Security Analyst Tier 1
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Your Mission
As a Security Analyst Level 1, you are the first line of defense within our 24x7 Managed Detection & Response (MDR) operations, part of the Cyber Fusion Center (CFC) / SOC. Your mission is to monitor, triage, and validate security alerts, ensuring timely escalation of confirmed threats while maintaining high operational quality across a multi-client SOC environment .
You will operate within clearly defined procedures, using modern security tooling and AI-assisted workflows to improve investigation efficiency, documentation quality, and learning velocity—while adhering strictly to escalation paths, data-handling rules, and security policies. You are based in Madrid, Spain, working a 24/7 shift rotation (morning, evening, night, and weekends) in a permanent, full-time role, reporting to the SOC Manager within a team of 15-20 L1 Analysts.
Your responsibilities will be:
- General responsibilities
- Monitor and triage security alerts generated by SIEM, EDR/XDR, firewalls, ICS/OT, and other security technologies to determine if further investigation or customer action is warranted.
- Perform first-level incident analysis, validation, and classification following SOPs and playbooks.
- Escalate confirmed, suspicious, or complex incidents to Tier 2 with clear, structured, and complete documentation (what happened, evidence, scope, actions taken, recommended next steps).
- Respond to alerts and tickets within defined SLAs and document all investigation steps accurately in the ticketing system.
- Adhere to internal policies, procedures, and security best practices to protect customer and company data.
- Participate in shift handovers, ensuring continuity of investigations and clear ownership of next actions.
- Contribute to customer satisfaction by handling customer interactions professionally, communicating critical findings, providing accurate information, and ensuring requests are routed to the appropriate teams for timely resolution and support.
- Maintain strong operational discipline: correct priority, categorization, and documentation standards.
- Threat monitoring & incident handling
- Validate alert fidelity by reviewing available telemetry, context, and enrichment to separate false positives from true security events.
- Perform initial scoping (impacted host/user, time window, key indicators, related alerts) using approved tools and data sources.
- Apply predefined containment or response actions only when explicitly authorized by procedures and customer runbooks.
- Collect and preserve relevant artifacts (e.g., alert context, event IDs, process names, hashes, IPs/domains) to support Tier 2 investigations.
- Support ongoing investigations by providing timely updates and evidence to senior analysts.
- Use approved AI tools to summarize alerts, logs, and timelines to accelerate triage.
- Use AI-assisted enrichment to understand unfamiliar indicators, techniques, or tool outputs.
- Identify recurring false positives, noisy detections, and tooling limitations; raise improvement suggestions through defined channels.
You are
- A team-oriented analyst comfortable working in a structured, high-tempo SOC environment.
- Methodical and detail-oriented, able to remain calm under pressure and manage multiple alerts in parallel.
- Curious and motivated to learn cybersecurity operations and modern SOC tooling.
- Clear and professional in written and verbal communication.
- Willing to work in a 24/7 shift-based operation.
You have
- More than 1 year of experience in cybersecurity, IT operations, or a related field (internships, labs, or SOC trainings), typically analyzing logs and host data to identify suspicious/abnormal activity.
- Initial to intermediate exposure to SIEM and/or EDR/XDR platforms for log analysis and detection.
- Understanding of TCP/IP, secu