SIEM Analyst

Fosh

Madrid

Presencial

EUR 40.000 - 65.000

Jornada completa

Hace 9 días
Generador de candidaturas

Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Descripción de la vacante

FoshTech is seeking an experienced SIEM/Log Analysis specialist to collect, normalize, and analyze security logs from diverse sources. You will develop dashboards, alerts, and use SIEM platforms to detect threats, investigate incidents, and conduct forensic analysis.

Collaboration with the Information Security Team and ongoing detection improvement are essential. Ideal candidates have 3+ years in SIEM/log operations, strong Splunk and CrowdStrike experience, and a solid foundation in networking

Formación

  • Studies in computer science, telecommunications, cybersecurity, or related fields.
  • Minimum 3 years in SIEM operations, log analysis, or security monitoring.
  • Experience collecting logs from endpoints, networks, servers, and cloud services.
  • 2+ years with Splunk and CrowdStrike required.
  • Experience with FortiAnalyzer, New Relic, ManageEngine AD Audit, Axonius, or similar.
  • Dashboard creation, visualization, and reporting from log data.
  • Experience in defining and tuning alerts and correlation rules.

Responsabilidades

  • Design, implement, and maintain log collection pipelines from multiple sources.
  • Ensure logs are ingested, parsed, normalized, and retained across SIEM platforms.
  • Maintain data quality and consistency across log sources.
  • Design and maintain dashboards and visualizations for security posture and metrics.
  • Create, tune, and maintain correlation rules and alerts (IOCs, attack patterns, anomalies).
  • Support incident response and forensic investigations through log analysis.
  • Collaborate with SOC Analysts, Dev Security, IAM and Threat Hunting teams.
  • Document procedures and ensure timely, traceable reporting via tickets (Jira).
  • Share knowledge to improve detection capabilities and maintain training.

Conocimientos

SIEM operations
Log analysis
Threat hunting
Dashboard creation
Alert tuning
SPL/KQL/SQL-like queries
Regex
YARA rules
Documentation
Incident response support

Educación

CS/telecommunications/cybersecurity studies

Herramientas

Splunk
CrowdStrike
FortiAnalyzer
New Relic
ManageEngine AD Audit
Axonius

Descripción del empleo

Our mission

We are a cutting-edge e-commerce company developing products for our technological platform. Our creative, smart, dedicated teams pool their knowledge and experience to deliver the best solutions to meet project needs while maintaining sustainable, long-lasting results. How? By making sure that our teams thrive and develop professionally. Strong advocates of hiring top talent and letting them do what they do best, we strive to create a workplace that allows for an open, collaborative, and respectful culture


The Role

You will be responsible for collecting, normalizing, analyzing, and exploiting security logs from multiple sources across the organization, ensuring they are ingested into SIEM platforms and used to detect threats, anomalies, and security incidents. You will play a key role in threat detection, incident investigation, and forensic analysis by transforming raw logs into actionable insights through dashboards, alerts, and advanced log analysis.

Key Responsibilities:
  • Design, implement, and maintain log collection pipelines from multiple sources, including security, infrastructure, cloud, and application systems.
  • Ensure logs are ingested, parsed, normalized, and retained correctly across SIEM platforms such as FortiAnalyzer, Splunk, CrowdStrike, and others.
  • Maintain data quality and consistency across all log sources.
  • Design, build, and maintain dashboards and visualizations to provide visibility into security posture, threats, and operational metrics.
  • Create, tune, and maintain correlation rules and alerts based on:
    • Attack patterns
    • Indicators of compromise (IOCs)
    • Behavioral anomalies
  • Custom detection use cases defined by the Information Security Team
  • Continuously analyze logs to identify suspicious, anomalous, or out-of-the-ordinary behavior.
  • Proactively hunt for threats by performing advanced log searches and pattern analysis.
  • Support incident response and forensic investigations by:
    • Searching historical logs
    • Reconstructing attack timelines
    • Identifying entry points, lateral movement, and attacker activity
  • Collaborate with SOC Analysts, Dev Security, IAM, Threat Hunting, and other security roles during incident investigation and response.
  • Validate alerts and detections to reduce false positives and improve detection quality.
  • Ensure all detections, investigations, and findings are properly documented and tracked via tickets (Jira).
  • Document new procedures or update existing ones for log management, detection, and investigation.
  • Ensure documentation is accurate, comprehensive, and delivered on time.
  • Create reports based on SIEM data for operational, technical, and management audiences.
  • Engage in ongoing training and professional development to stay current with emerging threats, attack techniques, and detection strategies.
  • Share knowledge and expertise with the team to foster a culture of security awareness and continuous improvement.
  • Adhere to the organization's different policies.
  • Keep your work organized and traceable through tickets (Jira).
Knowledge and skills you need to have
  • Studies in computer science, telecommunications, cybersecurity, or other related academic fields.
  • At least 3 years of work experience in SIEM operations, log analysis, or security monitoring roles.
  • Hands-on experience collecting and managing logs from multiple sources (endpoints, network devices, servers, cloud services, applications, authentication systems, etc.).
  • At least 2 years of experience with Splunk is required (by operating and configuring rules and settings).
  • At least 2 years of experience working with CrowdStrike is required.
  • Experience working with other SIEM and log platforms such as FortiAnalyzer, New Relic, ManageEngine AD Audit, Axonius, or similar.
  • Experience creating dashboards, visualizations, and reports based on log data.
  • Experience in defining and tuning alerts and correlation rules.
  • Knowledge of scripting or query languages used in SIEM platforms (e.g., SPL, KQL, SQL-like queries).
  • YARA rules.
  • Regular expressions (regex).
  • Familiarity with security tools generating logs, such as firewalls, EDR, IAM, cloud platforms, and application security tools.
  • Strong analytical mindset with the ability to identify patterns and anomalies in large datasets.
  • Experience supporting incident response and forensic investigations through log analysis.
  • Ability to work independently and as part of the Information Security Team under minimal supervision.
  • Eager to learn and continuously improve detection capabilities.
  • Strong documentation and reporting skills.
Technical skills:
  • Solid foundations in networking, operating systems, authentication flows, and cybersecurity.
  • Ability to understand how logs reflect system and user behavior across different platforms.
Additional requirements, not essential but "nice to have":
  • Any cybersecurity certification.
  • Experience with log normalization standards and detection methodologies.
  • Familiarity with MITRE ATT&CK and threat detection frameworks.
  • Experience with threat hunting activities.
  • Familiarity with forensic analysis concepts and incident response workflow

Why work at FoshTech?
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

SIEM Analyst
SIEM Analyst

Fosh • Comunidad de Madrid

Presencial
EUR 60.000 - 90.000
Siem Analyst
Siem Analyst

Novcom • Madrid

Presencial
EUR 55.000 - 75.000
SIEM Analyst – Threat Detection & Incident Response
SIEM Analyst – Threat Detection & Incident Response

Fosh • Madrid

Presencial
EUR 40.000 - 65.000
Senior SIEM Analyst & Threat Hunter
Senior SIEM Analyst & Threat Hunter

Fosh • Comunidad de Madrid

Presencial
EUR 60.000 - 90.000
Senior Security Engineer (SIEM) - RDT Security Platforms
Senior Security Engineer (SIEM) - RDT Security Platforms

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 90.000 - 140.000
Principal Security Engineer, Detection
Principal Security Engineer, Detection

Jobtailor • Madrid

Presencial
EUR 90.000 - 120.000
IT Security Analyst
IT Security Analyst

Signode • Bellprat

Presencial
EUR 38.000 - 54.000
Security Engineer (Infrastructure) - ESK Agency
Security Engineer (Infrastructure) - ESK Agency

hiring • Málaga

Presencial
EUR 50.000 - 80.000
Arquitecto de Plataforma de Detección y Respuesta, IA
Arquitecto de Plataforma de Detección y Respuesta, IA

Jobtailor • Madrid

Presencial
EUR 70.000 - 110.000
Security Engineer (Infrastructure)
Security Engineer (Infrastructure)

Hiring • Málaga

Presencial
EUR 45.000 - 65.000