SOC Analyst

hace 1 semana


Madrid, Madrid, España International Airlines Group A tiempo completo

Job Title

SOC Analyst

Overview  

Looking for a challenge in one of the world's leading airline Groups and a dual FTSE 100 and IBEX 35 listed company?  
The Group combines airlines in Ireland, the UK and Spain with key non-airline businesses, enabling them to enhance their presence in the aviation market. 

Purpose of the role

Investigate & analyze high priority cyber security incidents
• Respond to & contain security threats

Execute Cyber Security Incident Response Plan (CIRP)
• Collaborate with internal & external stakeholders
• Document incident response & create reports

Introduce and Utilize security automation & scripting

Accountabilities

Incident Detection and Triage:
Monitor security alerts and logs to detect potential security incidents.
Conduct initial triage and assessment of incidents to determine severity and impact.
Incident Analysis:
Conduct in-depth analysis of security incidents to determine root cause, scope, and extent of compromise.
Analyze malware samples, network traffic, and system logs to identify indicators of compromise (IOCs) and attack patterns.
Incident Response:
Lead and coordinate incident response efforts, including containment, eradication, and recovery activities.
Collaborate with cross-functional teams to mitigate security incidents and minimize business impact.
Forensic Investigation:
Assist partners in/and conduct digital forensic investigations to gather evidence and support incident response efforts.
Preserve and analyze forensic artifacts from compromised systems to identify attacker tactics, techniques, and procedures (TTPs).
Threat Intelligence Analysis:
Analyze threat intelligence feeds and reports to identify emerging threats and vulnerabilities.
Correlate threat intelligence with security events and incidents to enhance detection and response capabilities.
Incident Documentation and Reporting:
Document incident findings, analysis, and response actions in incident reports and case management systems.
Prepare and present post-incident reports to management, stakeholders, and regulatory authorities.
Incident Coordination and Communication:
Coordinate incident response activities with internal teams, external partners, and law enforcement agencies.
Communicate effectively with stakeholders to provide timely updates on incident status and resolution efforts.
Identify areas for process improvement and optimization within the CSIRT function.
Develop and implement enhancements to incident detection, analysis, and response procedures.
Perform Oncall Duties on rota basis during out of office hours

Required Skills, qualifications & experience

Primary Escalation Expertise: Proficient in acting as the primary escalation point, undertaking security analysis on critical alerts, and employing expertise to piece together the attack chain across intricate Environments, including cloud, identity, email, network, and endpoint.
Threat Knowledge: Comprehensive understanding of the cyber threat landscape, particularly as it relates to the aviation sector.
Proactive Threat Hunting: Demonstrated capability to convert threat knowledge into active threat hunting. Skilful in analysing and researching new, emerging, or trending attacks, actors, malware samples, and TTP's.
Communication Proficiency: Must have excellent English reading, writing, and speaking skills with the ability to convey security insights: both in crafting and deciphering security metrics, and in presenting them clearly across all hierarchical levels, up to senior leadership.

Several years of experience in cybersecurity, with a focus on incident detection, analysis, and response.

Experience working in a CIRT or SOC environment, preferably in a senior role. Demonstrated expertise in conducting digital forensic investigations and malware analysis.

Strong understanding of incident response frameworks, methodologies, and best practices (e.g., NIST Incident Response Framework, SANS Incident Handling Process).

Experience with threat intelligence analysis, including the use of threat intelligence feeds and platforms.

Familiarity with network security monitoring tools, SIEM (Security Information and Event Management) systems, and other security technologies.

Department

SOC Tech Leads (David Perez Sanz)

Reporting to

David Perez Sanz

Contract type

Regular

Location


  • SOC Analyst

    hace 2 semanas


    Madrid, Madrid, España Avanade A tiempo completo

    As an L2 SOC Analyst at Avanade, you will play a key role in safeguarding enterprise systems by monitoring, detecting, and responding to cybersecurity threats. You will work closely with cross-functional teams to enhance security posture, resolve escalated incidents, and contribute to the continuous improvement of security operations. Your expertise will...

  • SOC Analyst Level 1

    hace 8 horas


    Madrid, Madrid, España Uk Cyber Defence A tiempo completo

    Role Overview We are seeking a highly motivated SOC Analyst Level 1 to join our dynamic SOC team. As a Level 1 Analyst, you will be the first line of defence, responsible for monitoring, analysing, and responding to security events and incidents in real time. This is an exciting opportunity to gain hands-on experience and grow within a fast-paced,...

  • SOC Analyst

    hace 1 semana


    Madrid, Madrid, España IAG Transform A tiempo completo

    OverviewLooking for a challenge in one of the world's leading airline Groups and a dual FTSE 100 and IBEX 35 listed company?The Group combines airlines in Ireland, the UK and Spain with key non-airline businesses, enabling them to enhance their presence in the aviation market.Purpose of the roleInvestigate & analyze high priority cyber security incidents •...

  • SOC Analyst

    hace 1 semana


    Madrid, Madrid, España IAG Transform A tiempo completo

    About Us We are part of International Airlines Group (IAG), one of the world's leading airline groups and owner of some of the biggest brands in the sky.IAG Transform provides creative and innovative solutions to drive sustainable transformation by delivering procurement and airline services, as well as group-wide systems across IAG. Each operating company...

  • Cybersecurity Analyst

    hace 2 semanas


    Madrid, Madrid, España Devoteam A tiempo completo

    Company Description Devoteam es una consultora europea líder enfocada en estrategia digital, plataformas tecnológicas, ciberseguridad y transformación empresarial a través de la tecnología.La Tecnología está en nuestro ADN y creemos en ella como una palanca capaz de impulsar el cambio para mejorar, manteniendo un equilibrio que nos permite ofrecer a...

  • Marketing Data Analyst

    hace 2 semanas


    Madrid, Madrid, España Appfire Technologies. A tiempo completo

    At Appfire, we believe that great work happens when people get to choose how they work. After 20 years of creating software that empowers teams to break silos and collaborate seamlessly, we've learned that one size does not fit all. That's why at Appfire, you choose. Choose to work where you thrive: Whether from home, in one of our offices, or while...


  • Madrid, Madrid, España Mindrift A tiempo completo

    This opportunity is only for candidates currently residing in the specified country. Your location may affect eligibility and rates. Please submit your resume in English and indicate your level of English proficiency.At Mindrift, innovation meets opportunity. We believe in using the power of collective intelligence to ethically shape the future of AI.What...

  • Security Analyst

    hace 2 semanas


    Madrid, Madrid, España BT Group A tiempo completo

    Purpose Of Role/ Technical Skills:The role holder will be responsible for the in life delivery of 24x7x365 technical support meeting the agreed contractual SLA's.All communications are in English (both written and spoken) as both the client and all other internal teams that we work with are global so it is important to have a good English level.Despite...


  • Madrid, Madrid, España Synlab Global A tiempo completo

    DescriptionAs a Cyber Security Senior Specialist within the Security Operations Center (SOC), you will play a critical role in safeguarding the organization's information systems and data against cyber threats. This position requires proactive leadership in security operations, ensuring effective monitoring, detection, and response to emerging...


  • Madrid, Madrid, España Boomi A tiempo completo

    About Boomi and What Makes Us SpecialAre you ready to work at a fast-growing company where you can make a difference? Boomi aims to make the world a better place by connecting everyone to everything, anywhere. Our award-winning, intelligent integration and automation platform helps organizations power the future of business. At Boomi, you'll work with...