SOC Engineer

HappyRobot

Madrid

Presencial

EUR 60.000 - 90.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Healthcare coverage
Dental and vision insurance
Equity in startup
Ownership of projects

Descripción de la vacante

HappyRobot is seeking a SOC Engineer to build detection and response capabilities across cloud and identity stacks. You will design high-signal detections mapped to MITRE ATT&CK, tune false positives, and own the log pipeline end-to-end from data sources like CloudTrail and Okta.

You’ll investigate alerts, write runbooks, automate repetitive tasks in Python or Go, and help shape a scalable SOC foundation for future hybrid models.

Formación

  • 3–5 years in detection engineering, SOC engineering, or blue team roles.
  • Hands-on experience building detections in a modern SIEM — RunReveal, Panther, Elastic, Splunk, Sentinel, or similar — not just operating one.
  • Deep familiarity with cloud and identity log sources: CloudTrail, GuardDuty, Kubernetes audit logs, IdP/Okta logs.
  • Scripting and automation proficiency in Python or Go.
  • Experience mapping detections to MITRE ATT&CK.
  • English B2+ (professional working proficiency).

Responsabilidades

  • Design, write, and tune detections mapped to MITRE ATT&CK.
  • Onboard, parse, and normalize log sources into the SIEM.
  • Investigate alerts end-to-end and document triage decisions.
  • Automate repetitive SOC tasks with Python or Go.
  • Write triage runbooks for high/critical alerts.
  • Build the monitoring foundation to enable a future SOC model.

Conocimientos

Detection engineering
SOC engineering
Blue team
MITRE ATT&CK mapping
Python or Go scripting
Cloud & identity logs

Herramientas

RunReveal
Panther
Elastic
Splunk
Sentinel

Descripción del empleo

About HappyRobot

HappyRobot is the infrastructure for enterprises to build and orchestrate AI workforces. Our AI workers don't just communicate through voice and email - they make decisions, take action, and run operations autonomously across entire enterprise systems. Born in Y Combinator (S23) and backed by a16z, Base10, Prysm Capital and Eurazeo with over $150M raised, we power critical operations for global enterprises worldwide.

Our platform is battle-tested in the most demanding environments, where AI has real consequences. We started in logistics, built our own voice stack, models, and orchestration layer from the ground up, and are now bringing that infrastructure to every enterprise that runs the real economy. Learn more about our vision in our manifesto.

Role Overview

We are looking for a SOC Engineer to join our team. You will build and own our detection and response capability from the ground up — bringing the engineering depth and operational discipline to establish real monitoring across our cloud and identity stack, reduce mean-time-to-detect on security events, and set a foundation that scales into whatever SOC model we choose.

This is not an analyst role. Your deepest strength is detection engineering: designing high-signal detections mapped to ATT&CK, managing the tuning loop that keeps false positive rates in check, and building the log pipeline that makes everything else possible. That said, you operate end-to-end — you investigate alerts yourself, write runbooks an analyst can execute without hand-holding, and automate the repetitive work out of existence.

What You'll Do

  • Detection Engineering Design, write, and tune detections mapped to MITRE ATT&CK techniques. Own the false-positive loop — track noise per detection, tune aggressively, and grow coverage across prioritized techniques quarter over quarter. Detections should be high-signal from the start, not high-volume problems to manage later.

  • Log Pipeline Engineering Onboard, parse, and normalize log sources into the SIEM reliably. Get all tier-1 sources live within the first two quarters and keep the pipeline clean as new sources are added. Deep familiarity with cloud and identity logs — CloudTrail, GuardDuty, Kubernetes audit logs, Okta — is the foundation this work is built on.

  • Incident Triage & Response Investigate alerts end-to-end. Escalate with clear severity reasoning, complete timeline, and actionable context. Don't hand off half-investigated alerts — own the triage process through to a clear disposition.

  • Automation Script enrichment, response actions, and repetitive SOC tasks in Python or Go. If something is done manually more than twice, it should be automated. Reduce toil systematically rather than absorbing it.

  • Runbooks & Documentation Write triage runbooks for all high and critical alert types — documented well enough that an analyst can execute them without asking for clarification. Keep runbooks current as detections and infrastructure evolve.

  • SOC Foundation Build the monitoring capability that positions us to make an informed in-house vs. hybrid SOC decision by end of September. The architecture, coverage, and process you establish now directly shapes what that model looks like.

Must Have

  • 3–5 years in detection engineering, SOC engineering, or blue team roles.

  • Hands-on experience building detections in a modern SIEM — RunReveal, Panther, Elastic, Splunk, Sentinel, or similar — not just operating one.

  • Deep familiarity with cloud and identity log sources: CloudTrail, GuardDuty, Kubernetes audit logs, and IdP/Okta logs.

  • Scripting and automation proficiency in Python or Go.

  • Experience mapping detections to MITRE ATT&CK.

  • English B2+ (professional working proficiency).

Nice to Have

  • Detections-as-code with detection content managed in Git and deployed via CI/CD.

  • EDR experience with SentinelOne or CrowdStrike.

  • Incident response experience beyond triage.

  • CNAPP exposure (Wiz or similar) and cloud security fundamentals.

  • Certifications: GCIA, GCDA, GCIH, or BTL2.

  • Prior experience at a SaaS or tech startup building monitoring from scratch.

Why join us?
  • Join a world-class team of engineers and builders.

  • Backed by top investors including a16z, Y Combinator, Base10, Prysm Capital and Eurazeo.

  • Have ownership and autonomy of projects and are encouraged to ship.

  • Comprehensive Benefits including healthcare, dental, vision coverage.

  • Competitive salary + equity in a high-growth startup.

Our Operating Principles

Extreme Ownership

We take full responsibility for our work, outcomes, and team success. No excuses, no blame-shifting — if something needs fixing, we own it and make it better. This means stepping up, even when it’s not “your job.” If a ball is dropped, we pick it up. If a customer is unhappy, we fix it. If a process is broken, we redesign it. We don’t wait for someone else to solve it — we lead with accountability and expect the same from those around us.

Craftsmanship

Putting care and intention into every task, striving for excellence, and taking deep ownership of the quality and outcome of your work. Craftsmanship means never settling for “just fine.” We sweat the details because details compound. Whether it’s a product feature, an internal doc, or a sales call — we treat it as a reflection of our standards. We aim to deliver jaw-dropping customer experiences by being curious, meticulous, and proud of what we build — even when nobody’s watching.

We are “majos”
Be friendly & have fun with your coworkers. Always be genuine & honest, but kind. “Majo” is our way of saying: be a good human. Be approachable, helpful, and warm. We’re building something ambitious, and it’s easier (and more fun) when we enjoy the ride together. We give feedback with kindness, challenge each other with respect, and celebrate wins together without ego.

Urgency with Focus
Create the highest impact in the shortest amount of time. Move fast, but in the right direction. We operate with speed because time is our most limited resource. But speed without focus is chaos. We prioritize ruthlessly, act decisively, and stay aligned. We aim for high leverage: the biggest results from the simplest, smartest actions. We’re running a high-speed marathon — not a sprint with no strategy.

Talent Density and Meritocracy
Hire only people who can raise the average; ‘exceptional performance is the passing grade.’ Ability trumps seniority. We believe the best teams are built on talent density — every hire should raise the bar. We reward contribution, not titles or tenure. We give ownership to those who earn it, and we all hold each other to a high standard. A-players want to work with other A-players — that’s how we win.

First-Principles Thinking
Strip a problem to physics-level facts, ignore industry dogma, rebuild the solution from scratch. We don’t copy-paste solutions. We go back to basics, ask why things are the way they are, and rebuild from the ground up if needed. This mindset pushes us to innovate, challenge stale assumptions, and move faster than incumbents. It’s how we build what others think is impossible.

The personal data provided in your application and during the selection process will be processed by Happyrobot, Inc., acting as Data Controller.

By sending us your CV, you consent to the processing of your personal data for the purpose of evaluating and selecting you as a candidate for the position. Your personal data will be treated confidentially and will only be used for the recruitment process of the selected job offer.

In relation to the period of conservation of your personal data, these will be eliminated after three months of inactivity in compliance with the GDPR and legislation on the protection of personal data.

If you wish to exercise your rights of access, rectification, deletion, portability or opposition in relation to your personal data, you can do so through security@happyrobot.ai subject to the GDPR.

For more information, visit https://www.happyrobot.ai/privacy-policy

By submitting your request, you confirm that you have read and understood this clause and that you agree to the processing of your personal data as described.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

SOC Engineer
SOC Engineer

HappyRobot • Barcelona

Presencial
EUR 60.000 - 90.000
Healthcare
Dental coverage
Vision coverage
SOC Analyst
SOC Analyst

Happyrobot Inc. • Bellprat

Presencial
EUR 36.000 - 60.000
Healthcare coverage
Dental coverage
Vision coverage
SOC Analyst
SOC Analyst

HappyRobot • Barcelona

Presencial
EUR 42.000 - 64.000
Healthcare
Dental
Vision
+1
SOC Analyst
SOC Analyst

HappyRobot • Madrid

Presencial
EUR 42.000 - 64.000
Healthcare, dental, vision
Equity in startup
Growth Engineer
Growth Engineer

Happyrobot Inc. • Madrid

Presencial
EUR 90.000 - 130.000
Healthcare
Equity
Ownership & autonomy
+2
Cloud Security Engineer
Cloud Security Engineer

HappyRobot • Madrid

Presencial
EUR 70.000 - 110.000
Healthcare coverage
Dental coverage
Vision coverage
+1
Growth Engineer
Growth Engineer

Happyrobot Inc. • Barcelona

Presencial
EUR 70.000 - 110.000
Healthcare, dental and vision
Equity
Ownership & Autonomy
Technical Recruiter
Technical Recruiter

Happyrobot Inc. • Madrid

Presencial
EUR 60.000 - 90.000
Healthcare
Dental
Vision
+3
Technical Recruiter
Technical Recruiter

HappyRobot • Madrid

Presencial
EUR 42.000 - 64.000
Healthcare
Dental coverage
Vision coverage
Senior Legal Counsel - IP, Data Privacy & SaaS Contracts
Senior Legal Counsel - IP, Data Privacy & SaaS Contracts

HappyRobot • Madrid

Presencial
EUR 70.000 - 100.000
Top-tier compensation with equity
Ownership of projects
Work with a world-class team