> Markdown version of [/jobs/ext/3436299-security-analyst-level-1](https://www.wearedevelopers.com/jobs/ext/3436299-security-analyst-level-1). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst Level 1 - **Company:** Kudelski Security - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Software Documentation, CompTIA Security+, Cyber Security, Linux, Issue Tracking Systems, Information Technology Operations, Intrusion Detection Systems, Log Analysis, Security Information and Event Management, TCP/IP, Mitre Att&ck, Data Management - **Published:** September 1, 2026 - **Apply:** https://www.jobleads.com/es/job/eb11c868fd6971a3a8016b9141f399f4b ## About the Role * A team-oriented analyst comfortable working in a structured, high-tempo SOC environment. * Methodical and detail-oriented, able to remain calm under pressure and manage multiple alerts in parallel. * Curious and motivated to learn cybersecurity operations and modern SOC tooling. * Clear and professional in written and verbal communication. * Willing to work in a 24/7 shift-based operation., * More than 1 year of experience in cybersecurity, IT operations, or a related field (internships, labs, or SOC trainings), typically analyzing logs and host data to identify suspicious/abnormal activity. * Initial to intermediate exposure to SIEM and/or EDR/XDR platforms for log analysis and detection. * Understanding of TCP/IP, security architecture, adversary TTPs, common web attacks, and the MITRE ATT&CK framework. * Familiarity with incident response methodologies (NIST/SANS) and fundamentals in networking and operating systems (Windows/Linux). * Understanding of appropriate AI usage in security contexts. * Basic knowledge of OT and its core concepts. * Strong verbal and written communication skills for documenting findings, escalating incidents, and collaborating with customers. * Fluent in English and Spanish (written and verbal). * Nice to have: CompTIA Security+, CySA+, CEH, or BTL1 (or actively pursuing). ## Description As a Security Analyst Level 1, you are the first line of defense within our 24x7 Managed Detection & Response (MDR) operations, part of the Cyber Fusion Center (CFC) / SOC. Your mission is to monitor, triage, and validate security alerts, ensuring timely escalation of confirmed threats while maintaining high operational quality across a multi-client SOC environment., You will operate within clearly defined procedures, using modern security tooling and AI-assisted workflows to improve investigation efficiency, documentation quality, and learning velocity-while adhering strictly to escalation paths, data-handling rules, and security policies. You are based in Madrid, Spain, working a 24/7 shift rotation (morning, evening, night, and weekends) in a permanent, full-time role, reporting to the SOC Manager within a team of 15-20 L1 Analysts., Your responsibilities will be: * General responsibilities * Monitor and triage security alerts generated by SIEM, EDR/XDR, firewalls, IC/OT, and other security technologies to determine if further investigation or customer action is warranted. * Perform first-level incident analysis, validation, and classification following SOPs and playbooks. * Escalate confirmed, suspicious, or complex incidents to Tier 2 with clear, structured, and complete documentation (what happened, evidence, scope, actions taken, recommended next steps). * Respond to alerts and tickets within defined SLAs and document all investigation steps accurately in the ticketing system. * Adhere to internal policies, procedures, and security best practices to protect customer and company data. * Participate in shift handovers, ensuring continuity of investigations and clear ownership of next actions. * Contribute to customer satisfaction by handling customer interactions professionally, communicating critical findings, providing accurate information, and ensuring requests are routed to the appropriate teams for timely resolution and support. * Maintain strong operational discipline: correct priority, categorization, and documentation standards. * Threat monitoring & incident handling * Validate alert fidelity by reviewing available telemetry, context, and enrichment to separate false positives from true security events. * Perform initial scoping (impacted host/user, time window, key indicators, related alerts) using approved tools and data sources. * Apply predefined containment or response actions only when explicitly authorized by procedures and customer runbooks. * Collect and preserve relevant artifacts (e.g., alert context, event IDs, process names, hashes, IPs/domains) to support Tier 2 investigations. * Support ongoing investigations by providing timely updates and evidence to senior analysts. * Use approved AI tools to summarize alerts, logs, and timelines to accelerate triage. * Use AI-assisted enrichment to understand unfamiliar indicators, techniques, or tool outputs. * Identify recurring false positives, noisy detections, and tooling limitations; raise improvement suggestions through defined channels.