Security Incident Detection and Response Expert
Mapfre·Madrid, Spain
What they offer
Hybrid
Office and home days — the ad has the split.
What they ask for
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Work in English
English is required, per the ad.
Be near Madrid for hybrid days
No relocation package mentioned.
Have 7+ years of experience
Senior-level role.
Pulled from the advert automatically — the full ad is what counts.
About the role
Give your career a fresh start and keep growing professionally at MAPFRE! You'll be part of an international environment where you can innovate by taking part in global projects focused on the latest technology trends. All of this in a flexible and agile environment surrounded by top professionals from around the world... Are you ready?
From the Cybersecurity department, we are looking to bring on board a Security Incident Detection and Response Expert to analyze, evaluate, and develop the technical aspects of information systems and security services, ensuring their control and continuous improvement.
What you'll do
Define and implement use cases in line with MAPFRE's Detection and Response Model throughout its entire lifecycle:
-
Integration and normalization of new event sources into monitoring platforms (Splunk + SENTINEL).
-
Feasibility analysis, prototyping, testing, and deployment of use cases using the "Detection as Code" methodology and industry reference standards: MITRE ATT&CK + DETT&CT + MaGMA.
-
Design and implementation of response playbooks and operational procedures.
-
Automation + Alert orchestration.
-
Handover to CERT operations.
-
Periodic reviews.
Carry out first- and second-level response duties when information security incidents occur or are detected.
Apply techniques and tools for handling large volumes of data throughout the lifecycle of a security incident.
Collaborate on the preparation of technical expert reports that include all details related to the investigation (scope, impact, entry vector, criticality, evidence, etc.), conclusions, lessons learned, and improvement proposals.
Carry out post-incident reviews to identify strengths, weaknesses, and opportunities for improvement, and follow up on corrective actions.
Support internal investigations identified as necessary by the team.
What you'll get
Flexible working hours and remote work options to help you balance your professional and personal life.
A flexible compensation package that includes: meal vouchers, childcare vouchers, medical insurance, life insurance, employee discounts, and more. And if you live in Madrid, a company shuttle bus is available to get you to the office.
Access to an attractive pension plan.
Discounts on the products and services offered by our company.
Summer intensive schedule.
You'll be in charge of your own learning journey, with access to thousands of resources to keep advancing your technical expertise. Plus, you'll receive an additional €1,100 per year to further develop your skills.
The opportunity to participate in volunteer projects.
A great place to work! We're ranked among the 50 best companies to work for in Spain according to Forbes magazine.
Where are we?
In Majadahonda, Community of Madrid.
What do we need you to know?
A degree in Computer Engineering, Telecommunications Engineering, or a related field.
Specific training in Security, Engineering, or Use Case Definition on SIEM, IDS, or IPS platforms.
Knowledge and experience in forensic analysis (mainly in the DFIR field), security incident management (NIST), and Threat Hunting.
Strong programming skills in Powershell, Bash, and Python.
Strong proficiency in Excel and PowerBI.
Advanced level of English to take part in international projects.
Experience
Demonstrable experience of more than 7 years in security-related roles within large organizations.
Three years of specific experience in incident detection and response.
Certifications
Security certifications such as Certified Hacker Forensic Investigator (CHFI)
Incident Response Certified Professional (IRCP)
Certified Information System Security Professional (CISSP)
Certified Incident Handler (GCIH)
Certified Information Security Auditor (CISA)
Service management (ITIL) and quality management standards (ISO9001) as well as security standards (27001, ENS).
Skills
Strong presentation and communication skills to convey information effectively.
Ability to coordinate cross-functional teams and projects.
Ability to work under pressure.
Additional information
Every recruitment process at MAPFRE is carried out under the principles of EQUAL OPPORTUNITIES and NON-DISCRIMINATION, where the candidate's SKILLS and PROFESSIONAL MERIT are the only criteria considered for the final hiring decision.
We create work environments that value diversity and are free from discrimination based on sex, race, ideology, religion, sexual orientation, age, nationality, disability, or any other personal, physical, or social condition.
You can consult our Diversity and Equal Opportunities policy: politica-de-diversidad-e-igualdad-de-oportunidades.pdf (mapfre.com)
By registering for this job offer, you are informed of and consent to the processing by MAPFRE of the personal data you have voluntarily provided through this platform. If you provide data of third parties other than yourself, you guarantee that you have obtained and have their prior consent for the communication of their data and that you have informed them.
MAPFRE, as data controller, will process your data solely for the purpose of managing your participation in selection processes, for which profiles may be created and automated decisions may result from the processing of your data. In order to manage your participation in various selection processes at companies of the MAPFRE Group, subsidiaries and investees, and Fundación MAPFRE, your data may be communicated to those entities and may be subject to international transfer.
You can find additional information about data protection at MAPFRE at https://www.mapfre.com/corporativo-es/clausulas/RRHHseleccion.pdf, where we explain how to exercise your rights of access, rectification, erasure, restriction, objection, and portability of your personal data.
About the role
¡Dale un cambio a tu vida y sigue desarrollando tu carrera profesional en MAPFRE! Formarás parte de un entorno internacional donde podrás innovar participando en proyectos globales y enfocados en las últimas tendencias tecnológicas. Todo esto en un entorno flexible y ágil rodeado de excelentes profesionales de todo el mundo... ¿estás list@?
Desde el departamento de Ciberseguridad queremos incorporar un Experto en Detección y Respuesta a Incidentes para analizar, evaluar y desarrollar los aspectos técnicos de los sistemas de información y servicios de seguridad, garantizando su control y mejora.
What you'll do
Definir e implementar casos de uso acorde al Modelo de Detección y Respuesta de Mapfre en todo su ciclo de vida:
-
Integración y normalización de nuevas fuentes de eventos en plataformas de monitorización (Splunk + SENTINEL).
-
Análisis de viabilidad, prototipado, testing y despliegue de casos de uso mediante metodología "Detection as Code" y estándares de referencia en el sector: MITRE ATT&CK + DETT&CT + MaGMA.
-
Diseño e implantación de playbooks de respuesta y procedimientos de operación.
-
Automatización + Orquestación de alertas.
-
Traspaso a la operación del CERT.
-
Revisiones periódicas.
Realizar labores de primer y segundo nivel de respuesta ante la materialización o detección de incidentes de seguridad de la información.
Aplicar técnicas y herramientas de tratamiento masivo de datos durante el ciclo de vida de gestión de un incidente de seguridad.
Colaborar en la elaboración de informes periciales de naturaleza tecnológica, en los que se incluyan todos los detalles relacionados con la investigación (alcance, impacto, vector de entrada, criticidad, evidencias, etc), las conclusiones, lecciones aprendidas y propuestas de mejora.
Llevar a cabo revisiones posteriores al incidente para identificar fortalezas, debilidades, oportunidades de mejora y realizar seguimiento de las acciones correctivas.
Apoyar en las investigaciones internas que identifique el grupo como necesarias.
What you'll get
Horario flexible y teletrabajo, para facilitar la conciliación con tu vida personal.
Un programa de retribución flexible en el que tendrás: subvención de comida, cheques guardería, seguro médico, seguro de vida, descuentos para empleados, etc. Y si vives en la ciudad de Madrid, tendrás disponible una ruta de autobuses para llegar a la oficina.
Acceso a un plan de pensiones atractivo.
Descuentos en los productos y servicios que nuestra entidad comercializa.
Jornada intensiva de verano.
Serás el protagonista de tu ruta de aprendizaje, por lo que contarás con miles de recursos para seguir impulsando tu conocimiento técnico. Además, de forma extra contarás con 1.100€ anuales para que puedas ampliar aún más tu expertise.
Poder participar en proyectos de voluntariado.
¡Un lugar increíble para trabajar! Estamos en el ranking de las 50 mejores empresas para trabajar en España según la revista Forbes.
¿Dónde estamos?
En Majadahonda, Comunidad de Madrid.
¿Qué necesitamos que sepas?
Grado en Ingeniería Informática, de Telecomunicaciones o similares.
Formación específica en Seguridad, Ingeniería o Definición de casos de Uso en plataformas SIEM, IDS o IPS.
Conocimientos y experiencia en análisis forense (ámbito DFIR principalmente), gestión de incidentes de seguridad (NIST) y Threat Hunting.
Buen nivel en programación con Powershell, Bash y Python.
Buen nivel de Excel y PowerBI.
Alto nivel de inglés para participar en proyectos internacionales.
Experiencia
Experiencia demostrable mayor de 7 años en puestos relacionados con la seguridad en grandes organizaciones.
Tres años de experiencia específica en detección y respuesta a incidentes.
Certificaciones
Certificaciones en Seguridad como Certified Hacker Forensic Investigator (CHFI)
Incident Response Certified Professional (IRCP)
Certified Information System Security Professional (CISSP)
Certified Incident Handelr (GCIH)
Certified Information Security Auditor (CISA)
Gestión de servicios (ITIL) y estándares de gestión de la calidad (ISO9001) y de la seguridad (27001, ENS).
Competencias
Buenas habilidades para presentar y comunicar eficazmente la información.
Capacidad para coordinar de proyectos transversales, equipos y proyectos.
Capacidad para trabajar bajo presión.
Additional information
Todo proceso de selección que se desarrolla en MAPFRE se realiza bajo el principio de IGUALDAD DE OPORTUNIDADES y NO DISCRIMINACIÓN, siendo las APTITUDES y la VALÍA PERSONAL Y PROFESIONAL de la persona candidata, los criterios en los que se basa su elección final para el puesto de trabajo.
Creamos entornos de trabajo en los que se valora la diversidad y en los que no se producen discriminaciones por razón de sexo, raza, ideología, religión, orientación sexual, edad, nacionalidad, discapacidad o cualquier otra condición personal, física o social.
Puedes consultar nuestra política de Diversidad e Igualdad de Oportunidades: politica-de-diversidad-e-igualdad-de-oportunidades.pdf (mapfre.com)
Al inscribirte en esta oferta quedas informado y consientes el tratamiento por parte de MAPFRE, de los datos personales que has facilitado voluntariamente a través de esta plataforma. Si facilitas datos de terceras personas físicas distintas de ti, garantizas haber recabado y contar con el consentimiento previo de los mismos para la comunicación de sus datos y haberles informado.
MAPFRE como responsable, tratará tus datos, con la única finalidad de tramitar su participación en procesos de selección, para lo cual se podrán elaborar perfiles y del tratamiento de sus datos se podrá derivar la existencia de decisiones automatizadas. Con la finalidad de gestionar tu participación en diversos procesos de selección en empresas del Grupo MAPFRE, filiales y participadas, y Fundación MAPFRE, tus datos podrán comunicarse a dichas entidades, y ser objeto de transferencia internacional.
Puedes consultar información adicional de protección de datos en MAPFRE en https://www.mapfre.com/corporativo-es/clausulas/RRHHseleccion.pdf donde te indicamos donde ejercer los derechos de acceso, rectificación, supresión, limitación, oposición y portabilidad de tus datos personales.
This job was automatically translated to English, .