduct proactive threat hunting using threat intelligence and MITRE ATTu****CK * Identify detection gaps and enhance SOC capabilities and security posture * Mentor junior analysts and contribute to SOC process improvements and knowledge sharing Responsabilidades * 4+ years of experience in SOC operations, detection engineering, threat hunting, and incident response * Hands-on experience with SIEM, EDR, and SOAR platforms (Sentinel, Elastic, Defender for Endpoint, Cortex XSOAR) * Strong background in detection rule development, security investigations, and threat hunting across telemetry sources * Experience with scripting, automation, APIs, and tools such as Python, GitLab, Azure DevOps, and CI/CD practices * Knowledge of security frameworks, including MITRE ATTu****CK * Strong analytical, communication, collaboration, and mentoring skills Requisitos principales * Flexible work models * Personal development and learning opportunities * Agile working methods ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)