Security Operations Analyst (Cyber Defense Operations)

Pragmatike
Valencia, Spain
1 day ago
Apply on www.adzuna.es
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Microsoft Windows Amazon Web Services Apple Mac Systems Microsoft Azure Bash Shell Software as a Service Cloud Computing Cloud Computing Security Cyber Security Databases Linux Web Servers
+21 more
Infrastructure as a Service (IaaS) Python (Programming Language) Log Analysis Microsoft Security Essentials Network Intrusion Detection Systems Network Monitoring Platform as a Service (PAAS) Windows PowerShell ArcSight SIEM Tool Ruby Security Information and Event Management Syslog TCP/IP Scripting QRadar Firewalls (Computer Science) Azure Security Center Cybercrime Microsoft Sentinel Cyber Warfare Splunk

Job description

You’ll be part of a 24/7 Security Operations Centre (SOC) responsible for monitoring, detecting, investigating, and responding to cyber threats across enterprise, cloud, network, and endpoint environments.

This is a hands-on security role focused on alert triage, threat investigation, log analysis, incident response, and security monitoring, working alongside cybersecurity specialists distributed across multiple regions.

What You’ll Do

  • Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms.
  • Analyze host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS.
  • Investigate suspicious activity, identify root causes, and determine appropriate remediation or escalation.
  • Support incident response, remediation, and recovery activities.
  • Work closely with Incident Response and other cybersecurity teams to manage security threats.
  • Analyze network and security events using TCP/IP, syslog, firewall, and network monitoring data.
  • Identify opportunities to improve detection quality and reduce false positives through tuning and optimization.
  • Gather technical information from clients to improve security monitoring and detection.
  • Prepare and present security reports, summaries, and technical findings.
  • Contribute to SOC procedures, documentation, knowledge bases, and quality-control processes.
  • Review operational feedback and implement corrective actions to continuously improve service quality., * Work inside a global 24/7 cybersecurity operation protecting international organizations.
  • Gain exposure to large-scale cloud, SIEM, EDR, network, and endpoint security environments.
  • Collaborate with cybersecurity specialists across multiple regions and disciplines.
  • Work directly on real-world threat detection and incident response.
  • Build experience across a broad enterprise security technology stack.

Requirements

  • 5+ years of relevant experience in IT/cybersecurity, including security alert triage and incident support.
  • Hands-on experience working in a SOC environment.
  • Strong experience with SIEM and EDR platforms.
  • Advanced log analysis skills across Windows/Linux, databases, applications, and infrastructure.
  • Strong knowledge of Microsoft Security technologies, including Microsoft Sentinel and Defender.
  • Experience with cloud security across Azure, AWS, and/or GCP.
  • Experience with SIEM platforms such as Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK.
  • Experience with at least one EDR solution such as Microsoft Defender for Endpoint or CrowdStrike.
  • Knowledge of email security, network monitoring, and incident response.
  • Strong knowledge of Linux, macOS, and Windows.
  • Fluent English with excellent written and verbal communication skills.

Nice to Have

  • Experience working on an Incident Response team with Tier-1/Tier-2 incident triage.
  • AWS security monitoring experience across IaaS, PaaS, or SaaS environments.
  • Scripting experience with Python, PowerShell, Bash, Ruby, or similar.
  • Certifications such as Microsoft SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.
  • Customer-facing cybersecurity experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all