SOC Analyst
hace 1 semana
Job Title
SOC AnalystOverview
Looking for a challenge in one of the world's leading airline Groups and a dual FTSE 100 and IBEX 35 listed company?
The Group combines airlines in Ireland, the UK and Spain with key non-airline businesses, enabling them to enhance their presence in the aviation market.
Purpose of the role
Investigate & analyze high priority cyber security incidents• Respond to & contain security threats
Execute Cyber Security Incident Response Plan (CIRP)
• Collaborate with internal & external stakeholders
• Document incident response & create reports
Introduce and Utilize security automation & scripting
Accountabilities
Incident Detection and Triage:
Monitor security alerts and logs to detect potential security incidents.
Conduct initial triage and assessment of incidents to determine severity and impact.
Incident Analysis:
Conduct in-depth analysis of security incidents to determine root cause, scope, and extent of compromise.
Analyze malware samples, network traffic, and system logs to identify indicators of compromise (IOCs) and attack patterns.
Incident Response:
Lead and coordinate incident response efforts, including containment, eradication, and recovery activities.
Collaborate with cross-functional teams to mitigate security incidents and minimize business impact.
Forensic Investigation:
Assist partners in/and conduct digital forensic investigations to gather evidence and support incident response efforts.
Preserve and analyze forensic artifacts from compromised systems to identify attacker tactics, techniques, and procedures (TTPs).
Threat Intelligence Analysis:
Analyze threat intelligence feeds and reports to identify emerging threats and vulnerabilities.
Correlate threat intelligence with security events and incidents to enhance detection and response capabilities.
Incident Documentation and Reporting:
Document incident findings, analysis, and response actions in incident reports and case management systems.
Prepare and present post-incident reports to management, stakeholders, and regulatory authorities.
Incident Coordination and Communication:
Coordinate incident response activities with internal teams, external partners, and law enforcement agencies.
Communicate effectively with stakeholders to provide timely updates on incident status and resolution efforts.
Identify areas for process improvement and optimization within the CSIRT function.
Develop and implement enhancements to incident detection, analysis, and response procedures.
Perform Oncall Duties on rota basis during out of office hours
Required Skills, qualifications & experience
Primary Escalation Expertise: Proficient in acting as the primary escalation point, undertaking security analysis on critical alerts, and employing expertise to piece together the attack chain across intricate Environments, including cloud, identity, email, network, and endpoint.
Threat Knowledge: Comprehensive understanding of the cyber threat landscape, particularly as it relates to the aviation sector.
Proactive Threat Hunting: Demonstrated capability to convert threat knowledge into active threat hunting. Skilful in analysing and researching new, emerging, or trending attacks, actors, malware samples, and TTP's.
Communication Proficiency: Must have excellent English reading, writing, and speaking skills with the ability to convey security insights: both in crafting and deciphering security metrics, and in presenting them clearly across all hierarchical levels, up to senior leadership.
Several years of experience in cybersecurity, with a focus on incident detection, analysis, and response.
Experience working in a CIRT or SOC environment, preferably in a senior role. Demonstrated expertise in conducting digital forensic investigations and malware analysis.
Strong understanding of incident response frameworks, methodologies, and best practices (e.g., NIST Incident Response Framework, SANS Incident Handling Process).
Experience with threat intelligence analysis, including the use of threat intelligence feeds and platforms.
Familiarity with network security monitoring tools, SIEM (Security Information and Event Management) systems, and other security technologies.
Department
SOC Tech Leads (David Perez Sanz)Reporting to
David Perez SanzContract type
RegularLocation
-
SOC Analyst
hace 2 semanas
Madrid, Madrid, España Avanade A tiempo completoAs an L2 SOC Analyst at Avanade, you will play a key role in safeguarding enterprise systems by monitoring, detecting, and responding to cybersecurity threats. You will work closely with cross-functional teams to enhance security posture, resolve escalated incidents, and contribute to the continuous improvement of security operations. Your expertise will...
-
SOC Analyst Level 1
hace 9 horas
Madrid, Madrid, España Uk Cyber Defence A tiempo completoRole Overview We are seeking a highly motivated SOC Analyst Level 1 to join our dynamic SOC team. As a Level 1 Analyst, you will be the first line of defence, responsible for monitoring, analysing, and responding to security events and incidents in real time. This is an exciting opportunity to gain hands-on experience and grow within a fast-paced,...
-
Cybersecurity - SOC Analyst
hace 9 horas
Madrid, Madrid, España Capitole A tiempo completoCapitolesigue creciendo, y queremos hacerlo contigoBuscamos un/aSOC Analystapasionado/a por la ciberseguridad para unirse a nuestro equipo multicultural y dinámico. Si te motiva la detección, análisis y respuesta ante incidentes de seguridad, esta oportunidad es para tiRequisitosEstudios en informática, ciberseguridad o cualificación...
-
L2 SOC Analyst
hace 2 semanas
Madrid, Madrid, España EULEN Flexiplán A tiempo completoDesde la división de Operaciones de Ciberseguridad de Grupo EULEN, nos encontramos en búsqueda de un/aAnalista N2para nuestro Departamento deIngeniería de Seguridad.Dentro del equipo, tu misión será garantizar que las plataformas y soluciones de seguridad del SOC funcionen de manera óptima, soportando eficazmente la detección, análisis y respuesta...
-
FULLREMOTE - Cybersecurity - SOC Analyst
hace 9 horas
Madrid, Madrid, España CAPITOLE CONSULTING A tiempo completoOpenings:3- #### Country:España- #### Province:Comunidad de Madrid- #### Description:Capitole Consulting keeps growing and we want to do it with you Are you a passionate Ciber Security - SOC Analyst? We have an exciting opportunity to lead and empower a multicultural team. Responsibilities: • Identification and analysis of security incidents and...
-
SOC Analyst
hace 1 semana
Madrid, Madrid, España IAG Transform A tiempo completoOverviewLooking for a challenge in one of the world's leading airline Groups and a dual FTSE 100 and IBEX 35 listed company?The Group combines airlines in Ireland, the UK and Spain with key non-airline businesses, enabling them to enhance their presence in the aviation market.Purpose of the roleInvestigate & analyze high priority cyber security incidents •...
-
SOC Analyst
hace 1 semana
Madrid, Madrid, España IAG Transform A tiempo completoAbout Us We are part of International Airlines Group (IAG), one of the world's leading airline groups and owner of some of the biggest brands in the sky.IAG Transform provides creative and innovative solutions to drive sustainable transformation by delivering procurement and airline services, as well as group-wide systems across IAG. Each operating company...
-
Cybersecurity Analyst
hace 10 horas
Madrid, Madrid, España Devoteam A tiempo completoDevoteam es una consultora europea líder enfocada en estrategia digital, plataformas tecnológicas, ciberseguridad y transformación empresarial a través de la tecnología.La Tecnología está en nuestro ADN y creemos en ella como una palanca capaz de impulsar el cambio para mejorar, manteniendo un equilibrio que nos permite ofrecer a nuestra cartera de...
-
Freelance Cybersecurity Analyst
hace 7 días
Madrid, Madrid, España Mindrift A tiempo completoThis opportunity is only for candidates currently residing in the specified country. Your location may affect eligibility and rates. Please submit your resume in English and indicate your level of English proficiency.At Mindrift, innovation meets opportunity. We believe in using the power of collective intelligence to ethically shape the future of AI.What...
-
Security Analyst
hace 2 semanas
Madrid, Madrid, España BT Group A tiempo completoPurpose Of Role/ Technical Skills:The role holder will be responsible for the in life delivery of 24x7x365 technical support meeting the agreed contractual SLA's.All communications are in English (both written and spoken) as both the client and all other internal teams that we work with are global so it is important to have a good English level.Despite...