The English-language job board for Spain
Cybersecurity Intelligence Analyst
Hybrid in Almería·Added today
125 open roles
Overview
Job details
Permanent contract
Per the ad.
Hybrid
Office and home days — the ad has the split.
Requirements
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Work in English
English is required, per the ad.
Be near Almería for hybrid days
No relocation package mentioned.
Have 10+ years of experience
Mid-level role.
University degree
“Titulación: Licenciados y grados en Informática, Telecomunicaciones o similar” — per the ad.
This job was automatically translated to English.
Pay & benefits
What you'll get
-
Opportunity to integrate into a team of professionals, committed to a project of the present and future whose collaborative and dynamic work environment will facilitate a diversity of possibilities for professional growth and development.
-
Continuous training and availability of a personalized itinerary.
-
Possibility of flexible working day and schedule, depending on the project.
-
Compensation and social benefits: Flexible remuneration (Health Insurance, Childcare Vouchers, etc.), and special financial conditions.
-
Support and Wellbeing programs attending to your personal needs.
-
Access to various Volunteering Programs where you can get involved and leave a positive mark
-
Possibility of hybrid work.
-
Permanent contract in a reliable and continuously evolving project with remuneration according to your experience and value contribution.
Start date: Immediate
Work center: Almería, Barcelona, Málaga, Valencia or Madrid
Requirements
What we're looking for
Qualification: Bachelor's or Degree in Computer Science, Telecommunications or similar
Knowledge and/or experience:
-
Experience leading Threat Intelligence, Digital Surveillance, and Cyber Fraud teams.
-
Knowledge of cloud infrastructures and TTPs used by threat actors to compromise these types of architectures.
-
Experience of at least 10 years in threat identification, modeling, and management.
-
Analytical and investigative capacity, as well as incident response.
-
Experience at the malware analysis level, TTP identification, and IOC extraction.
-
Experience in producing technical and executive reports.
-
Experience in the definition of Threat Identification and Management models.
-
Digital forensics of clients who have suffered digital fraud.
-
Experience in the design and implementation of automatic management and blocking systems for IOCs.
-
Knowledge of the latest threats in the banking sector at a technological and fraud level, as well as the identification of groups and APTs that affect us.
-
Advanced knowledge of MITRE ATT&CK and MITRE D3FEND.
-
OSINT research for the identification of actors and threats.
-
Information gathering and infiltration to learn adversary TTPs.
-
Knowledge and experience in the deployment, sizing, and management of TIP architectures (MISP, Minemeld, Maltiverse, SocRadar...).
-
Experience in Hunting on XDR and/or SIEM platforms (Splunk, QRadar, XSIAM, Cortex XDR, ElasticSearch...).
-
Knowledge and experience in the sizing, deployment, and management of BAS architectures (Mandiant, Cymulate..) and rule creation.
-
Knowledge of Vulnerability Management platforms (Qualys, Nessus...)
-
Intermediate/advanced knowledge in process automation.
-
Intermediate/advanced knowledge in Python development.
-
Experience in the construction and execution of Yara rules.
-
Intermediate knowledge of operating systems and virtualization, container, and/or orchestration platforms (Linux, Windows, Docker, Kubernetes, Openshift...).
-
Intermediate/advanced level of English.
-
Knowledge of network protocols and technologies.
Skills:
-
Security certifications (CEH, CTIA, SANS, FOR578...)
-
Teamwork capacity is essential.
-
Critical thinking with high capacity for observation and analysis.
-
Good written and verbal communication skills.
-
Good planning capacity and orientation towards both objectives and processes.
-
Attitude and orientation towards quality and detail.
Nice to have
-
Knowledge of LLM models and AI is valued.
-
Experience in environments subject to financial system regulations (DORA, SWIFT, PCI...) is valued.
The role
What you'll do
- Investigate threats, IoCs, and TTPs
- Analyze indicators and techniques of malicious actors to support threat hunting, signature development, and the TIP platform.
- Maintenance of the entity's current model for Threat Identification and Management.
- Maintenance of the entity's automatic IOC blocking system.
- Manage integration projects for security platforms regarding Threat Intelligence, Digital Surveillance, and/or Fraud.
- Support cybersecurity assessments
- Perform technical analyses and issue recommendations for different levels of the organization.
- Participate in incident response
- Integrate into the response team when necessary, providing operational intelligence during active incidents.
- Evaluate and improve technical information
- Review and optimize technical data to maximize its utility in cyber defense.
- Collaborate with vulnerability management
- Keep the team informed about emerging threats that may affect the organization's exposure.
Hiring process
You only have to click on APPLY.
About Grupo Cooperativo Cajamar
The group offers retail and business banking products including accounts, mortgages, personal loans, investment funds, pension plans, insurance and cards, with a stated focus on the modernization of rural Spain. As of 30 June 2026 it reported assets of 67.582 million euros, managed business volume of 118.527 million euros, and more than 1.8 million member-owners (socios).
The group operates and recruits across Spain, with current openings in locations including Madrid, Barcelona, A Coruña, Lugo, Mallorca, Ibiza, Teruel, Almería, Castellón, Valladolid, Alicante, Murcia, San Sebastián and Gran Canaria, spanning commercial banking, administration and a substantial technology organization (Cajamar Tecnología) hiring data engineers, project managers, cybersecurity and digitalization specialists. Its website is published in Spanish, English and Valencià/Català, and it maintains a "Trabaja con nosotros" (work with us) careers channel.
- Industry
- Banking
- Website
- cajamar.es
Good to know if you are moving
- Cajamar Caja Rural is Spain's largest rural savings bank and the country's largest credit cooperative, part of Grupo Cooperativo Cajamar.
- The group has more than 1.8 million member-owners (socios) and plays a significant role in financing rural Spain.
- Current openings span many Spanish provinces, including Madrid, Barcelona, A Coruña, Mallorca, Almería, Valencia-region (Castellón, Alicante), Valladolid, Murcia and Gran Canaria, across commercial, administrative and technology roles.
- The group runs a dedicated technology organization (Cajamar Tecnología) hiring data engineers, cloud/ETL specialists, cybersecurity architects and digitalization analysts.
- Its website is available in Spanish, English and Valencià/Català.
In their own words
About the company & team
Cajamar Tecnología A.I.E. is a Cajamar Group company made up of more than 300 professionals whose main activity focuses on Generative AI as a primary lever to digitalize processes and Data Analytics, management of technological platforms and enterprise architecture, analysis, development and maintenance of computer systems, implementation of digital solutions and collaborative services, and user support and IT service quality.
Entity:Cajamar Tecnología
We would like you to be part of our GREAT TEAM
We are different because we do banking for people.
Additional information
For all this and many more things, we are waiting for you!!!






