This job was originally posted in Spanish and automatically translated to English. You'll most likely need Spanish to apply.
Requirements
Qualifications
Certifications (Optional but valued):
- Platform-specific certifications: SC-200, CrowdStrike Certified Falcon Administrator, or Google Chronicle Security Operations.
- GIAC: GCIA, GCIH, or GCFA.
- CompTIA Security+ or CySA+.
- Certified SOC Analyst (CSA) from EC-Council.
Benefits
Additional Information
English: C1-C2
Job Description
Company Description
Devoteam is a leading European consultancy focused on digital strategy, technology platforms, cybersecurity, and business transformation through technology.
Technology is in our DNA and we believe in it as a lever capable of driving change for improvement, maintaining a balance that allows us to offer our client portfolio top-tier technological tools, but always with the proximity and professionalism of a team that acts as a guide along the way.
Devoteam has been committed to technology at the service of people for over 25 years. With more than 10,000 people in the group, across 20 countries in Europe, the Middle East, and Africa.
Job Description
We are looking for a Level 2 (L2) Security Analyst for our Security Operations Center (SOC), with solid experience in SIEM/SOAR solutions, especially in Google SecOps, CrowdStrike NG-SIEM, and Microsoft/AWS/GCP ecosystems.
MAIN RESPONSIBILITIES
Detection and Response:
- Analyze and investigate medium-to-high complexity security alerts, with the goal of resolving 80% without the need to escalate to Level 3 (L3).
- Perform root cause analysis on complex incidents, documenting findings and recommendations.
- Coordinate incident responses involving multiple systems and cloud platforms.
Detection Engineering:
- Design, implement, and optimize detection use cases based on the MITRE ATT&CK framework.
- Adjust correlation rules in the SIEM and detection policies in EDR/XDR to reduce false positives.
- Validate and test new detections before their implementation in production.
Platforms and Tools:
- Operate and manage Google Chronicle SecOps, CrowdStrike Falcon Next-Gen SIEM, and PaloAlto XSIAM as primary platforms.
- Manage detections in Microsoft 365 Defender, Azure Sentinel, and AWS Security Hub.
- Use PaloAlto Cortex XSIAM for threat analysis and investigation.
Continuous Improvement:
- Develop automation scripts (Python/PowerShell) for repetitive tasks and alert enrichment.
- Mentor and provide technical support to L1 analysts.
- Contribute to technical documentation, playbooks, and operating procedures.
- Participate in proactive threat hunting exercises.
TECHNICAL REQUIREMENTS
Essential:
- Fluent English (C1/C2 level): both written and verbal communication.
- 2-4 years of experience in SOC operations, with at least 1 year in an L2 role.
- Hands-on experience with at least two of these SIEM/SOAR platforms: Google Chronicle SecOps, Palo Alto XSIAM, CrowdStrike Falcon Next-Gen SIEM, or Microsoft Sentinel.
- Demonstrable experience with EDR/XDR solutions (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Cortex XDR, or Sophos).
- Proficiency in query languages: KQL (Kusto), SPL (Splunk), or SQL.
- Solid knowledge of networks and protocols: TCP/IP, DNS, HTTP/S, network traffic analysis.
- Experience in Microsoft 365 environments (Exchange Online, Azure AD, Defender).
WORKING CONDITIONS
- Contract type: Permanent, full-time.
- Work model: Hybrid (Barcelona).
- On-call: Availability rotations (on-call)
View original advert (Spanish)
Company Description
Devoteam es una consultora europea líder enfocada en estrategia digital, plataformas tecnológicas, ciberseguridad y transformación empresarial a través de la tecnología.
La Tecnología está en nuestro ADN y creemos en ella como una palanca capaz de impulsar el cambio para mejorar, manteniendo un equilibrio que nos permite ofrecer a nuestra cartera de clientes herramientas tecnológicas de primer nivel pero siempre con la cercanía y profesionalidad de un equipo que actúa como guía durante el camino.
Devoteam lleva más de 25 años comprometidos con la tecnología al servicio de las personas. Con más de 10.000 personas en el grupo, en 20 países de Europa, Oriente Medio y África.
Job Description
Buscamos un Analista de Seguridad de Nivel 2 (L2) para nuestro Centro de Operaciones de Seguridad (SOC), con sólida experiencia en soluciones SIEM/SOAR, especialmente en Google SecOps, CrowdStrike NG-SIEM y ecosistemas Microsoft/AWS/GCP.
RESPONSABILIDADES PRINCIPALES
Detección y Respuesta:
- Analizar e investigar alertas de seguridad de complejidad media-alta, con el objetivo de resolver el 80% sin necesidad de escalar al Nivel 3 (L3).
- Realizar análisis de causa raíz en incidentes complejos, documentando hallazgos y recomendaciones.
- Coordinar respuestas a incidentes que involucren múltiples sistemas y plataformas en la nube.
Ingeniería de Detección:
- Diseñar, implementar y optimizar casos de uso de detección basados en el marco MITRE ATT&CK.
- Ajustar reglas de correlación en el SIEM y políticas de detección en EDR/XDR para reducir falsos positivos.
- Validar y probar nuevas detecciones antes de su implementación en producción.
Plataformas y Herramientas:
- Operar y gestionar Google Chronicle SecOps, CrowdStrike Falcon Next-Gen SIEM y PaloAlto XSIAM como plataformas principales.
- Gestionar detecciones en Microsoft 365 Defender, Azure Sentinel y AWS Security Hub.
- Utilizar PaloAlto Cortex XSIAM para el análisis e investigación de amenazas.
Mejora Continua:
- Desarrollar scripts de automatización (Python/PowerShell) para tareas repetitivas y enriquecimiento de alertas.
- Mentorizar y proporcionar soporte técnico a los analistas L1.
- Contribuir a la documentación técnica, playbooks y procedimientos operativos.
- Participar en ejercicios proactivos de búsqueda de amenazas (threat hunting).
REQUISITOS TÉCNICOS
Esenciales:
- Inglés fluido (nivel C1/C2): comunicación tanto escrita como verbal.
- 2-4 años de experiencia en operaciones de SOC, con al menos 1 año en un rol L2.
- Experiencia práctica con al menos dos de estas plataformas SIEM/SOAR: Google Chronicle SecOps, Palo Alto XSIAM, CrowdStrike Falcon Next-Gen SIEM o Microsoft Sentinel.
- Experiencia demostrable con soluciones EDR/XDR (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Cortex XDR o Sophos).
- Dominio de lenguajes de consulta: KQL (Kusto), SPL (Splunk) o SQL.
- Sólidos conocimientos de redes y protocolos: TCP/IP, DNS, HTTP/S, análisis de tráfico de red.
- Experiencia en entornos Microsoft 365 (Exchange Online, Azure AD, Defender).
CONDICIONES LABORALES
- Tipo de contrato: Indefinido, a jornada completa.
- Modelo de trabajo: Híbrido (Barcelona).
- Guardias: Rotaciones de disponibilidad (on-call)