Security Operations Analyst (SIEM & Threat Detection)
pragmatike · Madrid
Descripcion del puesto
About the role
Pragmatike is recruiting for a major international organization seeking a Security Operations Analyst specialized in SIEM and threat detection. The role sits within a global Cybersecurity Operations team and focuses on building, operating, and continuously improving security monitoring capabilities across multiple customer environments.
Key responsibilities
- Develop, implement, validate, tune, and maintain security monitoring and detection capabilities.
- Administer and optimise SIEM platforms across multiple customer environments.
- Manage security detection rules and use cases throughout their lifecycle.
- Onboard, integrate, test, and validate new security data sources and telemetry feeds.
- Collaborate with Threat Intelligence and Incident Response teams to translate threats into actionable detection capabilities.
- Support cybersecurity architecture reviews and provide recommendations to improve security monitoring.
- Build and maintain security metrics, dashboards, KPIs, and service‑performance reports.
- Evaluate detection effectiveness and identify opportunities to reduce false positives.
- Maintain SOC procedures, standards, documentation, knowledge bases, and operational guidance.
- Prepare technical reports, findings, and recommendations for internal and external stakeholders.
Required profile
- 5+ years of relevant IT/cybersecurity experience.
- Hands‑on experience administering a SIEM platform, ideally Splunk or Microsoft Sentinel.
- Strong experience with SIEM/EDR environments and technical security analysis.
- Deep knowledge of Microsoft security technologies.
- Strong cloud security knowledge across Azure, AWS, and/or GCP.
- Fluent English with excellent written and verbal communication skills.
Required skills
- SIEM platforms – Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK.
- EDR platforms – Microsoft Defender for Endpoint, CrowdStrike.
- Microsoft security suite.
- Cloud platforms – Azure, AWS, GCP.
- Scripting languages – Python, PowerShell, Bash, Ruby.
- Operating systems – Linux, macOS, Windows.
- Security certifications – SC‑200, GCIH, CEH, GCFA, GIAC, CCNA, MCSE.
What we offer
- Work beyond traditional SOC monitoring and contribute to engineering and optimisation of detection capabilities.
- Exposure to large‑scale SIEM, EDR, cloud, and threat‑detection environments.
- Direct collaboration with Threat Intelligence, Incident Response, and Cybersecurity Operations teams.
- Opportunity to shape detection use cases, monitoring architecture, and operational processes.
- Inclusive recruitment process committed to fairness and diversity.
Questions fréquentes
Por que reporta esta oferta?
Explorar más
Salarios, guías y búsquedas en España.
Salarios por profesión
Postula en 30 segundos
Ingresa tu email para postular. Se creara una cuenta automaticamente.
Al continuar, aceptas nuestras condiciones de uso.
Ya tienes cuenta? Iniciar sesion
Publicado hace 8 horas
Expira en 1 mes
2 vistas · 0 interested
Aumenta tus posibilidades
Sube tu CV: te propondremos las ofertas que coinciden con tu perfil.
Analizando tu CV...
pragmatike
Madrid