Security Operations Analyst (SIEM)

United ITS

Valencia

Híbrido

EUR 42.000 - 66.000

Jornada completa

hace 11 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Destaca en este puesto — crea un currículum adaptado y una carta de presentación en aproximadamente un minuto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Remote option
Teleworking 4 days/week Valencia

Descripción de la vacante

United ITS is seeking a skilled SOC professional to contribute to the development, validation, and tuning of security monitoring across SIEM, EDR, and cloud platforms. You will support operations and collaborate with IR teams to enhance detection capabilities.

Ideal candidates have 5+ years in IT security, hands-on SIEM experience (Splunk or MS Sentinel), and strong knowledge of Microsoft security tools and cloud technologies. Remote-friendly with Valencia base and 4 days/week telework option.

Formación

  • Minimum 5 years in IT with alert triage and security incidents support.
  • Experience administering SIEM platforms (Splunk or Microsoft Sentinel).
  • Proficient with SOC toolset (SIEMs, EDRs) and collaborating with IR teams.
  • Deep knowledge of Microsoft security tools (M365, Defender, Azure, Sentinel).
  • Cloud tech knowledge across Azure, AWS, GCP.
  • Knowledge of SIEMs: Splunk, QRadar, ArcSight, MS Sentinel, ELK stack.
  • Experience with email security, network monitoring, and incident response.
  • Proficiency with Linux, Mac, and Windows environments.
  • Excellent English written and spoken.

Responsabilidades

  • Contribute to development, implementation, validation, tuning, and maintenance of security monitoring and detection capabilities.
  • Support operation, maintenance, optimization, and improvement of security monitoring and threat detection services.
  • Participate in onboarding, integration, testing, and validation of security data sources and telemetry feeds.
  • Contribute to content management: use case lifecycle, rules reviews, testing and tuning.
  • Collaborate with threat intelligence, IR, and SOC teams to translate requirements into detections.
  • Assist in cybersecurity architecture reviews and recommendations for monitoring effectiveness.
  • Prepare and maintain security metrics, dashboards, and service reports.
  • Review detections, configurations, and processes; identify improvements.
  • Gather operational feedback to reduce false positives and improve detection quality.
  • Contribute to CSOC procedures, documentation, and knowledge base materials.
  • Prepare technical reports and recommendations for stakeholders.

Conocimientos

SIEM administration
Threat detection
EDR tools
Cloud security
Microsoft security tools
Azure/AWS/GCP
SIEM tools (Splunk)
Email security
Network monitoring
Linux/Mac/Windows
English proficiency

Herramientas

Splunk
Microsoft Sentinel
QRadar
ArcSight
ELK Stack
MS Defender for Endpoint
Azure
AWS
GCP

Descripción del empleo

Full Time | Valencia, Spain or Remote on EMEA (CET +/-2 hours)

Location: Valencia, Spain or Remote on EMEA (CET +/-2 hours)

Teleworking option: Yes

Required Technical Skills

SCOPE OF WORK:

  • Contribute to the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
  • Support the operation, maintenance, optimization, and continuous improvement of security monitoring and threat detection services.
  • Participate in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities.
  • Contribute to security content management activities, including use case lifecycle management, rule reviews, testing, tuning, and content quality assurance.
  • Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities.
  • Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and provide recommendations to enhance security monitoring and detection effectiveness.
  • Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs, and service performance reports.
  • Review, validate, and assess the effectiveness of detections, monitoring configurations, operational processes, and service deliverables, identifying opportunities for improvement.
  • Gather and analyze operational feedback to identify opportunities for tuning, optimization, reduction of false positives, and improvement of overall detection quality.
  • Contribute to quality assurance activities, including process reviews, control validation, service quality assessments, and implementation of corrective actions.
  • Support the development, review, and maintenance of CSOC procedures, standards, documentation, knowledge base articles, and operational guidance materials.
  • Prepare and present technical reports, summaries, findings, and recommendations to internal and external stakeholders.
  • Provide other ad hoc support as required

The resource MUST have the following skills and experience:

  • A minimum of five (5) years of relevant experience in information technology field, including triage of alerts and supporting security incidents.
  • Proven experience on administering a SIEM platform, preferably either Splunk or Microsoft Sentinel SIEM.
  • Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs) and being able to autonomously perform technical analysis of security threats and collaborate with Incident Response team
  • Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR
  • Deep Knowledge of Cloud technologies (e.g. Azure, AWS and GCP)
  • Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack
  • Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)
  • Knowledge of email security, network monitoring, and incident response
  • Knowledge of Linux/Mac/Windows
  • Expert knowledge of English, both written and spoken, is required

The resource SHOULD have the following skills and experience:

  • Experience in building SIEM architectures from initial design to implementation, including designing data ingestion pipelines for diverse log sources across cloud and on-prem environments
  • Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)
  • Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.)
  • Excellent communication skills
  • Customer-facing experience and oral communication skills
  • Ability to write documentation & reports
  • Creativity/ability to find innovative solutions
  • Willingness to learn on the job
  • Conflict management & cooperation

Desirable certifications:

  • Technical certifications: MCSE, CCNA, Microsoft Azure (e.g., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification
  • Relevant industry certifications

Teleworking Option:

  • Yes, up to 4 days per week for consultants working from Valencia
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Security Operations Analyst (SIEM & Threat Detection)
Security Operations Analyst (SIEM & Threat Detection)

Pragmatike • Elche

Híbrido
EUR 70.000 - 100.000
Security Operations Analyst (SIEM & Threat Detection)
Security Operations Analyst (SIEM & Threat Detection)

Pragmatike • Madrid

Híbrido
EUR 42.000 - 64.000
Security Operations Analyst (SIEM & Threat Detection)
Security Operations Analyst (SIEM & Threat Detection)

Pragmatike • Valencia

Híbrido
EUR 70.000 - 100.000
Security Operations Analyst – SIEM & Threat Detection
Security Operations Analyst – SIEM & Threat Detection

QCS Staffing Ltd • Valencia

Presencial
EUR 42.000 - 64.000
Security Operations Analyst (SIEM & Threat Detection)
Security Operations Analyst (SIEM & Threat Detection)

Pragmatike • España

Híbrido
EUR 52.000 - 70.000
Senior SIEM Security Operations Analyst (Remote)
Senior SIEM Security Operations Analyst (Remote)

United ITS • Valencia

Híbrido
EUR 42.000 - 66.000
Remote option
Teleworking 4 days/week Valencia
Security Operations Analyst (SIEM Operations and Threat Detection)
Security Operations Analyst (SIEM Operations and Threat Detection)

Talan • València d'Àneu

A distancia
EUR 70.000 - 95.000
Remote position
Full-time contract
Career development
+1
Security Operations Analyst - Defence Operations
Security Operations Analyst - Defence Operations

QCS Staffing Ltd • Valencia

Presencial
EUR 40.000 - 60.000
Security Operations Analyst (Cyber Defense Operations)
Security Operations Analyst (Cyber Defense Operations)

Pragmatike • Valencia

Híbrido
EUR 45.000 - 65.000
Security Operations Analyst (Cyber Defense Operations)
Security Operations Analyst (Cyber Defense Operations)

Pragmatike • Elche

Híbrido
EUR 45.000 - 67.000