Senior Cybersecurity Defense Specialist

Hace 20 horas

Barcelona, Cataluña, España TD Synnex Jornada completa
Job Purpose:   The Senior Cyber Security Specialist is responsible for designing, implementing and managing security technology solutions globally. Leads or serves as experienced technical resource in multi-discipline IT security projects intended to continually improve the security infrastructure and operating procedures. Keeps abreast of the latest technologies and identifies opportunities to leverage them to improve TD SYNNEX's cyber protection, detection and response capabilities. The responsibilities include reviewing our current security measures and processes in all geographies TD SYNNEX operates in, identifying and addressing areas of weakness through penetration testing and red teaming, and responding promptly to possible security breaches. Continuously improves core processes in identity & access management, threat hunting and analysis, vulnerability management, security monitoring and incident response both on-premise and in the cloud. Documents operating procedures and run books and trains the support team(s).
ABOUT THE TEAM:The Security Automation Engineering pod is the full-stack security engineering function of the future. It blends SIEM mastery, SOAR automation, detection craft, and AI/ML fluency into a single high-velocity pod — building, automating, and detecting across every layer of the security operations stack with intelligent systems as its force multiplier. Unlike other engineering pods where AI is an enhancement opportunity, this pod treats AI as a native, first-class capability woven into every workflow: these engineers don't just use AI tools — they build, tune, and govern them. The team supports a 25,000-employee enterprise.
POSITION SUMMARYA full-stack security engineer who operates fluidly across SIEM administration, playbook development, detection rule creation, and AI system implementation. Owns a domain focus area while maintaining cross-functional capability across all disciplines.

KEY RESPONSIBILITIES
Develop and deploy AI-powered detection rules using ML anomaly models, LLM-generated Sigma/SPL/KQL, and behavioral analytics.
Build intelligent SOAR playbooks that leverage LLM reasoning for dynamic decision-making and adaptive response.
Implement and tune AI-driven alert triage systems — automated scoring, enrichment, and routing based on ML classifiers.
Manage SIEM platform components: index optimization, search performance, and data model maintenance.
Design prompt engineering frameworks and evaluation harnesses for security-focused LLM RAG (Retrieval-Augmented Generation) pipelines using internal security knowledge bases, runbooks, and threat intel.
Conduct AI-augmented threat hunting — using LLMs to generate hypotheses and ML to identify anomalous and maintain CI/CD pipelines for detection rules, playbooks, and ML model deployments.

Responsibilities:
Technical design, implementation, enhancement and ongoing support for security technologies (30%)Executes and continually improves core security processes such as vulnerability management, threat analysis, security monitoring and incident response, identity and access management  (10%)AppSec reviews, penetration testing and red teaming activities to identify gaps and weaknesses. Utilize red team learnings to improve detection capabilities and response automation (20%)Process automation, orchestration for improving team efficiency, documentation and training  (20%)Data analytics and KPI reporting for ensuring operational effectiveness and controls health (10%)Collects, processes, preserves, analyzes, and presents computer-related evidence in support of breaches, vulnerability mitigation and/or criminal, fraud, counterintelligence, or law enforcement investigations. (10%)Knowledge, Skills and

Experience:
Bachelor's Degree with IT field of study required.8 to 10 Years of relevant work experience.5+ years in security engineering with demonstrated cross-domain experience (SIEM + SOAR or SIEM + Detection).
Proficiency in SIEM query languages (SPL, KQL) AND SOAR playbook development (Python, low-code platforms).
Experience building or integrating AI/ML models for security use cases.
Strong Python skills with familiarity in ML frameworks (scikit-learn, PyTorch) and LLM APIs.
Detection engineering

experience:
Sigma rules, MITRE ATT&CK mapping, rule tuning methodology.
Git-based workflow proficiency for detection-as-code and infrastructure-as-code.
Other Education / Certifications: selection of security and technology certifications and/or equivalent proven work experienceAble to recognize and attend to important details with accuracy and efficiency.
Able to communicate clearly and convey necessary to converse and write effectively in English and local language.
Able to create and conduct formal to interact effectively with all levels of managementPossesses strong multi-cultural interpersonal skills.
Possesses strong leadership skills with a willingness to lead, create new ideas, and be assertive.
Possesses strong organizational and time management ski