Security Incident Detection and Response Specialist

Mapfre·Madrid, Spain

What they offer

  • Hybrid

    Office and home days — the ad has the split.

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Speak native-level Spanish

    Listed as a requirement in the ad.

  • Work in English

    English is required, per the ad.

  • Be near Madrid for hybrid days

    No relocation package mentioned.

  • Have 4+ years of experience

    Senior-level role.

Pulled from the advert automatically — the full ad is what counts.

Added 3 days ago
Read the full advert

About the role

Give your career a fresh start and keep growing professionally at MAPFRE! You'll be part of an international environment where you can innovate by taking part in global projects focused on the latest technology trends. All of this in a flexible and agile environment surrounded by top professionals from around the world... Are you ready?

From the Cybersecurity department, we want to bring in a Security Incident Detection and Response Specialist to analyze, evaluate, and develop the technical aspects of information systems and security services, ensuring their control and improvement.

What you'll do

Collaborate on the implementation of use cases in accordance with the Mapfre Detection and Response Model throughout its entire lifecycle:

  • Integration and normalization of new event sources into monitoring platforms (Splunk + SENTINEL).

  • Feasibility analysis, prototyping, testing, and deployment of use cases using the "Detection as Code" methodology and industry reference standards: MITRE ATT&CK + DETT&CT + MaGMA.

  • Design and implementation of response playbooks and operational procedures.

  • Automation + Alert orchestration.

  • Handover to CERT operations.

  • Periodic reviews.

Monitor and control the operation of cybersecurity alerts:

  • Ensure compliance with SLAs
  • Identify pain points, inefficiencies, and manual tasks
  • Propose and follow up on improvement actions and automations
  • Ensure quality in security analyses, verdicts, and recommendations

Carry out first- and second-level response duties when information security incidents occur or are detected.

Collaborate on compliance, certification, and support for audits of the standards: ISO9001, ISO27001, ISO22301, DORA, and ENS

Apply techniques and tools for handling large volumes of data throughout the lifecycle of a security incident.

Ensure the quality, completeness, and consistency of incident records in the organization's incident database.

Support internal investigations identified as necessary by the team.

Help implement contingency procedures and continuity of services provided by the CERT.

Collaborate with the remaining areas and departments of the Corporate Security Directorate in achieving their objectives.

What you'll get

Flexible working hours and remote work options to help you balance your professional and personal life.

A flexible compensation package that includes: meal vouchers, childcare vouchers, medical insurance, life insurance, employee discounts, and more. And if you live in Madrid, a company shuttle bus is available to get you to the office.

Access to an attractive pension plan.

Discounts on the products and services offered by our company.

Summer intensive schedule.

You'll be in charge of your own learning journey, with access to thousands of resources to keep advancing your technical expertise. Plus, you'll receive an additional €1,100 per year to further develop your skills.

The opportunity to participate in volunteer projects.

A great place to work! We're ranked among the 50 best companies to work for in Spain according to Forbes magazine.

We are diverse, and that makes us unique!

How you'll work

In Majadahonda, Community of Madrid.

What do we need you to know?

A degree in Computer Engineering, Telecommunications Engineering, or a related field.

Specific training in Security, Engineering, or use case definition on SIEM, IDS, or IPS platforms, knowledge of SPL or KQL, and related frameworks such as MITRE ATT&CK, DETT&CT, MAGMA, etc.

Knowledge and experience in vulnerability analysis, forensic analysis (mainly in the DFIR field), security incident management (NIST), and Threat Hunting.

Strong programming skills in Powershell, Bash, and Python.

Strong proficiency in Excel and PowerBI.

Advanced level of English to take part in international projects.

Experience

Demonstrable experience of more than 4 years in security-related positions in large organizations.

Two years of specific experience in incident detection and response.

Certifications

Security certifications such as Certified Hacker Forensic Investigator (CHFI)

Incident Response Certified Professional (IRCP)

Certified Information System Security Professional (CISSP)

Certified Incident Handler (GCIH)

Certified Information Security Auditor (CISA)

Service management (ITIL) and quality management standards (ISO9001) as well as security standards (27001, ENS).

Skills

Strong presentation and communication skills to convey information effectively.

Ability to coordinate cross-functional teams and projects.

Ability to work under pressure.

Additional information

Every recruitment process at MAPFRE is carried out under the principles of EQUAL OPPORTUNITIES and NON-DISCRIMINATION, where the candidate's SKILLS and PROFESSIONAL MERIT are the only criteria considered for the final hiring decision.

We create work environments that value diversity and are free from discrimination based on sex, race, ideology, religion, sexual orientation, age, nationality, disability, or any other personal, physical, or social condition.

You can consult our Diversity and Equal Opportunities policy: politica-de-diversidad-e-igualdad-de-oportunidades.pdf (mapfre.com)

By registering for this job offer, you are informed of and consent to the processing by MAPFRE of the personal data you have voluntarily provided through this platform. If you provide data of third parties other than yourself, you guarantee that you have obtained and have their prior consent for the communication of their data and that you have informed them.

MAPFRE, as data controller, will process your data solely for the purpose of managing your participation in selection processes, for which profiles may be created and automated decisions may result from the processing of your data. In order to manage your participation in various selection processes at companies of the MAPFRE Group, subsidiaries and investees, and Fundación MAPFRE, your data may be communicated to those entities and may be subject to international transfer.

You can find additional information about data protection at MAPFRE at https://www.mapfre.com/corporativo-es/clausulas/RRHHseleccion.pdf, where we explain how to exercise your rights of access, rectification, erasure, restriction, objection, and portability of your personal data.

This job was automatically translated to English, .

About the company

Mapfre

Mapfre

Insurance

View company profile
Spanish company
31000 employees