Security Analyst - Tier 1
Publicado en 2026-09-23
-
TI/Tecnología
Seguridad cibernética
Stimulating. Motivating. Challenging.Leveraging its long-standing expertise in securing digital content as well as fighting piracy, Kudelski Security, a division of the Kudelski Group, is a provider of cybersecurity solutions and services focused on protecting data, processes and systems for companies and organizations around the world, safeguarding their assets at a time of increasingly remote communications.
Stimulating. Motivating. Challenging.Leveraging its long-standing expertise in securing digital content as well as fighting piracy, Kudelski Security, a division of the Kudelski Group, is a provider of cybersecurity solutions and services focused on protecting data, processes and systems for companies and organizations around the world, safeguarding their assets at a time of increasingly remote communications.
LocationMadrid, Spain
Mission Your MissionAs a Security Analyst Level 1, you are the first line of defense within our 24x7 Managed Detection & Response (MDR) operations, part of the Cyber Fusion Center (CFC) / SOC. Your mission is to monitor, triage, and validate security alerts, ensuring timely escalation of confirmed threats while maintaining high operational quality across a multi-client SOC environment.
You will operate within clearly defined procedures, using modern security tooling and AI-assisted workflows to improve investigation efficiency, documentation quality, and learning velocity—while adhering strictly to escalation paths, data-handling rules, and security policies. You are based in Madrid, Spain, working a 24/7 shift rotation (morning, evening, night, and weekends) in a permanent, full-time role, reporting to the SOC Manager within a team of 15-20 L1 Analysts.
ResponsibilitiesYour responsibilities will be:
- General responsibilities
- Monitor and triage security alerts generated by SIEM, EDR/XDR, firewalls, IC/OT, and other security technologies to determine if further investigation or customer action is warranted.
- Perform first-level incident analysis, validation, and classification following SOPs and playbooks.
- Escalate confirmed, suspicious, or complex incidents to Tier 2 with clear, structured, and complete documentation (what happened, evidence, scope, actions taken, recommended next steps).
- Respond to alerts and tickets within defined SLAs and document all investigation steps accurately in the ticketing system.
- Adhere to internal policies, procedures, and security best practices to protect customer and company data.
- Participate in shift handovers, ensuring continuity of investigations and clear ownership of next actions.
- Contribute to customer satisfaction by handling customer interactions professionally, communicating critical findings, providing accurate information, and ensuring requests are routed to the appropriate teams for timely resolution and support.
- Maintain strong operational discipline: correct priority, categorization, and documentation standards.
- Threat monitoring & incident handling
- Validate alert fidelity by reviewing available telemetry, context, and enrichment to separate false positives from true security events.
- Perform initial scoping (impacted host/user, time window, key indicators, related alerts) using approved tools and data sources.
- Apply predefined containment or response actions only when explicitly authorized by procedures and customer runbooks.
- Collect and preserve relevant artifacts (e.g., alert context, event IDs, process names, hashes, IPs/domains) to support Tier 2 investigations.
- Support ongoing investigations by providing timely updates and evidence to senior analysts.
- Use approved AI tools to summarize alerts, logs, and timelines to accelerate triage.
- Use AI-assisted enrichment to understand unfamiliar indicators, techniques, or tool outputs.
- Identify recurring false positives, noisy detections, and tooling limitations; raise improvement suggestions through defined channels.
- A team-oriented analyst comfortable working in a structured, high-tempo SOC environment.
- Methodical and detail-oriented, able to remain calm under pressure and manage multiple alerts in parallel.
- Curious and motivated to learn cybersecurity operations and modern SOC tooling.
- Clear and professional in written and verbal communication.
- Willing to work in a 24/7 shift-based operation.
- More than 1 year of experience in cybersecurity, IT operations, or a related field (internships, labs, or SOC trainings), typically analyzing logs and host data to identify…
(Si este trabajo está en su jurisdicción, entonces puede estar usando un Proxy o VPN para acceder a este sitio, para seguir avanzando, debe cambiar su conectividad a otro dispositivo móvil o PC).