> Markdown version of [/jobs/ext/3488658-security-incident-handler](https://www.wearedevelopers.com/jobs/ext/3488658-security-incident-handler). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Incident Handler - **Company:** Liebherr - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Cyber Security, Mitre Att&ck, Information Technology, Cybercrime - **Published:** September 8, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role Bachelor's/Master's in Cybersecurity, Computer Science, or related field. 7+ years of operational experience in SOC environments (L2/L3, threat hunting, incident response, service delivery, operational delivery). Exposure to global organizations and distributed security functions. Knowledge of modern security frameworks (MITRE ATT&CK, NIST CSF, ISO *****). Experience implementing KPIs and running continual service improvement processes. Relevant certifications (e.g., CISSP, GCIH, CCSP, GCIA, GMON) are a plus, but not mandatory. Fluency in English (written and spoken). Willingness and ability to travel to Liebherr sites worldwide up to 10% of the time. ## Description We are expanding our Global Corporate Information Security team and are looking for a Security Monitoring & Incident Response Product Owner (m/f/d) to establish and scale our global security operations. The Security Monitoring & Incident Response Product Owner is responsible for driving the operational excellence, implementing the strategic evolution, and service quality of our global Security Operations Center (SOC). The Security Monitoring & Incident Response Product Owner serves as the central orchestrator between internal SOC team members, the MSSP, technology teams, and the Head of Global SOC - ensuring that the SOC delivers reliable, high quality security monitoring and continuously improves its maturity, coverage, and effectiveness. The working location for this position will be in Madrid city, where we operate a hybrid model, requiring at least 40% of the working time on-site. Creating passion: your responsibilities SOC Operations & Service Management Own the end-to-end operations of the global SOC, ensuring effective collaboration between internal analysts and the MSSP (L1/L2). Monitor, manage, and optimize processes, including alert triage, escalation flows, and incident response handovers. Ensure all services related to Security Monitoring and Incident Response to perform against defined SLAs and KPIs, and drive actions when service quality deviates. Implement the SOC "product" roadmap related to Security Monitoring & Incident Response, including implementation of the strategic vision, backlog, and prioritization of improvements. Vendor & MSSP Management Act as the primary liaison between the organization and the MSSP to deliver SOC services. Conduct recurring service governance meetings (operational and tactical). Track and validate MSSP deliverables, including detection operations, case handling quality, and runbook adherence. Coordinate improvements to MSSP workflows, communication channels, and response processes. Incident Response Alignment Align with the internal incident response team to ensure seamless escalation. Support the refinement of incident response procedures, playbooks, and communication guidelines. Ensure major incidents are appropriately handled, documented, and followed by lessons learned sessions. Guide the continuous evolution of incident management maturity and readiness. Governance, Compliance & Documentation Maintain alignment with internal security frameworks, standards, and regulatory requirements. Produce regular reports on operational performance, risks, coverage, and incident trends. Ensure processes, runbooks, service definitions, and operating procedures are consistently documented and kept up to date. Support audits, assessments, and readiness activities related to detection and response. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany)