Jobiglo

No results.

Principal Analyst Cyber Security Defense Center

BASF SE · Madrid

New
Indefinido Hybrid Senior 🇬🇧 English
Elastic Security SIEM EDR ES|QL OSQuery Velociraptor Volatility Suricata Wireshark Ghidra IDA Pro x64dbg WinDbg Python Go Bash PowerShell x64 assembly Microsoft Entra ID Active Directory Azure AWS

Job description

About the role

The Principal Analyst leads the technical response to the most complex and high‑risk security incidents at BASF’s Cyber Security Defense Center. You will drive threat hunting, detection design, and AI‑assisted automation while mentoring senior analysts.

Key responsibilities

  • Lead end‑to‑end incident response as Case Lead, from triage through containment, eradication and closure.
  • Design and execute hypothesis‑driven threat‑hunting campaigns and translate findings into durable detection coverage.
  • Develop, review and continuously improve detection logic, correlation rules and SOAR playbooks on the Elastic Security platform.
  • Shape the CSDC automation and AI roadmap, co‑designing AI‑assisted triage workflows with human‑in‑the‑loop safeguards.
  • Mentor Tier 2 and Tier 3 analysts, create advanced training content and drive knowledge transfer.
  • Represent CSDC in internal governance bodies and external trusted networks (e.g., BSI, FIRST).

Required profile

  • 8+ years of professional experience in cyber defence and incident response, with proven subject‑matter expertise.
  • Strong leadership under pressure, excellent communication in English and ability to mentor technical teams.
  • Relevant certifications are valued (e.g., GIAC, Elastic, Microsoft, OSCP) but not mandatory.

Required skills

  • Deep knowledge of Windows and Linux internals, network protocols and traffic analysis.
  • Expertise with Elastic Security (SIEM/EDR), detection rule development, ES|QL and automation workflows.
  • Proficiency with DFIR tools such as OSQuery, Velociraptor, Volatility, Suricata, Wireshark.
  • Malware analysis and reverse‑engineering tools: Ghidra, IDA Pro, x64dbg, WinDbg; ability to read C and x86/x64 assembly.
  • Cloud and identity threat detection experience (Microsoft Entra ID/Active Directory, Azure, AWS).
  • Programming/scripting in Python, Go, Bash and PowerShell.
  • Understanding of AI/ML applications in security operations is a plus.

What we offer

  • Secure work environment with health, safety and wellbeing priority.
  • Flexible schedule and home‑office options (hybrid work model).
  • 23 holiday days plus additional cultural days.
  • Learning and development opportunities.
  • Relocation assistance to Madrid.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec BASF SE.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Le contrat proposé est un Indefinido basé à Madrid.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Spain.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 2 hours ago

Expires 1 month from now

5 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

BASF SE

Madrid