L3 SOC Analyst - Madrid
11 days ago
Madrid
ph3About Us /h3 pIntegrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees across 12 locations and six Security Operations Centres (SOCs) – including Dublin, Sofia, Stockholm, Madrid, Rome and Cape Town – we support more than 2,500 clients across a wide range of industries. /p pOver 80% of our team are technical experts, focused on helping clients proactively identify, protect, detect and respond to threats in an ever‑evolving cyber landscape. Our security‑first approach positions cyber resilience as a business enabler, empowering organisations to operate with confidence. /p pAt Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you’re ready to take your cyber security career to the next level, we’d love to hear from you. /p h3Job Role / Responsibilities /h3 pIn this role you will act as a Level 3 escalation point within the MDR/SOC function, providing advanced technical support to Level 2 analysts during complex or high‑severity investigations. You will bring deep operational knowledge across modern security technologies, including SIEM, EDR, Network Intrusion Detection Systems, SOAR, DLP and related security monitoring platforms. The Principal SOC Analyst will support the investigation, containment and remediation of advanced threats, ensuring incidents are analysed in the correct business and technical context. You will contribute to the continuous improvement of the MDR service by supporting the definition of security monitoring strategies, improving detection logic, tuning security technologies, reviewing investigation processes and advising customers on technical optimisation opportunities. A strong understanding of malware behaviour, adversary tactics, techniques and procedures, and emerging threats will be critical to success. /p h3Primary Duties and Responsibilities /h3 ul liAct as the Level 3 escalation point for advanced, complex or high‑impact security investigations. /li liSupport Level 2 analysts during complex investigations, providing technical guidance, validation and direction. /li liPerform in‑depth analysis of security events, alerts, logs, endpoint telemetry, network traffic and other relevant data sources. /li liLead advanced incident investigations, including scoping, containment, eradication and remediation recommendations. /li liAnalyse malicious activity, suspicious files, attacker behaviour and adversary TTPs. /li liSupport customers from a technical perspective in the optimisation, tuning and improvement of their security monitoring capabilities. /li liReview and improve SIEM, EDR, NIDS, SOAR and other security tool configurations to reduce false positives and improve detection quality. /li liContribute to the development and refinement of detection use cases, correlation rules, alerting logic and investigation playbooks. /li liSupport the definition of customer security monitoring strategies based on risk profile, threat landscape and available telemetry. /li liProvide technical recommendations to strengthen customer cyber security posture and improve resilience against current and emerging threats. /li liConduct threat hunting and proactive analysis based on indicators, behaviours, intelligence and attack patterns. /li liDocument investigation findings, evidence, timelines, containment actions and remediation recommendations in a clear and structured manner. /li liPrepare and deliver technical reports to customers, partners and internal stakeholders. /li liMonitor trusted sources for emerging threats, vulnerabilities and adversary activity relevant to customer environments. /li liContribute to the continuous improvement of SOC processes, procedures, documentation and knowledge base material. /li liSupport mentoring and technical development of Level 1 and Level 2 analysts where required. /li /ul h3Desired Skills /h3 ul liStrong hands‑on experience in Security Operations Centre or MDR environments. /li liDeep operational knowledge of SIEM, EDR, Network Intrusion Detection Systems, SOAR, DLP and related security monitoring technologies. /li liStrong experience with security event triage, correlation, investigation and escalation. /li liAbility to analyse endpoint, network, identity, cloud and application telemetry in support of complex investigations. /li liExperience with SIEM query languages and detection logic, such as KQL, SPL, Sigma or equivalent. /li liExperience tuning security controls and detection content to improve alert fidelity and reduce false positives. /li liStrong understanding of attacker tactics, techniques and procedures, including MITRE ATTCK. /li liAbility to perform host‑based and network‑based threat analysis. /li liExperience analysing packet captures, endpoint artefacts, logs, scripts, documents and potentially malicious files. /li liStrong understanding of incident response lifecycle, including preparation, identification, containment, eradication, recovery and lessons learned. /li liStrong understanding of enterprise network architecture, TCP/IP, firewalls, proxies, VPNs, DNS, email security and cloud environments. /li liUnderstanding of security protocols, encryption technologies and common authentication mechanisms. /li liExperience supporting customer‑facing technical discussions, including investigation reviews, tuning recommendations and posture improvement activities. /li liAbility to manage multiple complex incidents and make effective decisions under pressure. /li liStrong written and verbal communication skills, with the ability to explain technical findings to both technical and non‑technical stakeholders. /li liExperience with Microsoft Sentinel, Microsoft Defender, Splunk, QRadar, CrowdStrike, SentinelOne, Palo Alto, Suricata, Zeek, Snort or similar technologies is highly beneficial. /li liExperience with cloud security monitoring across Microsoft Azure, AWS or Google Cloud is beneficial. /li liExperience with threat hunting, detection engineering or purple team activities is beneficial. /li liAbility to produce clear technical documentation, investigation reports and customer‑facing recommendations. /li /ul h3Certifications and Qualifications /h3 ul liSecurity industry certifications such as GCIH, GCFA, GCIA, GNFA, GCTI, GSEC, CISSP, CySA+, SC‑200, AZ‑500 or equivalent are highly beneficial. /li liMinimum 2–3 years of experience in a SOC, MDR, incident response, CSIRT or cyber security operations role. /li liProven experience handling complex security incidents and supporting advanced investigations. /li liWorking knowledge of SIEM, EDR, SOAR, NIDS, DLP and threat intelligence platforms. /li liExperience working with threat hunting methodologies and security detection frameworks. /li liExperience supporting customers or internal stakeholders with security optimisation, detection tuning and cyber security posture improvement. /li /ul /p #J-18808-Ljbffr