Cybersecurity Operations Engineer

hace 3 días


Barcelona, Barcelona, España AstraZeneca A tiempo completo

Role based in Barcelona - 3 days office/2 days home

As a Cybersecurity Operations Engineer at Evinova, you will play a key role in strengthening our operational security posture by leading hands-on technical activities across detection engineering, incident response, and cloud security. You will work within the Cybersecurity Operations function to ensure continuous monitoring, visibility, and control across cloud, SaaS, and enterprise platforms.

The role focuses on the operation and optimization of our SIEM and SOAR platforms (Splunk Cloud Enterprise Security and Splunk SOAR), integrating critical data sources from AWS, Microsoft 365, and SaaS environments, and developing high-fidelity detections that enable proactive threat response. You will also provide technical leadership supporting IT, Infrastructure, and Cloud teams in implementing hardening standards, configuration validation, and secure-by-design practices.

Success in this role means maintaining strong visibility across our digital landscape, driving automation for detection and response, and ensuring that cloud and endpoint platforms remain protected and compliant with Evinova's cybersecurity standards and global frameworks such as ISO 27001, SOC 2, and NIST CSF.

This position is ideal for a technically skilled cybersecurity professional who thrives in a fast-paced global environment and enjoys solving complex operational challenges while contributing directly to securing Evinova's digital health platforms.

Key Responsibilities:

Security Monitoring and Detection Engineering

  • Maintain and operate the organization's SIEM and SOAR platforms (Splunk Enterprise Security and SOAR) to ensure continuous, reliable, and scalable security monitoring.

  • Develop and manage log source integrations across cloud and SaaS environments including infrastructure, applications, identity providers, and endpoints.

  • Collaborate with the external SOC on rule tuning, enrichment mapping, and validation of false-positive reduction efforts.

  • Create and maintain dashboards, reports, and visualizations to support SOC operations, threat hunting, and management visibility.

  • Monitor and optimize SIEM ingestion performance, ensuring efficient parsing, filtering, and normalization of logs to control license consumption.

  • Conduct periodic use-case reviews to ensure alignment with the evolving threat landscape, business priorities, and technology stack.

Incident Response and Operations Support

  • Collaborate with the Security Operations, Incident Response, and Threat Intelligence teams to improve detection coverage and response playbooks.

  • Provide tier-3 support during incident investigations, including forensic data extraction and SIEM correlation analysis.

  • Participate in on-call escalation for critical incidents requiring Splunk or SOAR expertise.

  • Support IT and Cloud teams during investigations involving phishing, account compromise, or insider risk events.

  • Collaborate on technical implementations of security controls and alerting mechanisms within cloud and SaaS platforms integrated into the SIEM and SOAR environment.

Automation and Continuous Improvement

  • Automate repetitive processes and data enrichment using scripting (Python, PowerShell) or integrations with SOAR and third-party APIs.

  • Support automation of compliance evidence collection, aligning outputs with ISO 27001 and SOC 2 control families.

  • Evaluate and recommend improvements to SIEM architecture, detection capabilities, and enrichment logic in coordination with the Director of Cybersecurity Operations.

  • Contribute to the roadmap and maturity development of Evinova's security monitoring and detection engineering functions.

  • Support the development of operational runbooks, standard operating procedures, and integration documentation for SecOps processes.

Minimum Qualifications:

  • Bachelor's degree in Cybersecurity, Management / Business Information Systems, Computer Science, or a related field.

  • 4+ years of experience in cybersecurity roles.

  • 2+ years of experience working with SIEM platforms (preferably Splunk ES and MS Sentinel).

  • Familiarity with cybersecurity guidance, frameworks, and standards such as ISO 27001, SOC 2, or CIS Controls.

  • Ability to work cross-functionally with engineering, product, and legal teams.

  • Proactive, curious, and eager to learn in a fast-paced, evolving environment.

  • Strong understanding of log management, event correlation, and alerting principles.

  • Proficiency in developing and tuning detection rules, dashboards, and reports.

  • Knowledge of security operations, incident response, and threat detection workflows.

  • Scripting ability in Python, PowerShell, or similar for automation and data enrichment.

  • Understanding of the MITRE ATT&CK framework and its application in detection engineering.

  • Strong analytical, troubleshooting, communication, and documentation skills.

  • Fluency in English (written and spoken).

Desired Qualifications:

  • Experience with SOAR platforms and automated playbook development.

  • Hands-on familiarity with endpoint detection and response (EDR) solutions.

  • Experience with cloud security environments (AWS, Azure) and related log sources.

  • Understanding of vulnerability management and exposure reduction processes.

  • Prior experience in a global or distributed Security Operations environment

Evinova delivers market-leading digital health solutions that are science-based, evidence-led, and human experience-driven. Thoughtful risks and quick decisions come together to accelerate innovation across the life sciences sector. Be part of a diverse team that pushes the boundaries of science by digitally empowering a deeper understanding of the patients we're helping. Launch pioneering digital solutions that improve the patients' experience and deliver better health outcomes. Together, we have the opportunity to combine deep scientific expertise with digital and artificial intelligence to serve the wider healthcare community and create new standards across the sector.


  • Cybersecurity Architect

    hace 1 semana


    Barcelona, Barcelona, España Michael Page A tiempo completo

    This role is part of the Product Cybersecurity Department, a specialized unit within the organization dedicated to safeguarding the security of its products and servicesDetalles del clienteDesign, implement, test, and manage security solutions that protect systems, networks, and data. It requires a strong grasp of current and emerging cybersecurity threats,...


  • Barcelona, Barcelona, España Michael Page A tiempo completo

    Perfil buscado (Hombre/Mujer)• Conduct threat modeling and define security controls for complex applications and web-based platforms.• Develop and apply advanced hardening techniques for operating systems.• Design and implement basic network security mechanisms such as VPNs and tunneling.• Configure robust security settings for cloud-based...


  • Barcelona, Barcelona, España Talent-R A tiempo completo

    Job Description : Segment: INFRASTRUCTURE_SERVICES_WORKPLACERequested Profile: Operations Engineerjob title: Cloud Security Operations EngineerPrefered experience: 3–7 years in cybersecurity or cloud operationsHands-on experience with cloud-native security tools and servicesExperience with compliance frameworks (ISO 27001, NIST, CIS, GDPR)Very good...


  • Barcelona, Barcelona, España AGH Ibérica A tiempo completo

    Desde AGH Ibérica, nos encontramos en la búsqueda de un perfil Cybersecurity Support Engineer  , para formar parte de uno de nuestros clientes del sector de la seguridad.¿Qué tareas realizarás en tu día a día?Administración y soporte de infraestructuras de ciberseguridad de entornos de NGFW.Operación y administración de equipamientos y entornos...


  • Barcelona, Barcelona, España Fynity A tiempo completo

    Senior Cloud Security Operations Engineer – Barcelona (Hybrid)Fynity is supporting a rapidly scaling SaaS company headquartered in Barcelona in the search for an experienced and proactiveSenior Cloud Security Operations Engineerto join their growing Security Operations team (5 Engineers + Manager).This is a hands-on role where you'll drive detection,...

  • Cybersecurity Engineer

    hace 2 semanas


    Barcelona, Barcelona, España Abacum Inc A tiempo completo

    About AbacumAbacum is the leading Business Planning solution for finance teams to drive performance. By automating reporting, enabling collaboration, and simplifying planning and forecasting, we help finance teams shift from number crunching to driving strategic decisions.Founded in 2020 by two former CFOs, we've grown into a global team of 100+ people...

  • Sales Engineer

    hace 2 semanas


    Barcelona, Barcelona, España Zynap A tiempo completo

    About ZynapZynap is redefining how companies defend themselves in cyberspace, building the first AI agent workflow platform for preventive cybersecurity.Our AI-driven platform acts as the operational brain for security teams, automating what slows them down, connecting what's fragmented, and transforming threat intelligence into proactive defense. By...


  • Barcelona, Barcelona, España psd group A tiempo completo

    Cybersecurity Project ManagerSummaryLocation:Barcelona (Hybrid)Day Rate:NegotiableDuration:12 MonthsAvailability:ASAPAbout the ClientMy client is the air transport industry's IT provider, delivering solutions for airlines, airports, aircraft, and governments. Their technology powers more seamless, safe, and sustainable air travel.They are looking to hire an...


  • Barcelona, Barcelona, España Factorial A tiempo completo

    Hey there, Cybersecurity EnthusiastsFactorial is looking for a skilled and experienced Senior Cloud Security Operations Engineer to join our team and strengthen the security of our systems and infrastructure. As a key member of the Security Operations Team, you will be responsible for protecting our environments and ensuring the security of our data. You'll...

  • Operations Engineer

    hace 1 semana


    Barcelona, Barcelona, España Qualifyze A tiempo completo

    About QualifyzeFounded in 2019, Qualifyze is a leading company in supply chain compliance management in the Life Sciences industry, trusted by over 1,500 pharmaceutical and healthcare companies globally. Our digital suite of solutions connects manufacturers, suppliers, and a global network of more than 250 auditors and quality experts.With a track record of...