SOC Technical Lead – Threat Hunting & Incident Response

Thales Group

Madrid

Híbrido

EUR 70.000 - 110.000

Jornada completa

14 días+
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca para contratar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Flexible Hybrid Work
Up to 41 vacation days
Friday focus time (monthly)
Flexible compensation package
Annual training & certifications
Speakers Program
Performance-based bonuses

Descripción de la vacante

Thales S21sec Spain is seeking a SOC Technical Lead for Threat Hunting and Incident Response in Madrid. You will lead proactive defense, guide investigations, and mentor a growing team across hybrid environments.

You will drive a culture of security as code, automation, and continuous improvement while coordinating with cloud and product teams to strengthen the global security ecosystem.

Formación

  • 2–5 years of experience in Cybersecurity, focusing on Security Operations, Incident Response, or Threat Hunting.
  • Demonstrated experience in technical lead or senior advisory role guiding teams through complex challenges.
  • Proven background in security operations within high-scale, distributed environments (Cloud or Hybrid).
  • Advanced understanding of attacker TTPs and the MITRE ATT&CK framework.
  • Deep expertise in SIEM/SOAR platforms, EDR/XDR tools, and network traffic analysis.
  • Experience with Cloud security (AWS, Azure, or GCP) and shared responsibility models.
  • Experience leading large-scale incident investigations and performing root-cause analysis.
  • Familiarity with forensic analysis tools and procedures.

Responsabilidades

  • Drive Proactive Defense: spearhead threat hunting strategy using telemetry and intelligence to uncover attacker patterns before impact.
  • Lead Through Crisis: provide the technical force behind Incident Response, guide the team in high-pressure situations and refine the playbook.
  • Mentor and Innovate: mentor teammates, run technical workshops, and foster continuous improvement and excellence.
  • Architect the Future: partner with cloud/product teams to embed security into lifecycle with Security-as-Code and automation.

Conocimientos

Threat Hunting
Incident Response
Security Leadership
Forensics
MITRE ATT&CK
Team Mentoring

Herramientas

SIEM/SOAR
EDR/XDR
Network Traffic Analysis
Cloud Security (AWS/Azure/GCP)

Descripción del empleo

## SOC Technical Lead – Threat Hunting & Incident ResponseApplyremote type: Hybridlocations: Madrid Emilio Vargastime type: Full timeposted on: Posted Todayjob requisition id: R0333099Location: Madrid Emilio Vargas, SpainThales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billions of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more. More than 30,000 organizations already rely on us to verify the identities of people and things, grant access to digital services, analyze vast quantities of information and encrypt data to make the connected world more secure.Thales in Spain is a leader in technological solutions applied to Defence, Aeronautics, Security, Transportation and Space and, furthermore, is a global centre for excellence in Space, Security of Critical Infrastructures and Transportation. With a turnover of €320 million and a staff of 1,200, it exports approximately 40% of its total production principally to the Middle East, North Africa and Latin America.At **Thales S21sec Spain**, we are looking for a **SOC Technical Lead – Threat Hunting & Incident Response** with **4****+ years of experience in cybersecurity** to join our central services team.We are seeking a highly motivated professional with strong expertise in **cybersecurity infrastructures**, capable of supporting and managing complex technological environments across leading security vendors.Join the Team Defending Thales’ Future At Thales, we don't just respond to threats—we anticipate them. We are looking for a visionary SOC Technical Lead who thrives at the intersection of advanced threat hunting, rapid incident response, and team mentorship. If you are passionate about building resilient security architectures and want to lead a team that is defining the next generation of SOC services, this is your opportunity to make a lasting impact.### **Key Responsibilities*** Drive Proactive Defense: You will spearhead our threat hunting strategy, utilizing advanced telemetry and intelligence to uncover sophisticated attacker patterns before they impact our infrastructure.* Lead Through Crisis: You will be the technical force behind our Incident Response, guiding the team through high-pressure situations, conducting deep-dive forensics, and refining our defense playbook to stay ahead of the adversary.* Mentor and Innovate: You will elevate the talent around you. Through hands-on mentorship, technical workshops, and collaboration, you will cultivate a culture of continuous improvement and technical excellence.* Architect the Future: You will partner with our cloud and product teams to integrate security into every stage of the lifecycle. By championing "Security-as-Code" and automation, you will transform how we monitor and protect our global ecosystem.### **Requirements*** ### Experience: Minimum 2–5 years of experience in Cybersecurity, with a strong focus on Security Operations, Incident Response, or Threat Hunting.* ### Demonstrated experience in a technical lead or senior-level advisory role, guiding teams through complex technical challenges.* ### Proven background in managing security operations within high-scale, distributed environments (Cloud or Hybrid).* ### Advanced understanding of attacker TTPs (Tactics, Techniques, and Procedures) and the MITRE ATT&CK framework.* ### Deep expertise in SIEM/SOAR platforms, EDR/XDR tools, and network traffic analysis.* ### Experience with Cloud security (AWS, Azure, or GCP) and understanding of shared responsibility models.* ### Experience leading large-scale incident investigations and performing root-cause analysis.* ### Familiarity with forensic analysis tools and procedures.### ### **Why Join Thales S21sec Spain?**At Thales S21sec, we pride ourselves on being **innovative and flexible** in how we work. We continuously evolve our policies to ensure a true **work-life balance**.**100% Flexible Hybrid Work** Work from home or come to the office whenever you choose.**Up to 41 Days Off Per Year*** 24 vacation days + additional flexible days* Option to enjoy **one free Friday per month (12 per year)*** Choose between **summer reduced hours** or extra days of**Flexible Compensation Package**Optimize your net salary with benefits such as meal vouchers, transport cards, childcare vouchers, and training support.**Continuous Learning & Certifications** Access to an **annual training plan** including technical certifications, languages, and soft skills.**Knowledge Sharing Culture** Participate in our voluntary **Speakers Program** and share your expertise.**Performance-Based Bonuses** Clear and transparent objectives aligned with KPI-based annual bonuses.**Career Growth Your Way** Choose your path:* Leadership and team management* Deep technical specialization with top experts### **Join Us**If you are passionate about cybersecurity and want to make an impact, **we are your company**. *We’re looking forward to meeting you!*At Thales we provide CAREERS and not only jobs. With Thales employing 80,000 employees in 68 countries our mobility policy enables thousands of employees each year to develop their careers at home and abroad, in their existing areas of expertise or by branching out into new fields. Together we believe that embracing flexibility is a smarter way of working. Great journeys start here, apply now!
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

SOC Technical Lead - Threat Hunting & Incident Response
SOC Technical Lead - Threat Hunting & Incident Response

Thales • España

Híbrido
EUR 70.000 - 110.000
Flexible hybrid work
Up to 41 days off per year
Meal vouchers & transport support
+3
SOC Technical Lead – Threat Hunting & Incident Response
SOC Technical Lead – Threat Hunting & Incident Response

Thales • Madrid

Híbrido
EUR 70.000 - 110.000
Flexible hybrid work
41 days off
Meal vouchers
+3
Regional Sales Manager Spain (Hybrid)
Regional Sales Manager Spain (Hybrid)

Thales Group • Madrid

Híbrido
EUR 90.000 - 130.000
Remote-friendly
Restaurant allowance
Health insurance
+2
Sales Manager (Hybrid)
Sales Manager (Hybrid)

Thales Group • Madrid

Híbrido
EUR 60.000 - 90.000
Remote-friendly – 2 days per week work
Restaurant allowance
Health insurance
+1
Electronics Production & Process Engineer (Hybrid)
Electronics Production & Process Engineer (Hybrid)

Thales Group • Madrid

Híbrido
EUR 40.000 - 60.000
Remote-friendly - 2 days a week working from home
Restaurant allowance
Health insurance
+1
DevSecOps
DevSecOps

Thales • Leganés

Presencial
EUR 60.000 - 90.000
Security Site Manager (Hybrid)
Security Site Manager (Hybrid)

Thales • Madrid

Híbrido
EUR 60.000 - 80.000
Flexible working hours
Remote-friendly – 2 days a week
Restaurant allowance
+2
Offer owner - Detection & Respond Services
Offer owner - Detection & Respond Services

Thales • Madrid

Presencial
EUR 60.000 - 90.000
Maximize your net salary
Continue your training and expand your certifications
Work with clear and transparent objectives
+2
QA Engineer
QA Engineer

Thales Group • Madrid

Híbrido
EUR 38.000 - 58.000
Remote-friendly
Health benefits
Restaurant allowance
SOC Tech Lead: Proactive Threat Hunting & Incident Response
SOC Tech Lead: Proactive Threat Hunting & Incident Response

Thales • Madrid

Híbrido
EUR 70.000 - 110.000
Flexible hybrid work
41 days off
Meal vouchers
+3