> Markdown version of [/jobs/ext/3497642-security-operations-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/3497642-security-operations-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations & Incident Response Analyst - **Company:** Aleph Holding - **Location:** Madrid, Spain - **Salary:** €48,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cyber Security, Digital Forensics, Identity and Access Management, Information Technology Operations, Log Analysis, PCI Data Security Standards, Anti-Phishing, Security Information and Event Management, Software Vulnerability Management, Cyberark, Mitre Att&ck, Cyber Threat Analysis, Cybercrime, Tenable Nessus, Qualys, Vulnerability Analysis - **Published:** September 26, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0e788c29e89a0394 ## About the Role * 3-5 years in a SOC analyst, incident response, or security operations role, with at least 1-2 years at L3 level is a plus. * Experience implementing or managing IAM and PAM solutions * Experience working within international or multinational environments. * Hands-on experience with incident response engagements (internal or consulting) is strongly valued. * Relevant certifications: GCIH, GCFE, GCFA, CEH, CompTIA CySA+, or equivalent. OSCP is a plus. * Strong hands-on experience with SIEM platforms (alert triage, rule writing, query development) and EDR/XDR tools. * Solid knowledge of the MITRE ATT&CK framework and its application to threat hunting and incident response. * Experience conducting vulnerability scans using tools such as Tenable Nessus, Qualys, Rapid7, or similar. * Familiarity with IAM and PAM concepts and platforms (e.g. CyberArk, BeyondTrust, Azure PIM, or equivalent). * Experience with digital forensics and incident response (DFIR) methodologies: evidence collection, log analysis, and timeline reconstruction. * Knowledge of threat intelligence platforms and feeds (e.g. MISP, VirusTotal, threat intel feeds). * Understanding of ISO 27001 incident management controls, NIS2 incident reporting obligations, and PCI DSS requirement 12.10. * Calm and decisive under pressure. * Strong investigative mindset with structured problem-solving approach, excellent documentation skills. * Ability to communicate incident status and findings clearly to both technical teams and executive stakeholders. * Collaborative and proactive, comfortable working asynchronously across time zones. * English: full professional proficiency (C1/C2) - primary working language. Spanish: professional proficiency is a plus. ## Description Incident Response * Own and coordinate the end-to-end incident response process: identification, triage, containment, eradication, recovery, and post-incident review (lessons learned). * Serve as the primary point of contact for security incidents escalated from IT Operations, the Security Engineer, and external sources. * Maintain and continuously improve incident response playbooks for the most relevant threat scenarios (ransomware, phishing, account compromise, data breach, insider threat, etc.). * Manage the security incident log and register: track all incidents, document timelines and actions, and produce trend analysis and reporting for the CISO. * Coordinate with external SOC or MDR providers where applicable: review daily reports, validate alert quality, and manage escalation workflows. Data Breach Management * Lead data breach investigations: scope the breach, gather and preserve evidence, assess PII exposure, and coordinate response with Legal, Privacy, and HR. * Produce breach investigation reports with findings, root cause, and recommendations. Threat Hunting & Intelligence * Conduct proactive threat hunting across the environment: develop hypotheses based on threat intelligence, search for indicators of compromise (IoCs), and investigate anomalous behaviour. * Manage the Threat Intelligence function: track relevant threat actors, TTPs (MITRE ATT&CK), and sector-specific threat campaigns; integrate intelligence into SIEM/XDR detection rules and hunting queries. * Produce threat intelligence summaries and briefings for the CISO and relevant stakeholders. Vulnerability Management * Own the vulnerability management programme: schedule and execute periodic vulnerability scans across infrastructure, endpoints, and cloud environments. * Analyse scan results, prioritise findings by risk and exploitability, and coordinate remediation with IT Operations within agreed SLAs. * Track remediation progress, produce vulnerability metrics, and report status to the CISO. * Validate remediation effectiveness through re-scanning and spot-checks. Identity & Access Management (IAM) * Manage periodic access reviews: coordinate with system owners and HR to review and certify user permissions across critical systems, ensuring least privilege is maintained. * Oversee the Privileged Access Management (PAM) programme: define PAM policies, monitor privileged account usage, and review access rights for administrator-level accounts. * Investigate and respond to identity-related anomalies and access policy violations. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)