SOC Technical Lead - Threat Hunting & Incident Response

Thales

España

Presencial

EUR 70.000 - 110.000

Jornada completa

14 días+
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Flexible hybrid work
Up to 41 days off per year
Meal vouchers & transport support
Annual training plan
Speakers Program
Performance-based bonuses

Descripción de la vacante

Thales S21sec Spain is looking for a SOC Technical Lead - Threat Hunting & Incident Response with 4+ years of cybersecurity to join our central services team in Madrid. You will spearhead threat hunting, guide incident response, mentor colleagues, and help embed security into every stage of the lifecycle across cloud and on‑prem environments.

This role offers a flexible hybrid work model, up to 41 days off per year, and a active learning culture with an annual training plan and KPI‑based bonuses.

Formación

  • 2–5 years in Cybersecurity with focus on SOC, IR, or Threat Hunting.
  • Technical lead or senior advisory experience guiding teams.
  • Security operations in large, distributed environments (Cloud/Hybrid).
  • Strong knowledge of MITRE ATT&CK, attacker TTPs, and forensics basics.

Responsabilidades

  • Drive proactive defense by leading threat hunting and telemetry analysis.
  • Lead incident response during high‑pressure events and refine playbooks.
  • Mentor teammates through hands‑on workshops and collaboration.
  • Architect secure workflows with cloud, product, and security teams.

Conocimientos

Threat Hunting
Incident Response
Security Operations
Technical Leadership
Cloud Security
MITRE ATT&CK
TTPs
Forensics

Herramientas

SIEM/SOAR
EDR/XDR
Network Traffic Analysis
Cloud Security (AWS/Azure/GCP)

Descripción del empleo

Location: Madrid Emilio Vargas, Spain

Thales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billions of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more. More than 30,000 organizations already rely on us to verify the identities of people and things, grant access to digital services, analyze vast quantities of information and encrypt data to make the connected world more secure.

Thales in Spain is a leader in technological solutions applied to Defence, Aeronautics, Security, Transportation and Space and, furthermore, is a global centre for excellence in Space, Security of Critical Infrastructures and Transportation. With a turnover of €320 million and a staff of 1,200, it exports approximately 40% of its total production principally to the Middle East, North Africa and Latin America.

At Thales S21sec Spain, we are looking for a SOC Technical Lead - Threat Hunting & Incident Response with 4+ years of experience in cybersecurity to join our central services team.

We are seeking a highly motivated professional with strong expertise in cybersecurity infrastructures, capable of supporting and managing complex technological environments across leading security vendors.

Join the Team Defending Thales' Future At Thales, we don't just respond to threats—we anticipate them. We are looking for a visionary SOC Technical Lead who thrives at the intersection of advanced threat hunting, rapid incident response, and team mentorship. If you are passionate about building resilient security architectures and want to lead a team that is defining the next generation of SOC services, this is your opportunity to make a lasting impact.

Key Responsibilities
  • Drive Proactive Defense: spearhead our threat hunting strategy, utilizing advanced telemetry and intelligence to uncover sophisticated attacker patterns before they impact our infrastructure.
  • Lead Through Crisis: be the technical force behind our Incident Response, guiding the team through high-pressure situations, conducting deep-dive forensics, and refining our defense playbook to stay ahead of the adversary.
  • Mentor and Innovate: elevate the talent around you through hands‑on mentorship, technical workshops, and collaboration, cultivating a culture of continuous improvement and technical excellence.
  • Architect the Future: partner with our cloud and product teams to integrate security into every stage of the lifecycle. Champion "Security‑as‑Code" and automation, transforming how we monitor and protect our global ecosystem.
Requirements
  • Minimum 2‑5 years of experience in Cybersecurity, with a strong focus on Security Operations, Incident Response, or Threat Hunting.
  • Demonstrated experience in a technical lead or senior‑level advisory role, guiding teams through complex technical challenges.
  • Proven background in managing security operations within high‑scale, distributed environments (Cloud or Hybrid).
  • Advanced understanding of attacker TTPs (Tactics, Techniques, and Procedures) and the MITRE ATT&CK framework.
  • Deep expertise in SIEM/SOAR platforms, EDR/XDR tools, and network traffic analysis.
  • Experience with Cloud security (AWS, Azure, or GCP) and understanding of shared responsibility models.
  • Experience leading large-scale incident investigations and performing root‑cause analysis.
  • Familiarity with forensic analysis tools and procedures.
Why Join Thales S21sec Spain?

At Thales S21sec, we pride ourselves on being innovative and flexible in how we work. We continuously evolve our policies to ensure a true work‑life balance.

100% Flexible Hybrid Work

Work from home or come to the office whenever you choose.

Up to 41 Days Off Per Year
  • 24 vacation days + additional flexible days
  • Option to enjoy one free Friday per month (12 per year)
  • Choose between summer reduced hours or extra days of leave
Flexible Compensation Package

Optimize your net salary with benefits such as meal vouchers, transport cards, childcare vouchers, and training support.

Continuous Learning & Certifications

Access to an annual training plan including technical certifications, languages, and soft skills.

Knowledge Sharing Culture

Participate in our voluntary Speakers Program and share your expertise.

Performance-Based Bonuses

Clear and transparent objectives aligned with KPI-based annual bonuses.

Career Growth Your Way

Choose your path:

  • Leadership and team management
  • Deep technical specialization with top experts
Join Us

If you are passionate about cybersecurity and want to make an impact, we are your company.

We're looking forward to meeting you!

At Thales we provide CAREERS and not only jobs. With Thales employing 80,000 employees in 68 countries our mobility policy enables thousands of employees each year to develop their careers at home and abroad, in their existing areas of expertise or by branching out into new fields. Together we believe that embracing flexibility is a smarter way of working. Great journeys start here, apply now!

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

SOC Technical Lead – Threat Hunting & Incident Response
SOC Technical Lead – Threat Hunting & Incident Response

Thales • Madrid

Híbrido
EUR 70.000 - 110.000
Flexible hybrid work
41 days off
Meal vouchers
+3
SOC Technical Lead – Threat Hunting & Incident Response
SOC Technical Lead – Threat Hunting & Incident Response

Thales Group • Madrid

Híbrido
EUR 70.000 - 110.000
Flexible Hybrid Work
Up to 41 vacation days
Friday focus time (monthly)
+4
SOC Engineer
SOC Engineer

Thales • Madrid

Presencial
EUR 52.000 - 74.000
Offer owner - Detection & Respond Services
Offer owner - Detection & Respond Services

Thales • Madrid

Presencial
EUR 60.000 - 90.000
Maximize your net salary
Continue your training and expand your certifications
Work with clear and transparent objectives
+2
DevSecOps
DevSecOps

Thales • Leganés

Presencial
EUR 60.000 - 90.000
Security Site Manager (Hybrid)
Security Site Manager (Hybrid)

Thales • Madrid

Híbrido
EUR 60.000 - 80.000
Flexible working hours
Remote-friendly – 2 days a week
Restaurant allowance
+2
SOC Tech Lead: Proactive Threat Hunting & Incident Response
SOC Tech Lead: Proactive Threat Hunting & Incident Response

Thales • Madrid

Híbrido
EUR 70.000 - 110.000
Flexible hybrid work
41 days off
Meal vouchers
+3
SOC Tech Lead: Threat Hunting & Incident Response
SOC Tech Lead: Threat Hunting & Incident Response

Thales Group • Madrid

Híbrido
EUR 70.000 - 110.000
Flexible Hybrid Work
Up to 41 vacation days
Friday focus time (monthly)
+4
Hybrid SOC Lead: Threat Hunting & Incident Response
Hybrid SOC Lead: Threat Hunting & Incident Response

Thales • España

Híbrido
EUR 70.000 - 110.000
Flexible hybrid work
Up to 41 days off per year
Meal vouchers & transport support
+3
Solution Arquitect (Hybrid)
Solution Arquitect (Hybrid)

Thales • Madrid

Presencial
EUR 40.000 - 60.000
Flexible working hours
Intensive Fridays
Remote-friendly
+3