Security Analyst Tier 1

Hace 5 días

valencia, província de valència, España Confidential Jornada completa

Your Mission


As a Security Analyst Level 1, you are the first line of defense within our 24x7 Managed Detection & Response (MDR) operations, part of the Cyber Fusion Center (CFC) / SOC. Your mission is to monitor, triage, and validate security alerts, ensuring timely escalation of confirmed threats while maintaining high operational quality across a multi-client SOC environment .


You will operate within clearly defined procedures, using modern security tooling and AI-assisted workflows to improve investigation efficiency, documentation quality, and learning velocity—while adhering strictly to escalation paths, data-handling rules, and security policies. You are based in Madrid, Spain, working a 24/7 shift rotation (morning, evening, night, and weekends) in a permanent, full-time role, reporting to the SOC Manager within a team of 15-20 L1 Analysts.


Your responsibilities will be:


  1. General responsibilities
  • Monitor and triage security alerts generated by SIEM, EDR/XDR, firewalls, ICS/OT, and other security technologies to determine if further investigation or customer action is warranted.
  • Perform first-level incident analysis, validation, and classification following SOPs and playbooks.
  • Escalate confirmed, suspicious, or complex incidents to Tier 2 with clear, structured, and complete documentation (what happened, evidence, scope, actions taken, recommended next steps).
  • Respond to alerts and tickets within defined SLAs and document all investigation steps accurately in the ticketing system.
  • Adhere to internal policies, procedures, and security best practices to protect customer and company data.
  • Participate in shift handovers, ensuring continuity of investigations and clear ownership of next actions.
  • Contribute to customer satisfaction by handling customer interactions professionally, communicating critical findings, providing accurate information, and ensuring requests are routed to the appropriate teams for timely resolution and support.
  • Maintain strong operational discipline: correct priority, categorization, and documentation standards.


  1. Threat monitoring & incident handling
  • Validate alert fidelity by reviewing available telemetry, context, and enrichment to separate false positives from true security events.
  • Perform initial scoping (impacted host/user, time window, key indicators, related alerts) using approved tools and data sources.
  • Apply predefined containment or response actions only when explicitly authorized by procedures and customer runbooks.
  • Collect and preserve relevant artifacts (e.g., alert context, event IDs, process names, hashes, IPs/domains) to support Tier 2 investigations.
  • Support ongoing investigations by providing timely updates and evidence to senior analysts.
  • Use approved AI tools to summarize alerts, logs, and timelines to accelerate triage.
  • Use AI-assisted enrichment to understand unfamiliar indicators, techniques, or tool outputs.
  • Identify recurring false positives, noisy detections, and tooling limitations; raise improvement suggestions through defined channels.



You are

  • A team-oriented analyst comfortable working in a structured, high-tempo SOC environment.
  • Methodical and detail-oriented, able to remain calm under pressure and manage multiple alerts in parallel.
  • Curious and motivated to learn cybersecurity operations and modern SOC tooling.
  • Clear and professional in written and verbal communication.
  • Willing to work in a 24/7 shift-based operation.


You have

  • More than 1 year of experience in cybersecurity, IT operations, or a related field (internships, labs, or SOC trainings), typically analyzing logs and host data to identify suspicious/abnormal activity.
  • Initial to intermediate exposure to SIEM and/or EDR/XDR platforms for log analysis and detection.
  • Understanding of TCP/IP, secu