Security Operations Analyst (SIEM & Threat Detection)

Pragmatike
Valencia, Spain
1 day ago
Apply on www.adzuna.es
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Microsoft Windows Amazon Web Services Apple Mac Systems Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cyber Security Linux Intrusion Detection and Prevention Python (Programming Language) Microsoft Security Essentials
+12 more
Network Monitoring Windows PowerShell ArcSight SIEM Tool Ruby Security Information and Event Management Scripting Data Ingestion QRadar Cyber Threat Analysis Azure Security Center Microsoft Sentinel Splunk

Job description

Pragmatike is recruiting on behalf of a major international organization for a Security Operations Analyst specializing in SIEM and Threat Detection.

You’ll join a global Cybersecurity Operations team focused on building, operating, and continuously improving the security monitoring capabilities protecting international organizations and their technology environments.

Unlike a traditional SOC monitoring role, this position has a strong focus on SIEM administration, detection engineering, security content, data-source onboarding, use-case lifecycle management, and detection optimization.

You’ll work closely with Threat Intelligence, Incident Response, and Cybersecurity Operations teams to turn security requirements and emerging threats into effective, measurable detection capabilities.

What You’ll Do

  • Develop, implement, validate, tune, and maintain security monitoring and detection capabilities.
  • Administer and optimize SIEM platforms across multiple customer environments.
  • Manage security detection rules and use cases throughout their lifecycle.
  • Onboard, integrate, test, and validate new security data sources and telemetry feeds.
  • Review and improve detection logic, security content, and monitoring configurations.
  • Collaborate with Threat Intelligence and Incident Response teams to translate threats into actionable detection capabilities.
  • Support cybersecurity architecture reviews and provide recommendations to improve security monitoring.
  • Build and maintain security metrics, dashboards, KPIs, and service-performance reports.
  • Evaluate detection effectiveness and identify opportunities to reduce false positives.
  • Contribute to quality assurance, process reviews, control validation, and corrective actions.
  • Maintain SOC procedures, standards, documentation, knowledge bases, and operational guidance.
  • Prepare technical reports, findings, and recommendations for internal and external stakeholders., * Work beyond traditional SOC monitoring and contribute to the engineering and optimization of security detection capabilities.
  • Gain exposure to large-scale SIEM, EDR, cloud, and threat-detection environments.
  • Work directly with Threat Intelligence, Incident Response, and Cybersecurity Operations teams.
  • Help shape detection use cases, monitoring architecture, and operational processes.
  • Work on cybersecurity services supporting multiple international organizations.

Requirements

  • 5+ years of relevant IT/cybersecurity experience.
  • Proven hands-on experience administering a SIEM platform, ideally Splunk or Microsoft Sentinel.
  • Strong experience with SIEM/EDR environments and technical security analysis.
  • Deep knowledge of Microsoft Security technologies.
  • Strong cloud security knowledge across Azure, AWS, and/or GCP.
  • Experience with platforms such as Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK.
  • Experience with at least one EDR platform such as Microsoft Defender for Endpoint or CrowdStrike.
  • Knowledge of email security, network monitoring, and incident response.
  • Strong Linux, macOS, and Windows knowledge.
  • Fluent English with excellent written and verbal communication skills.

Nice to Have

  • Experience designing SIEM architecture from initial design through implementation.
  • Experience building data-ingestion pipelines for diverse cloud and on-premise log sources.
  • AWS security monitoring experience.
  • Scripting experience with Python, PowerShell, Bash, Ruby, or similar.
  • Security certifications such as SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.
  • Experience working across multiple customer environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all