SOC Analyst

HappyRobot

Madrid

Presencial

EUR 42.000 - 64.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Healthcare, dental, vision
Equity in startup

Descripción de la vacante

HappyRobot, born in YC and backed by top investors, is hiring a SOC Analyst to own alert triage during coverage hours. You will prioritize high‑severity alerts, distinguish signal from noise, and relay clear, actionable context so engineers can act immediately.

You’ll analyze logs across cloud, identity, and endpoints, reference MITRE ATT&CK, escalate incidents with concise notes in English, and contribute to a weekly tuning loop and runbook improvements.

Formación

  • 2–3 years as a SOC analyst or in a blue team/detection role.
  • Hands-on alert triage experience with a SIEM and an EDR.
  • Log analysis across cloud, identity, and endpoint sources.
  • Working knowledge of MITRE ATT&CK and common attack patterns.
  • Clear written incident notes and escalations in English (B2+).
  • Comfortable operating on a coverage-hours rotation.

Responsabilidades

  • Alert triage: Own the queue during coverage hours and triage with SLA.
  • Log & threat analysis across cloud, identity, and endpoints.
  • Incident escalation with complete context and actionable steps.
  • Runbook discipline: follow, flag gaps, and propose fixes.
  • Tuning feedback loop: weekly input with the SOC Engineer.
  • Audit readiness: keep evidence current for SOC 2 and ISO 27001.

Conocimientos

Alert triage
SIEM & EDR
Log analysis
MITRE ATT&CK
English incident notes
Coverage-hours rotation
Cloud platforms
Python / Bash
Phishing threat analysis
Security certifications
Detection tuning
SaaS startup experience

Herramientas

SIEM
EDR

Descripción del empleo

About HappyRobot

HappyRobot is the infrastructure for enterprises to build and orchestrate AI workforces. Our AI workers don't just communicate through voice and email - they make decisions, take action, and run operations autonomously across entire enterprise systems. Born in Y Combinator (S23) and backed by a16z, Base10, Prysm Capital and Eurazeo with over $150M raised, we power critical operations for global enterprises worldwide.

Our platform is battle-tested in the most demanding environments, where AI has real consequences. We started in logistics, built our own voice stack, models, and orchestration layer from the ground up, and are now bringing that infrastructure to every enterprise that runs the real economy. Learn more about our vision in our manifesto.

Role Overview

We are looking for a SOC Analyst to join our team. You will be the consistent, accountable owner of alert triage during coverage hours - bringing the speed, rigor, and communication discipline that transforms alert handling from a best-effort scramble into a reliable, measurable function.

This is not a detection engineering or research role. Your deepest strength is triage: prioritizing fast, distinguishing signal from noise, and escalating with the context that lets engineers act immediately rather than re-investigate from scratch. That said, you operate with a continuous improvement mindset - feeding a structured tuning loop with the SOC Engineer and proposing runbook fixes when the playbook doesn't match reality.

What You'll Do

  • Alert Triage Own the queue during coverage hours. Prioritize and disposition alerts accurately and fast - high-severity alerts acknowledged within 15 minutes, all alerts dispositioned within SLA. Know the difference between a true positive and noise, and act accordingly without waiting to be told.
  • Log & Threat Analysis Pivot across cloud, identity, and endpoint log sources to build a clear timeline when an alert warrants deeper investigation. Use MITRE ATT&CK as a reference frame to understand what you're looking at and what it means in context.
  • Incident Escalation & Communication Escalate incidents with complete, actionable context - severity reasoning, timeline, affected systems, and recommended next steps. Write clearly in English. Engineers receiving your escalations should be able to act without asking follow-up questions.
  • Runbook Discipline & Improvement Follow runbooks rigorously. When a runbook falls short - wrong steps, missing cases, outdated assumptions - flag it and propose a fix. Runbooks improve because analysts use them critically, not obediently.
  • Tuning Feedback Loop Run a weekly feedback cycle with the SOC Engineer. Report false positives, patterns in noise, and cases where detection logic needs adjustment. Improve signal quality over time rather than just processing the same noise on repeat.
  • Audit Readiness Keep monitoring and response evidence current and organized for SOC 2, ISO 27001, and customer incident response commitments. Triage work that isn't documented doesn't exist for audit purposes - make sure yours does.

Must Have

  • 2-3 years as a SOC analyst or in a blue team / detection and response role.
  • Hands‑on alert triage experience with a SIEM and an EDR - investigation, disposition, and escalation.
  • Log analysis across cloud, identity, and endpoint sources.
  • Working knowledge of MITRE ATT&CK and common attack patterns.
  • Clear written incident notes and escalations in English (B2+).
  • Comfortable operating on a coverage-hours rotation.

Nice to Have

  • Cloud console familiarity with AWS, Azure, or GCP.
  • Scripting basics in Python or Bash.
  • Phishing and email threat analysis experience.
  • Certifications: BTL1, GCIH, Security+, or CySA+.
  • Exposure to detection tuning or writing simple detection rules.
  • Prior experience at a SaaS or tech startup.
Why join us?
  • Join a world-class team of engineers and builders.
  • Backed by top investors including a16z, Y Combinator, Base10, Prysm Capital and Eurazeo.
  • Have ownership and autonomy of projects and are encouraged to ship.
  • Comprehensive Benefits including healthcare, dental, vision coverage.
  • Competitive salary + equity in a high-growth startup.

Our Operating Principles

Extreme Ownership

We take full responsibility for our work, outcomes, and team success. No excuses, no blame-shifting - if something needs fixing, we own it and make it better. This means stepping up, even when it's not "your job". If a ball is dropped, we pick it up. If a customer is unhappy, we fix it. If a process is broken, we redesign it. We don’t wait for someone else to solve it - we lead with accountability and expect the same from those around us.

Craftsmanship

Putting care and intention into every task, striving for excellence, and taking deep ownership of the quality and outcome of your work. Craftsmanship means never settling for "just fine". We sweat the details because details compound. Whether it’s a product feature, an internal doc, or a sales call - we treat it as a reflection of our standards. We aim to deliver jaw-dropping customer experiences by being curious, meticulous, and proud of what we build - even when nobody’s watching.

We are majos

Be friendly & have fun with your coworkers. Always be genuine & honest, but kind. Majo is our way of saying: be a good human. Be approachable, helpful, and warm. We're building something ambitious, and it's easier (and more fun) when we enjoy the ride together. We give feedback with kindness, challenge each other with respect, and celebrate wins together without ego.

Urgency with Focus

Create the highest impact in the shortest amount of time. Move fast, but in the right direction. We operate with speed because time is our most limited resource. But speed without focus is chaos. We prioritize ruthlessly, act decisively, and stay aligned. We aim for high leverage: the biggest results from the simplest, smartest actions. We're running a high-speed marathon - not a sprint with no strategy.

Talent Density and Meritocracy

Hire only people who can raise the average; 'exceptional performance is the passing grade.' Ability trumps seniority. We believe the best teams are built on talent density - every hire should raise the bar. We reward contribution, not titles or tenure. We give ownership to those who earn it, and we all hold each other to a high standard. A-players want to work with other A-players - that's how we win.

First-Principles Thinking

Strip a problem to physics-level facts, ignore industry dogma, rebuild the solution from scratch. We don't copy-paste solutions. We go back to basics, ask why things are the way they are, and rebuild from the ground up if needed. This mindset pushes us to innovate, challenge stale assumptions, and move faster than incumbents. It's how we build what others think is impossible.

The personal data provided in your application and during the selection process will be processed by Happyrobot, Inc., acting as Data Controller.

By sending us your CV, you consent to the processing of your personal data for the purpose of evaluating and selecting you as a candidate for the position. Your personal data will be treated confidentially and will only be used for the recruitment process of the selected job offer.

In relation to the period of conservation of your personal data, these will be eliminated after three months of inactivity in compliance with the GDPR and legislation on the protection of personal data.

If you wish to exercise your rights of access, rectification, deletion, portability or opposition in relation to your personal data, you can do so through security@happyrobot.ai subject to the GDPR.

For more information, visit https://www.happyrobot.ai/privacy-policy

By submitting your request, you confirm that you have read and understood this clause and that you agree to the processing of your personal data as described.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

SOC Analyst
SOC Analyst

HappyRobot • Barcelona

Presencial
EUR 42.000 - 64.000
Healthcare
Dental
Vision
+1
SOC Analyst
SOC Analyst

Happyrobot Inc. • Bellprat

Presencial
EUR 36.000 - 60.000
Healthcare coverage
Dental coverage
Vision coverage
SOC Engineer
SOC Engineer

HappyRobot • Madrid

Presencial
EUR 60.000 - 90.000
Healthcare coverage
Dental and vision insurance
Equity in startup
+1
SOC Engineer
SOC Engineer

HappyRobot • Barcelona

Presencial
EUR 60.000 - 90.000
Healthcare
Dental coverage
Vision coverage
Data Scientist
Data Scientist

HappyRobot • Barcelona

Presencial
EUR 60.000 - 90.000
Healthcare coverage
Equity compensation
Cloud Security Engineer
Cloud Security Engineer

Happyrobot Inc. • Bellprat

Presencial
EUR 90.000 - 130.000
Healthcare coverage
Dental coverage
Vision coverage
+1
Cloud Security Engineer
Cloud Security Engineer

HappyRobot • Barcelona

Presencial
EUR 70.000 - 110.000
Healthcare coverage
Dental coverage
Vision coverage
+1
Data Scientist
Data Scientist

Happyrobot Inc. • Barcelona

Presencial
EUR 55.000 - 75.000
Healthcare
Equity
Dental & Vision
Data Scientist
Data Scientist

Happyrobot Inc. • Bellprat

Presencial
EUR 65.000 - 90.000
Cloud Security Engineer
Cloud Security Engineer

HappyRobot • Madrid

Presencial
EUR 70.000 - 110.000
Healthcare coverage
Dental coverage
Vision coverage
+1