Cybersecurity Analyst - SOC
EY·Madrid, Spain
What they ask for
Have the right to work in Spain
EY doesn't mention sponsorship in the ad.
Work on-site in Madrid
No relocation package mentioned.
Pulled from the advert automatically — the full ad is what counts.
About the role
At EY, we shape the future with confidence.
Here you will find more than a job: an opportunity to grow, learn, and make an impact.
Join our 7,000 professionals in Spain and 15 offices and a global network of 400,000 people who work every day to transform businesses and societies.
#ShapeTheFutureWithConfidence | #EYCareers | #BuildingABetterWorkingWorld
What you'll do
- Analyze alerts escalated by Level 1, validate false positives, identify attack patterns, and determine severity, scope, and potential impact.
- Conduct advanced investigation in SIEM, EDR/XDR, network logs, identity, endpoint, cloud, email, firewall, proxy, IDS/IPS, and other telemetry sources.
- Operate and leverage Splunk SIEM for searches, correlation, event analysis, rule review, dashboards, evidence, and investigation traceability.
- Participate in Splunk SOAR operations, executing playbooks, reviewing automations, and proposing improvements to response workflows.
- Analyze events in OT/ICS environments, considering the particularities of industrial networks, critical assets, industrial protocols, segmentation, and operational constraints.
- Prepare incident reports, timelines, evidence, attack hypotheses, and recommendations for containment, eradication, and recovery.
- Coordinate escalations with response, infrastructure, OT, networking, endpoint, identity, cloud teams, and business stakeholders.
- Contribute to the continuous improvement of use cases, correlation rules, playbooks, runbooks, and analysis procedures.
- Participate in hunting, threat review, analysis of indicators of compromise, and contextualization with threat intelligence.
What you'll get
- Wellbeing HUB: includes policies and actions for physical (Wellhub) and mental health.
- Life and Accident Insurance.
- Bankinter office with special conditions.
- EY Flex Compensation Plan (transport, training, restaurant card, daycare...).
The opportunity
At EY, we are a leading global firm in audit, consulting, strategy and transactions, and legal and tax services.
We are looking for professionals with experience in a Security Operations Center (SOC).
Requirements
- University degree in computer science, telecommunications, or similar IT-related fields.
- Security certifications such as CISM, CISSP, OSCP, CEH, GPEN, among others.
- English: B1/B2
- At least 3 years of experience performing the described duties in international projects and environments.
- Analytical.
- Proactive.
- Results-oriented.
- Willing to work or accustomed to working in high-performance teams.
- Willingness to learn and ability to take responsibility for continuous training.
Flexibility and work-life balance
- Hybrid work and flexibility according to the project.
Professional development
- Continuous training through EY University, with an individualized training itinerary.
- Career plan to boost annual growth within the firm.
- Personalized support: you will have the support of a Buddy and a Counselor throughout your career.
Culture and work environment
- Work in a dynamic and collaborative environment.
- Opportunity to collaborate with global and multidisciplinary teams.
- Expand your professional network in a diverse and enriching context.
Social commitment
- Social impact actions from the EY Foundation.
About the role
En EY, damos forma al futuro con confianza.
Aquí encontrarás más que un trabajo: una oportunidad para crecer, aprender y dejar huella.
Únete a nuestros 7.000 profesionales en España y 15 oficinas y a una red global de 400.000 personas que trabajan cada día para transformar negocios y sociedades.
#ShapeTheFutureWithConfidence | #EYCareers | #BuildingABetterWorkingWorld
What you'll do
- Analizar alertas escaladas por Nivel 1, validar falsos positivos, identificar patrones de ataque y determinar severidad, alcance e impacto potencial.
- Realizar investigación avanzada en SIEM, EDR/XDR, logs de red, identidad, endpoint, cloud, correo, firewall, proxy, IDS/IPS y otras fuentes de telemetría.
- Operar y explotar Splunk SIEM para búsquedas, correlación, análisis de eventos, revisión de reglas, dashboards, evidencias y trazabilidad de investigaciones.
- Participar en la operación de Splunk SOAR, ejecutando playbooks, revisando automatizaciones y proponiendo mejoras en flujos de respuesta.
- Analizar eventos en entornos OT/ICS, considerando particularidades de redes industriales, activos críticos, protocolos industriales, segmentación y limitaciones operativas.
- Elaborar informes de incidente, líneas temporales, evidencias, hipótesis de ataque, recomendaciones de contención, erradicación y recuperación.
- Coordinar escalados con equipos de respuesta, infraestructura, OT, networking, endpoint, identidad, cloud y responsables de negocio.
- Contribuir a la mejora continua de casos de uso, reglas de correlación, playbooks, runbooks y procedimientos de análisis.
- Participar en hunting, revisión de amenazas, análisis de indicadores de compromiso y contextualización con inteligencia de amenazas.
What you'll get
- Wellbeing HUB: incluye políticas y acciones para la salud física (Wellhub) y mental.
- Seguro de Vida y Accidentes.
- Oficina Bankinter con condiciones especiales.
- Plan de Compensación Flexible EY Flex (transporte, formación, tarjeta restaurante, guardería...).
La oportunidad
En EY, somos una firma global líder en auditoría, consultoría, estrategia y transacciones y servicios legales y fiscales.
Buscamos perfiles que tengan experiencia en Centro de Operaciones de CiberSeguridad (SOC).
Requisitos
- Titulado universitario en informática, telecomunicaciones o similares en el ámbito IT.
- Certificaciones de seguridad CISM, CISSP, OSCP, CEH, GPEN, entre otros.
- Inglés: B1/B2
- Experiencia de, al menos, 3 años desarrollando las funciones descritas en proyectos y entornos a nivel internacional.
- Analítico.
- Proactivo.
- Orientado a resultados.
- Dispuesto o habituado al trabajo en equipo de alto desempeño.
- Ganas de aprender y capacidad para responsabilizarse por su formación continua.
Flexibilidad y conciliación
- Trabajo híbrido y flexibilidad según proyecto.
Desarrollo profesional
- Formación continua a través de EY University, con un itinerario formativo individualizado.
- Plan de carrera para potenciar el crecimiento anual dentro de la firma.
- Acompañamiento personalizado: contarás con el apoyo de un Buddy y un Counselor durante toda tu trayectoria.
Cultura y entorno de trabajo
- Trabajo en un entorno dinámico y colaborativo.
- Oportunidad de colaborar con equipos globales y multidisciplinares.
- Ampliación de tu red profesional en un contexto diverso y enriquecedor.
Compromiso social
- Acciones de impacto social desde la Fundación EY.
You'll most likely need Spanish to apply.This job was automatically translated to English, .
About the company
EY
Consulting