Security Operations Analyst (SIEM & Threat Detection)
pragmatike · Madrid
Job description
About the role
Pragmatike is recruiting for a major international organization seeking a Security Operations Analyst specialized in SIEM and threat detection. The role sits within a global Cybersecurity Operations team and focuses on building, operating, and continuously improving security monitoring capabilities across multiple customer environments.
Key responsibilities
- Develop, implement, validate, tune, and maintain security monitoring and detection capabilities.
- Administer and optimise SIEM platforms across multiple customer environments.
- Manage security detection rules and use cases throughout their lifecycle.
- Onboard, integrate, test, and validate new security data sources and telemetry feeds.
- Collaborate with Threat Intelligence and Incident Response teams to translate threats into actionable detection capabilities.
- Support cybersecurity architecture reviews and provide recommendations to improve security monitoring.
- Build and maintain security metrics, dashboards, KPIs, and service‑performance reports.
- Evaluate detection effectiveness and identify opportunities to reduce false positives.
- Maintain SOC procedures, standards, documentation, knowledge bases, and operational guidance.
- Prepare technical reports, findings, and recommendations for internal and external stakeholders.
Required profile
- 5+ years of relevant IT/cybersecurity experience.
- Hands‑on experience administering a SIEM platform, ideally Splunk or Microsoft Sentinel.
- Strong experience with SIEM/EDR environments and technical security analysis.
- Deep knowledge of Microsoft security technologies.
- Strong cloud security knowledge across Azure, AWS, and/or GCP.
- Fluent English with excellent written and verbal communication skills.
Required skills
- SIEM platforms – Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK.
- EDR platforms – Microsoft Defender for Endpoint, CrowdStrike.
- Microsoft security suite.
- Cloud platforms – Azure, AWS, GCP.
- Scripting languages – Python, PowerShell, Bash, Ruby.
- Operating systems – Linux, macOS, Windows.
- Security certifications – SC‑200, GCIH, CEH, GCFA, GIAC, CCNA, MCSE.
What we offer
- Work beyond traditional SOC monitoring and contribute to engineering and optimisation of detection capabilities.
- Exposure to large‑scale SIEM, EDR, cloud, and threat‑detection environments.
- Direct collaboration with Threat Intelligence, Incident Response, and Cybersecurity Operations teams.
- Opportunity to shape detection use cases, monitoring architecture, and operational processes.
- Inclusive recruitment process committed to fairness and diversity.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Spain.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 2 days ago
Expires 1 month from now
9 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
pragmatike
Madrid
Related job offers
-
Ingeniero Full Stack (Híbrido, Madrid Centro)
knowmad mood Madrid -
Arquitecto/a de Plataforma IA (semipresencial Madrid centro)
knowmad mood Madrid -
Ingeniero/a Full Stack (Java + Angular + IA) – Madrid híbrido
knowmad mood Madrid -
Senior Système Technicien – SQL Server & PostgreSQL (hybride)
Abalia Madrid / Bilbao -
Solution Consultant – Quality
veeva Spain - Barcelona