Security Operations Analyst

United ITS

Valencia

A distancia

EUR 45.000 - 65.000

Jornada completa

hace 25 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Transforma esta oferta en una entrevista — un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Descripción de la vacante

United ITS is seeking an experienced Security Operations Center (SOC) analyst to monitor, triage, and investigate alerts across Microsoft security tools, AWS, SIEMs, and EDRs. Based in Valencia, Spain, or remote, you will analyze network and host logs and support incident response efforts.

You will collect client information, prepare security reports, and help improve CSOC processes, procedures, and knowledge bases.

Formación

  • Minimum five years in IT/security including alert triage and incident support.
  • Proven experience with SOC toolbox: SIEMs, EDRs, and ticketing systems.
  • Expert knowledge of Windows, Linux, DB, app, and web server log analysis.
  • Knowledge of TCP/IP protocols.
  • Strong written and spoken English.

Responsabilidades

  • Monitor, triage, and investigate alerts across security tools, AWS, SIEMs, and EDRs.
  • Analyze network and host logs to determine remediation and escalation.
  • Identify root causes and support incident response.
  • Prepare and present security reports and findings to clients.
  • Improve CSOC processes, documentation, and knowledge bases.
  • Gather client information to tune whitelists and reduce false positives.

Conocimientos

SOC analysis
Incident response
Windows/Linux log analysis
English fluency
SIEM tools
EDR tools
TCP/IP networking
Cloud security (Azure/AWS)

Herramientas

Splunk
QRadar
ArcSight
MS Sentinel
ELK Stack
Azure Defender/Defender for Endpoint
CrowdStrike

Descripción del empleo

Full Time | Valencia, Spain or Remote (CET, LATAM, or IST time zones)

Location: Valencia, Spain or remote (EMEA, LATAM, or IST)

Teleworking option: Yes

Required Technical Skills

SCOPE OF WORK:

  • Monitor, triage, and investigate alerts across Microsoft security tools, AWS, SIEM platforms, and EDR solutions
  • Analyze network and host-based logs (firewalls, NIDS/HIDS, syslog, etc.) to determine appropriate remediation and escalation
  • Identify root causes, direct remediation and recovery actions, and support incident response efforts
  • Follow structured analytical processes and collaborate with other analysts and teams to ensure effective threat management
  • Prepare and present security reports, summaries, and findings to clients
  • Contribute to the improvement of CSOC processes and procedures, including quality control procedures, documentation and knowledge base updates
  • Gather the necessary information from the client to identify opportunities for whitelist tuning and optimization to reduce false positives and enhance detection quality
  • Reviewing feedback and implementing corrective actions to maintain service excellence
  • Provide other ad hoc support as required

The resource MUST have the following skills and experience:

  • A minimum of five (5) years of relevant experience in information technology field, including triage of alerts and supporting security incidents
  • Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs), able to autonomously perform technical analysis of security threats and collaborate with Incident Response team
  • Trouble ticket generation and processing experience
  • Expert knowledge of Windows, Linux, Database, Application, Web server, etc. log analysis
  • Knowledge of Transmission Control Protocol / Internet Protocol (TCP/IP) protocols
  • Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR)
  • Deep knowledge of Cloud technologies (e.g. Azure, AWS and GCP)
  • Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack
  • Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)
  • Knowledge of email security, network monitoring, and incident response
  • Knowledge of Linux/Mac/Windows
  • Expert knowledge of English, both written and spoken, is required

The resource SHOULD have the following skills and experience:

  • Experience on an Incident Response team performing Tier I/II initial incident triage.
  • Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)
  • Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.)
  • Excellent communication skills
  • Customer-facing experience and oral communication skills
  • Ability to write documentation & reports
  • Creativity/ ability to find innovative solutions
  • Willingness to learn on the job
  • Conflict management & cooperation

Desirable certifications:

  • Technical certifications: MCSE, CCNA, Microsoft Azure (e.g., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification
  • Relevant industry certifications
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Security Operations Analyst (SIEM)
Security Operations Analyst (SIEM)

United ITS • Valencia

Híbrido
EUR 42.000 - 66.000
Remote option
Teleworking 4 days/week Valencia
Security Operations Analyst (Cyber Defense Operations)
Security Operations Analyst (Cyber Defense Operations)

Pragmatike • Valencia

Híbrido
EUR 45.000 - 65.000
Security Operations Analyst (Cyber Defense Operations)
Security Operations Analyst (Cyber Defense Operations)

Pragmatike • Elche

Híbrido
EUR 45.000 - 67.000
Security Operations Analyst — Remote/Valencia
Security Operations Analyst — Remote/Valencia

United ITS • Valencia

A distancia
EUR 45.000 - 65.000
Security Operations Analyst (Cyber Defense Operations)
Security Operations Analyst (Cyber Defense Operations)

Pragmatike • España

Híbrido
EUR 42.000 - 62.000
Security Operations Analyst - Defence Operations
Security Operations Analyst - Defence Operations

QCS Staffing Ltd • Valencia

Presencial
EUR 40.000 - 60.000
IT Security Analyst
IT Security Analyst

Signode • Bellprat

Presencial
EUR 38.000 - 54.000
IT Security Analyst
IT Security Analyst

Signode • España

Presencial
EUR 35.000 - 52.000
Security Operations Analyst (SIEM & Threat Detection)
Security Operations Analyst (SIEM & Threat Detection)

Pragmatike • Valencia

Híbrido
EUR 70.000 - 100.000
Security Operations Analyst (SIEM & Threat Detection)
Security Operations Analyst (SIEM & Threat Detection)

Pragmatike • Elche

Híbrido
EUR 70.000 - 100.000