Security Operations Analyst (SIEM)
12 hours ago
Valencia
Full Time | Valencia, Spain or Remote on EMEA (CET +/-2 hours) Location: Valencia, Spain or Remote on EMEA (CET +/-2 hours) Teleworking option: Yes SCOPE OF WORK: • Contribute to the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms., • Support the operation, maintenance, optimization, and continuous improvement of security monitoring and threat detection services., • Participate in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities., • Contribute to security content management activities, including use case lifecycle management, rule reviews, testing, tuning, and content quality assurance., • Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities., • Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and provide recommendations to enhance security monitoring and detection effectiveness., • Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs, and service performance reports., • Review, validate, and assess the effectiveness of detections, monitoring configurations, operational processes, and service deliverables, identifying opportunities for improvement., • Gather and analyze operational feedback to identify opportunities for tuning, optimization, reduction of false positives, and improvement of overall detection quality., • Contribute to quality assurance activities, including process reviews, control validation, service quality assessments, and implementation of corrective actions., • Support the development, review, and maintenance of CSOC procedures, standards, documentation, knowledge base articles, and operational guidance materials., • Prepare and present technical reports, summaries, findings, and recommendations to internal and external stakeholders., • Provide other ad hoc support as required The resource MUST have the following skills and experience: • A minimum of five (5) years of relevant experience in information technology field, including triage of alerts and supporting security incidents., • Proven experience on administering a SIEM platform, preferably either Splunk or Microsoft Sentinel SIEM., • Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs) and being able to autonomously perform technical analysis of security threats and collaborate with Incident Response team, • Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR, • Deep Knowledge of Cloud technologies (e.g. Azure, AWS and GCP), • Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack, • Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike), • Knowledge of email security, network monitoring, and incident response, • Knowledge of Linux/Mac/Windows, • Expert knowledge of English, both written and spoken, is required The resource SHOULD have the following skills and experience: • Experience in building SIEM architectures from initial design to implementation, including designing data ingestion pipelines for diverse log sources across cloud and on-prem environments, • Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas), • Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.), • Excellent communication skills, • Customer-facing experience and oral communication skills, • Ability to write documentation & reports, • Creativity/ability to find innovative solutions, • Willingness to learn on the job, • Conflict management & cooperation Desirable certifications: • Technical certifications: MCSE, CCNA, Microsoft Azure (e.g., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification, • Relevant industry certifications Teleworking Option: • Yes, up to 4 days per week for consultants working from Valencia #J-18808-Ljbffr