> Markdown version of [/jobs/ext/2999611-cybersecurity-defense-specialist](https://www.wearedevelopers.com/jobs/ext/2999611-cybersecurity-defense-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Defense Specialist - **Company:** Network with other new co-workers within your first 30 days through our onboarding program. - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Cyber Security, Query Languages, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Machine Learning, Tensorflow, Red Team (Cyber Security), Kusto Query Language, Runbook, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Pytorch, Retrieval-Augmented Generation, Large Language Models, Prompt Engineering, Mitre Att&ck, Cyber Threat Analysis, Git, Scikit Learn, Data Analytics, Low-code - **Published:** September 19, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role + Bachelor's Degree with IT field of study required. + 8 to 10 Years of relevant work experience. + 5+ years in security engineering with demonstrated cross-domain experience (SIEM + SOAR or SIEM + Detection). + Proficiency in SIEM query languages (SPL, KQL) AND SOAR playbook development (Python, low-code platforms). + Experience building or integrating AI/ML models for security use cases. + Strong Python skills with familiarity in ML frameworks (scikit-learn, PyTorch) and LLM APIs. + Detection engineering experience: Sigma rules, MITRE ATT&CK mapping, rule tuning methodology. + Git-based workflow proficiency for detection-as-code and infrastructure-as-code. + Other Education / Certifications: selection of security and technology certifications and/or equivalent proven work experience + Able to recognize and attend to important details with accuracy and efficiency. + Able to communicate clearly and convey necessary information. + Able to converse and write effectively in English and local language. + Able to create and conduct formal presentations. + Able to interact effectively with all levels of management + Possesses strong multi-cultural interpersonal skills. + Possesses strong leadership skills with a willingness to lead, create new ideas, and be assertive. + Possesses strong organizational and time management skills, driving tasks to completion. + Able to constructively work under stress and pressure when faced with high workloads and deadlines. + Able to maintain and promote social, ethical, and organizational standards in conducting internal and external business activities. + Able to work independently with minimum supervision. + Able to exhibit ability to be sensitive to the needs, concerns, and feelings of others. + Able to quickly learn new systems and technology. + Able to use relevant computer system applications at an advanced level. ## Description The Senior Cyber Security Specialist is responsible for designing, implementing and managing security technology solutions globally. Leads or serves as experienced technical resource in multi-discipline IT security projects intended to continually improve the security infrastructure and operating procedures. Keeps abreast of the latest technologies and identifies opportunities to leverage them to improve TD SYNNEX's cyber protection, detection and response capabilities. The responsibilities include reviewing our current security measures and processes in all geographies TD SYNNEX operates in, identifying and addressing areas of weakness through penetration testing and red teaming, and responding promptly to possible security breaches. Continuously improves core processes in identity & access management, threat hunting and analysis, vulnerability management, security monitoring and incident response both on-premise and in the cloud. Documents operating procedures and run books and trains the support team(s)., A full-stack security engineer who operates fluidly across SIEM administration, playbook development, detection rule creation, and AI system implementation. Owns a domain focus area while maintaining cross-functional capability across all disciplines., + Develop and deploy AI-powered detection rules using ML anomaly models, LLM-generated Sigma/SPL/KQL, and behavioral analytics. + Build intelligent SOAR playbooks that leverage LLM reasoning for dynamic decision-making and adaptive response. + Implement and tune AI-driven alert triage systems - automated scoring, enrichment, and routing based on ML classifiers. + Manage SIEM platform components: index optimization, search performance, and data model maintenance. + Design prompt engineering frameworks and evaluation harnesses for security-focused LLM applications. + Build RAG (Retrieval-Augmented Generation) pipelines using internal security knowledge bases, runbooks, and threat intel. + Conduct AI-augmented threat hunting - using LLMs to generate hypotheses and ML to identify anomalous patterns at scale. + Develop and maintain CI/CD pipelines for detection rules, playbooks, and ML model deployments., + Technical design, implementation, enhancement and ongoing support for security technologies (30%) + Executes and continually improves core security processes such as vulnerability management, threat analysis, security monitoring and incident response, identity and access management (10%) + AppSec reviews, penetration testing and red teaming activities to identify gaps and weaknesses. Utilize red team learnings to improve detection capabilities and response automation (20%) + Process automation, orchestration for improving team efficiency, documentation and training (20%) + Data analytics and KPI reporting for ensuring operational effectiveness and controls health (10%) + Collects, processes, preserves, analyzes, and presents computer-related evidence in support of breaches, vulnerability mitigation and/or criminal, fraud, counterintelligence, or law enforcement investigations. (10%) ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Photonic Computing: Programming a New Class of AI Accelerators (incl. Live Coding)](https://www.wearedevelopers.com/videos/100196-photonic-computing-programming-a-new-class-of-ai-accelerators-incl-live-coding) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Serverless deployment of (large) NLP models ](https://www.wearedevelopers.com/videos/158-serverless-deployment-of-large-nlp-models) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)