Up to €70K
Blue Card threshold🇬🇧 🇪🇸Cyber Threat Intelligence Analyst
Madrid, Spain·Added 16 days ago
29 open roles
What they offer
Hybrid
Only from certain places, per the ad: “This position is available only in Spain due to the restrictions of some of the intelligence sources.”
What they ask for
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Be near Madrid for hybrid days
No relocation package mentioned.
Have 4+ years of experience
Mid-level role.
About the job
SIX drives the transformation of financial markets.
What sets us apart drives us ahead: between local roots and global relevance, we are a unique blend of tradition and future, of foundation and growth. We value bright minds and inspire them to grow with their ideas. Come and shape the future of finance with us.
We are seeking a motivated Cyber Threat Intelligence (CTI) Analyst with a strong technical mindset to support the intelligence collection, automation and maturation of our intelligence capabilities.
The focus of this role in Cyber Threat Intelligence is to enhance cyber threat intelligence capabilities through automation, AI-driven analysis, and continuous improvement of telemetry and intelligence workflows. You will work closely with senior team members and partners to enhance the company's intelligence capabilities.
What you'll do
- Monitor, collect, and analyze intelligence from restricted communities, internal telemetry, and monitoring systems to identify actionable insights and support investigations, incident response, and threat detection activities.
- Own and continuously improve weekly intelligence telemetry reporting, dashboards, and visualization capabilities to provide accurate, consistent, and actionable insights to stakeholders.
- Contribute to the automation and orchestration of CTI workflows, including data collection, enrichment, analysis, reporting, and the integration of AI-driven capabilities for correlation, prioritization, and analytical output generation.
- Work with Threat Intelligence Platforms and security tooling, including OpenCTI, Elastic stack, SIEM, Threat Intelligence Platforms, and malware sandboxes, while applying frameworks such as MITRE ATT&CK to contextualize threats and improve detection effectiveness.
- Collaborate with SOC, Detection & Hunting, Vulnerability Management, Corporate Security, and other cross-functional teams to operationalize intelligence insights, produce threat reports and executive summaries, and support the continuous improvement and scalability of CTI processes.
What we're looking for
- 4 years of experience in Cyber Threat Intelligence, incident response, SOC, or related technical cybersecurity roles.
- Strong technical profile with hands-on experience in automation, scripting, or orchestration
- Familiarity with AI applications in cybersecurity, particularly for automation, data processing, analytics, and intelligence workflow improvement.
- Experience with Threat Intelligence Platforms and security monitoring tools, including OpenCTI, Elastic stack, SIEM platforms, or similar technologies.
- Solid understanding of the intelligence lifecycle, telemetry analysis, tactical intelligence collection, and frameworks such as MITRE ATT&CK for threat detection and analysis
How you'll work
Madrid | Working from home up to 40% | Reference 8095
- Join an international Cyber Threat Intelligence team operating 24x7, including on-call availability when required.
Visa & relocation
This position is available only in Spain due to the restrictions of some of the intelligence sources.
Hiring process
If you have any questions, check out our FAQ page or call Yuliya Stoyko at +34 917095993.
For this vacancy we only accept direct applications.
Additional information
Diversity is important to us. Therefore, we are looking to receiving applications regardless of any personal background.
How they hire
Application review, then generally two to three interviews, online or in person; some roles add a case study or an individual assessment 3 interviews
- SIX aims to respond to every application within two weeks.
- Only direct applications through the careers website are considered.
More jobs like this
or browse Madrid·Security·Security·Mid-level·Hybrid·Cybersecurity·Community of Madrid·Financial Markets



