Security Monitoring Analyst

AXA Group
Madrid, Spain
10 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Red Team (Cyber Security) Kusto Query Language Security Information and Event Management Data Logging

Job description

Experteer Overview As a Detection Strategist in AXA’s Security Operations Center, you shape high-fidelity detections by translating attacker behavior into durable rules.You bridge offensive tradecraft with SOC outcomes, owning detection content and guiding telemetry needs to improve visibility.Your work focuses on crafting advanced KQL-based alerts, reducing false positives, and collaborating with incident response to close gaps.This role offers impact at scale within a global, tech-driven security team.Compensaciones / Beneficios * Author complex KQL queries to detect sophisticated behaviors * Analyze raw telemetry from EDR, identity providers, and cloud infra to identify data gaps and improve logging policies * Tune rules to minimize false positives and prevent SOC noise * Validate new detections via targeted validation attacks and technique mapping to MITRE ATTu**CK * Perform gap analyses to uncover blind spots and drive remediation * Translate threat intelligence and red team techniques into actionable detection logic * Review and optimize the detection rule library for accuracy and coverage * Collaborate with Incident Response to understand and prevent recurrence of missed attacks Responsabilidades * Experience as a Red Teamer or in offensive security * Strong knowledge of attacker techniques and how to bypass detections * Ability to author high-fidelity SIEM detections and understand telemetry needs * Hands-on experience with log data from EDR, identity providers, and cloud platforms * Familiarity with MITRE ATTu**CK mapping and validation of detections Requisitos principales *

Requirements

Compensaciones / Beneficios * Author complex KQL queries to detect sophisticated behaviors * Analyze raw telemetry from EDR, identity providers, and cloud infra to identify data gaps and improve logging policies * Tune rules to minimize false positives and prevent SOC noise * Validate new detections via targeted validation attacks and technique mapping to MITRE ATTu**CK * Perform gap analyses to uncover blind spots and drive remediation * Translate threat intelligence and red team techniques into actionable detection logic * Review and optimize the detection rule library for accuracy and coverage * Collaborate with Incident Response to understand and prevent recurrence of missed attacks Responsabilidades * Experience as a Red Teamer or in offensive security * Strong knowledge of attacker techniques and how to bypass detections * Ability to author high-fidelity SIEM detections and understand telemetry needs * Hands-on experience with log data from EDR, identity providers, and cloud platforms * Familiarity with MITRE ATTu**CK mapping and validation of detections Requisitos principales *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:19 min

Enhancing product safety through continual red teaming operations

Rebekka Weiss Rebekka Weiss +1 · World Congress 2025

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

10:34 min

Implementing pragmatic security automation and analysis tools

LIVE

Videos

See all

Related articles

See all