Security Operations Analyst (SIEM Operations and Threat Detection) - valència
11 hours ago
Valencia
Overview As a Senior CSOC Consultant, you will strengthen threat detection and security operations for diverse, global environments. You will enhance detection capabilities across SIEM, EDR, cloud, and related platforms, while ensuring quality and ongoing improvement of monitoring services. You’ll collaborate with threat intelligence and incident response teams to translate requirements into effective detections. This role offers exposure to large-scale security operations and a chance to shape detection strategies in a multi-customer setting. Compensaciones / Beneficios • Remote position, • Freelance, full-time contract, • Training and career development, • Multicultural team and international projects, • On-call rotation system, • Competitive exposure to large-scale cybersecurity environments Responsabilidades, • Develop, validate, tune, and maintain security monitoring and detection across SIEM, EDR, cloud, and other platforms, • Operate and continuously improve security monitoring and threat detection services, • Onboard and validate new security data sources and telemetry feeds, • Manage security content, use-case lifecycle, rules reviews, testing, tuning, and QA, • Collaborate with threat intelligence, incident response, and CSOC teams to translate requirements into detections, • Contribute to cybersecurity architecture reviews and provide recommendations, • Prepare CSOC metrics, dashboards, KPIs, and service performance reports, • Review and assess detection effectiveness and monitoring configurations for improvements, • Analyze operational feedback to reduce false positives and improve detection quality, • Contribute to CSOC procedures, knowledge base, and operational guidance, • Prepare technical reports and recommendations for stakeholders Requisitos principales, • +5 years of IT experience with alert triage and security incidents, • Experience administering a SIEM (preferably Splunk or Microsoft Sentinel), • Proficiency with SOC toolbox (SIEMs, EDRs) and technical threat analysis, • Deep knowledge of Microsoft security tools (M365, Defender for Endpoints, Azure, Defender, Sentinel, XDR), • Strong Cloud knowledge (Azure, AWS, GCP), • Experience with SIEM tools (Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack), • Knowledge of at least one EDR (MS Defender for Endpoint, CrowdStrike), • Knowledge of email security, network monitoring, and incident response, • Proficiency with Linux/Mac/Windows, • C1 English proficiency, • Nice to have: SIEM architecture design, AWS monitoring, scripting (Python, Bash, PowerShell, Ruby), • Certifications such as MCSE, CCNA, SC-200, GCIH, CEH, GCFA, • Soft skills: excellent communication, customer-facing, documentation, creativity, willingness to learn, conflict management, • excellent communication, • customer-facing, • documentation, • SIEM (Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK Stack), • EDR (Microsoft Defender for Endpoint, CrowdStrike), • Microsoft security tools (M365, Defender, Cloud App Security, Azure)