Security Operations Analysts
Hace 2 días
Valencia, Valencia (comarca); Provincia de Valencia; Comunidad Valenciana, España
Talan
Jornada completa
Gratis con email o Google
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Gratis con email o Google
Al continuar, aceptas nuestros Términos & Política de Privacidad.
Company DescriptionTalan
- Positive InnovationTalan is an international consulting group specializing in innovation and business transformation through technology. Talan at a GlanceHeadquartered in Paris and operating globally, Talan combines technology, innovation, and empowerment to deliver measurable results for our clients. Over the past 22 years, we’ve built a strong presence in the IT and consulting landscape, and we’re on track to reach 1 billion in revenue this year.
Our Core Areas of ExpertiseData & Technologies: We design and implement large-scale, end-to-end architecture and data solutions, including data integration, data science, visualization, Big Data, AI, and Generative AI.
Cloud & Application Services: We integrate leading platforms such as SAP, Salesforce, Oracle, Microsoft, AWS, and IBM Maximo, helping clients transition to the cloud and improve operational efficiency.
Management & Innovation Consulting: We lead business and digital transformation initiatives through project and change management best practices (PM, PMO, Agile, Scrum, Product Ownership), and support domains such as Supply Chain, Cybersecurity, and ESG/Low-Carbon strategies.
We work with major global clients across diverse sectors, including Transport & Logistics, Financial Services, Energy & Utilities, Retail, and Media & Telecommunications.
Job Description
We are looking to join a Senior consultant within the Cyber Security Operations Center (CSOC), a globally distributed team of cybersecurity professionals responsible for protecting complex and diverse technology environments. The role is primarily focused on enhancing threat detection and cybersecurity operations capabilities through activities such as security content management, quality assurance and validation of detection mechanisms, detection use case lifecycle management, onboarding and integration of new security data sources, reporting, and process optimization.
This is an excellent opportunity for professionals interested in working within a large-scale international cybersecurity environment, where they will play a key role in the continuous improvement of security monitoring and threat detection services across multiple customer landscapes. The position combines elements of Security Operations, Threat Detection Engineering, SIEM optimization, cyber risk management, and operational excellence, offering exposure to a wide variety of cybersecurity technologies and challenges.
Contribute to the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
Support the operation, maintenance, optimization, and continuous improvement of security monitoring and threat detection services.
Participate in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities.
Contribute to security content management activities, including use case lifecycle management, rule reviews, testing, tuning, and content quality assurance.
Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities.
Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and provide recommendations to enhance security monitoring and detection effectiveness.
Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs, and service performance reports.
Review, validate, and assess the effectiveness of detections, monitoring configurations, operational processes, and service deliverables, identifying opportunities for improvement.
Gather and analyze operational feedback to identify opportunities for tuning, optimization, reduction of false positives, and improvement of overall detection quality.
Contribute to quality assurance activities, including process reviews, control validation, service quality assessments, and implementation of corrective actions.
QualificationsOn-Call Availability (On-Call Shift System)Mandatory 24/7 On-Call Rotation: You will be required to participate in a rotating on-call shift schedule from Monday to Sunday.
This does not mean you will be actively working 24/7 or during late-night shifts. Frequency: The approximate rotation frequency is one full week (7 consecutive days) every X months, depending on the number of team membersMust have:+5 years of relevant experience in information technology field, including triage of alerts and supporting security incidentsProven experience on administering a SIEM platform, preferably either Splunk or MicrosoftSentinel SIEM Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs) and being able to autonomously perform technical analysis of security threats and collaborate with Incident Response teamDeep kno
- Positive InnovationTalan is an international consulting group specializing in innovation and business transformation through technology. Talan at a GlanceHeadquartered in Paris and operating globally, Talan combines technology, innovation, and empowerment to deliver measurable results for our clients. Over the past 22 years, we’ve built a strong presence in the IT and consulting landscape, and we’re on track to reach 1 billion in revenue this year.
Our Core Areas of ExpertiseData & Technologies: We design and implement large-scale, end-to-end architecture and data solutions, including data integration, data science, visualization, Big Data, AI, and Generative AI.
Cloud & Application Services: We integrate leading platforms such as SAP, Salesforce, Oracle, Microsoft, AWS, and IBM Maximo, helping clients transition to the cloud and improve operational efficiency.
Management & Innovation Consulting: We lead business and digital transformation initiatives through project and change management best practices (PM, PMO, Agile, Scrum, Product Ownership), and support domains such as Supply Chain, Cybersecurity, and ESG/Low-Carbon strategies.
We work with major global clients across diverse sectors, including Transport & Logistics, Financial Services, Energy & Utilities, Retail, and Media & Telecommunications.
Job Description
We are looking to join a Senior consultant within the Cyber Security Operations Center (CSOC), a globally distributed team of cybersecurity professionals responsible for protecting complex and diverse technology environments. The role is primarily focused on enhancing threat detection and cybersecurity operations capabilities through activities such as security content management, quality assurance and validation of detection mechanisms, detection use case lifecycle management, onboarding and integration of new security data sources, reporting, and process optimization.
This is an excellent opportunity for professionals interested in working within a large-scale international cybersecurity environment, where they will play a key role in the continuous improvement of security monitoring and threat detection services across multiple customer landscapes. The position combines elements of Security Operations, Threat Detection Engineering, SIEM optimization, cyber risk management, and operational excellence, offering exposure to a wide variety of cybersecurity technologies and challenges.
Contribute to the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
Support the operation, maintenance, optimization, and continuous improvement of security monitoring and threat detection services.
Participate in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities.
Contribute to security content management activities, including use case lifecycle management, rule reviews, testing, tuning, and content quality assurance.
Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities.
Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and provide recommendations to enhance security monitoring and detection effectiveness.
Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs, and service performance reports.
Review, validate, and assess the effectiveness of detections, monitoring configurations, operational processes, and service deliverables, identifying opportunities for improvement.
Gather and analyze operational feedback to identify opportunities for tuning, optimization, reduction of false positives, and improvement of overall detection quality.
Contribute to quality assurance activities, including process reviews, control validation, service quality assessments, and implementation of corrective actions.
QualificationsOn-Call Availability (On-Call Shift System)Mandatory 24/7 On-Call Rotation: You will be required to participate in a rotating on-call shift schedule from Monday to Sunday.
This does not mean you will be actively working 24/7 or during late-night shifts. Frequency: The approximate rotation frequency is one full week (7 consecutive days) every X months, depending on the number of team membersMust have:+5 years of relevant experience in information technology field, including triage of alerts and supporting security incidentsProven experience on administering a SIEM platform, preferably either Splunk or MicrosoftSentinel SIEM Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs) and being able to autonomously perform technical analysis of security threats and collaborate with Incident Response teamDeep kno