SOC Analyst

hace 1 semana


Madrid, Madrid, España International Airlines Group A tiempo completo

Job Title

SOC Analyst

Overview  

Looking for a challenge in one of the world's leading airline Groups and a dual FTSE 100 and IBEX 35 listed company?  
The Group combines airlines in Ireland, the UK and Spain with key non-airline businesses, enabling them to enhance their presence in the aviation market. 

Purpose of the role

Investigate & analyze high priority cyber security incidents
• Respond to & contain security threats

Execute Cyber Security Incident Response Plan (CIRP)
• Collaborate with internal & external stakeholders
• Document incident response & create reports

Introduce and Utilize security automation & scripting

Accountabilities

Incident Detection and Triage:
Monitor security alerts and logs to detect potential security incidents.
Conduct initial triage and assessment of incidents to determine severity and impact.
Incident Analysis:
Conduct in-depth analysis of security incidents to determine root cause, scope, and extent of compromise.
Analyze malware samples, network traffic, and system logs to identify indicators of compromise (IOCs) and attack patterns.
Incident Response:
Lead and coordinate incident response efforts, including containment, eradication, and recovery activities.
Collaborate with cross-functional teams to mitigate security incidents and minimize business impact.
Forensic Investigation:
Assist partners in/and conduct digital forensic investigations to gather evidence and support incident response efforts.
Preserve and analyze forensic artifacts from compromised systems to identify attacker tactics, techniques, and procedures (TTPs).
Threat Intelligence Analysis:
Analyze threat intelligence feeds and reports to identify emerging threats and vulnerabilities.
Correlate threat intelligence with security events and incidents to enhance detection and response capabilities.
Incident Documentation and Reporting:
Document incident findings, analysis, and response actions in incident reports and case management systems.
Prepare and present post-incident reports to management, stakeholders, and regulatory authorities.
Incident Coordination and Communication:
Coordinate incident response activities with internal teams, external partners, and law enforcement agencies.
Communicate effectively with stakeholders to provide timely updates on incident status and resolution efforts.
Identify areas for process improvement and optimization within the CSIRT function.
Develop and implement enhancements to incident detection, analysis, and response procedures.
Perform Oncall Duties on rota basis during out of office hours

Required Skills, qualifications & experience

Primary Escalation Expertise: Proficient in acting as the primary escalation point, undertaking security analysis on critical alerts, and employing expertise to piece together the attack chain across intricate Environments, including cloud, identity, email, network, and endpoint.
Threat Knowledge: Comprehensive understanding of the cyber threat landscape, particularly as it relates to the aviation sector.
Proactive Threat Hunting: Demonstrated capability to convert threat knowledge into active threat hunting. Skilful in analysing and researching new, emerging, or trending attacks, actors, malware samples, and TTP's.
Communication Proficiency: Must have excellent English reading, writing, and speaking skills with the ability to convey security insights: both in crafting and deciphering security metrics, and in presenting them clearly across all hierarchical levels, up to senior leadership.

Several years of experience in cybersecurity, with a focus on incident detection, analysis, and response.

Experience working in a CIRT or SOC environment, preferably in a senior role. Demonstrated expertise in conducting digital forensic investigations and malware analysis.

Strong understanding of incident response frameworks, methodologies, and best practices (e.g., NIST Incident Response Framework, SANS Incident Handling Process).

Experience with threat intelligence analysis, including the use of threat intelligence feeds and platforms.

Familiarity with network security monitoring tools, SIEM (Security Information and Event Management) systems, and other security technologies.

Department

SOC Tech Leads (David Perez Sanz)

Reporting to

David Perez Sanz

Contract type

Regular

Location


  • SOC Analyst

    hace 2 semanas


    Madrid, Madrid, España Avanade A tiempo completo

    As an L2 SOC Analyst at Avanade, you will play a key role in safeguarding enterprise systems by monitoring, detecting, and responding to cybersecurity threats. You will work closely with cross-functional teams to enhance security posture, resolve escalated incidents, and contribute to the continuous improvement of security operations. Your expertise will...

  • SOC Analyst Level 1

    hace 9 horas


    Madrid, Madrid, España Uk Cyber Defence A tiempo completo

    Role Overview We are seeking a highly motivated SOC Analyst Level 1 to join our dynamic SOC team. As a Level 1 Analyst, you will be the first line of defence, responsible for monitoring, analysing, and responding to security events and incidents in real time. This is an exciting opportunity to gain hands-on experience and grow within a fast-paced,...


  • Madrid, Madrid, España Capitole A tiempo completo

    Capitolesigue creciendo, y queremos hacerlo contigoBuscamos un/aSOC Analystapasionado/a por la ciberseguridad para unirse a nuestro equipo multicultural y dinámico. Si te motiva la detección, análisis y respuesta ante incidentes de seguridad, esta oportunidad es para tiRequisitosEstudios en informática, ciberseguridad o cualificación...

  • L2 SOC Analyst

    hace 2 semanas


    Madrid, Madrid, España EULEN Flexiplán A tiempo completo

    Desde la división de Operaciones de Ciberseguridad de Grupo EULEN, nos encontramos en búsqueda de un/aAnalista N2para nuestro Departamento deIngeniería de Seguridad.Dentro del equipo, tu misión será garantizar que las plataformas y soluciones de seguridad del SOC funcionen de manera óptima, soportando eficazmente la detección, análisis y respuesta...


  • Madrid, Madrid, España CAPITOLE CONSULTING A tiempo completo

    Openings:3- #### Country:España- #### Province:Comunidad de Madrid- #### Description:Capitole Consulting keeps growing and we want to do it with you Are you a passionate Ciber Security - SOC Analyst? We have an exciting opportunity to lead and empower a multicultural team. Responsibilities: • Identification and analysis of security incidents and...

  • SOC Analyst

    hace 1 semana


    Madrid, Madrid, España IAG Transform A tiempo completo

    OverviewLooking for a challenge in one of the world's leading airline Groups and a dual FTSE 100 and IBEX 35 listed company?The Group combines airlines in Ireland, the UK and Spain with key non-airline businesses, enabling them to enhance their presence in the aviation market.Purpose of the roleInvestigate & analyze high priority cyber security incidents •...

  • SOC Analyst

    hace 1 semana


    Madrid, Madrid, España IAG Transform A tiempo completo

    About Us We are part of International Airlines Group (IAG), one of the world's leading airline groups and owner of some of the biggest brands in the sky.IAG Transform provides creative and innovative solutions to drive sustainable transformation by delivering procurement and airline services, as well as group-wide systems across IAG. Each operating company...

  • Cybersecurity Analyst

    hace 10 horas


    Madrid, Madrid, España Devoteam A tiempo completo

    Devoteam es una consultora europea líder enfocada en estrategia digital, plataformas tecnológicas, ciberseguridad y transformación empresarial a través de la tecnología.La Tecnología está en nuestro ADN y creemos en ella como una palanca capaz de impulsar el cambio para mejorar, manteniendo un equilibrio que nos permite ofrecer a nuestra cartera de...


  • Madrid, Madrid, España Mindrift A tiempo completo

    This opportunity is only for candidates currently residing in the specified country. Your location may affect eligibility and rates. Please submit your resume in English and indicate your level of English proficiency.At Mindrift, innovation meets opportunity. We believe in using the power of collective intelligence to ethically shape the future of AI.What...

  • Security Analyst

    hace 2 semanas


    Madrid, Madrid, España BT Group A tiempo completo

    Purpose Of Role/ Technical Skills:The role holder will be responsible for the in life delivery of 24x7x365 technical support meeting the agreed contractual SLA's.All communications are in English (both written and spoken) as both the client and all other internal teams that we work with are global so it is important to have a good English level.Despite...