Soc Analyst

Bme | Bolsas Y Mercados Españoles
Madrid, Spain
8 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work

Tech stack

Application Programming Interfaces (APIs) Microsoft Azure Cyber Security Continuous Integration Query Languages Intrusion Detection and Prevention Python (Programming Language) Security Information and Event Management EndPointSecurity Scripting Mitre Att&ck Gitlab
+3 more
Cybercrime Cortex XSOAR Platform Security Orchestration, Automation & Response

Job description

The Security Operations Center (SOC) is a critical Line of Defense 1 function at SIX, responsible for detecting, investigating, and responding to cyber threats across endpoint, identity, network, cloud, and email environments.We are looking for a hands-on security professional with experience in incident response, threat hunting, and security monitoring.In this role, you will investigate complex alerts, develop and tune detection use cases, support containment and remediation efforts, improve automation and playbooks, and proactively identify threats to strengthen SIX’s overall security posture.What You Will DoDevelop, tune, and maintain threat detections and SIEM use cases across endpoint, network, identity, cloud, mail, and M365 environments.Investigate complex security incidents, lead threat analysis, and coordinate containment and remediation activities.Design and improve detection content, SOC automation, SOAR workflows, and incident response playbooks.Conduct proactive threat hunting using threat intelligence and the MITRE ATT&CK framework.Identify detection gaps and continuously enhance SOC capabilities and security posture.Mentor junior analysts and contribute to SOC process improvements and knowledge sharing.What You Bring4+ years of experience in SOC operations, detection engineering, threat hunting, and incident response.Hands-on experience with SIEM, EDR, and SOAR platforms (preferably Sentinel, Elastic, Defender for Endpoint, and Cortex XSOAR).Strong background in detection rule development, security investigations, and threat hunting across multiple telemetry sources.Experience with scripting, automation, APIs, and tools such as Python, GitLab, Azure DevOps, and CI/CD practices.Knowledge of security query languages and frameworks, including MITRE ATT&CK.Strong analytical, communication, collaboration, and mentoring skills.What We OfferHybrid model up to 40% working from home37,5 hours/week with flexible schedule and 29+2 holidaysDaily meal allowanceAdditional Medical Insurance for employee and familyPension fundAccess to technical and language learning platformsFree parking spots, charger spots and shuttle bus (only for Las Rozas - Madrid location)#J-*****-Ljbffr

Requirements

We are looking for a hands-on security professional with experience in incident response, threat hunting, and security monitoring. In this role, you will investigate complex alerts, develop and tune detection use cases, support containment and remediation efforts, improve automation and playbooks, and proactively identify threats to strengthen SIX’s overall security posture.What You Will DoDevelop, tune, and maintain threat detections and SIEM use cases across endpoint, network, identity, cloud, mail, and M365 environments.Investigate complex security incidents, lead threat analysis, and coordinate containment and remediation activities.Design and improve detection content, SOC automation, SOAR workflows, and incident response playbooks.Conduct proactive threat hunting using threat intelligence and the MITRE ATT&CK framework.Identify detection gaps and continuously enhance SOC capabilities and security posture.Mentor junior analysts and contribute to SOC process improvements and knowledge sharing.What You Bring4+ years of experience in SOC operations, detection engineering, threat hunting, and incident response.Hands-on experience with SIEM, EDR, and SOAR platforms (preferably Sentinel, Elastic, Defender for Endpoint, and Cortex XSOAR). Strong background in detection rule development, security investigations, and threat hunting across multiple telemetry sources.Experience with scripting, automation, APIs, and tools such as Python, GitLab, Azure DevOps, and CI/CD practices.Knowledge of security query languages and frameworks, including MITRE ATT&CK.Strong analytical, communication, collaboration, and mentoring skills.What We OfferHybrid model up to 40% working from home37,5 hours/week with flexible schedule and 29+2 holidaysDaily meal allowanceAdditional Medical Insurance for employee and familyPension fundAccess to technical and language learning platformsFree parking spots, charger spots and shuttle bus (only for Las Rozas - Madrid location)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:54 min

Implementing geographic salary tiers for compensation equity and fairness

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

Videos

See all

Related articles

See all