What they offer
Permanent contract
Full-time hours.
Hybrid
Office and home days — the ad has the split.
What they ask for
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Work in English
English is required, per the ad.
Be near Madrid for hybrid days
No relocation package mentioned.
Have 4+ years of experience
Mid-level role.
This job was automatically translated to English,.
The role
Computer Engineering/Telecommunications or similar
Experience in process automation, desirable in Cybersecurity environments through SOAR.
Knowledge of programming and scripting languages. Python, Powershell, and Bash are especially valued.
Knowledge of cloud infrastructure management: Azure and AWS.
Knowledge of cybersecurity, specifically SOC operations, as well as the digital threat ecosystem, with the capacity for analysis and prioritization of relevant risks.
Knowledge of LEAN, AGILE, and DevSecOps methodologies.
English Level: B2+/C1.
What you'll do
You will coordinate and participate in the integral management of cybersecurity incidents in IT and OT environments, from detection and initial analysis to containment, mitigation, recovery, and closure.
You will analyze alerts and incidents to identify scope, impact, root cause, affected assets, attack vectors, and response measures.
You will drive vulnerability management, prioritizing based on risk, coordinating remediation, and performing follow-up until resolution.
You will collaborate with technical teams and providers to execute containment, mitigation, patching, and compensatory control actions on infrastructure, cloud, endpoint, networks, identity, applications, and industrial environments.
You will contribute to improving procedures, playbooks, escalation criteria, reporting, automation, and the governance of the SOC-IRT service.
Key Information
Team: Digitalization and Services
Location: Madrid, Spain
Experience level: approx. 4 years
Work type: hybrid
Requirements: B2 English or higher + Bachelor's degree or higher
Additional Requirements
Master's degree/certifications in any of the fields related to Cybersecurity are valuable.
Security certifications in the field of infrastructure and technologies such as IBM QRadar, Tenable Security Center, Microsoft Azure Sentinel, and AWS Security Hub are valuable.
Experience in security incident management and vulnerability analysis, as well as in quantum cryptography, will be valued.
Availability to travel occasionally.
Required skills
Automation, Communication, Coordinating Services, Cybersecurity, Data Reporting, English Language, Incident Response, IT Technologies, Linux, Microsoft Windows, Networks, Operational Technology (OT), Process Improvements, Report Writing, Technical Knowledge, Vulnerability Management, Works Under Pressure
Pay & benefits
What you'll get
Permanent contract
Challenging work throughout your entire professional career
Motivating work environment
Fixed salary plus variable (objective achievement incentive)
Health insurance
Pension plan contribution
Digital disconnection
Work-life balance measures
Employee support services
The role
Ingeniería Informática/Telecomunicaciones o similar
Experiencia en automatización de procesos, deseable en entornos de Ciberseguridad a través de SOAR.
Conocimientos de lenguajes de programación y scripting. Valorándose especialmente Python, Powershell y Bash.
Conocimientos de gestión de infraestructura cloud: Azure y AWS.
Conocimientos en ciberseguridad, en especial, de las operaciones de un SOC, así como en el ecosistema de las amenazas digitales, con capacidad de análisis y priorización de riesgos relevantes.
Conocimiento de metodologías LEAN, AGILE, DevSecOps.
Nivel de Inglés: B2+/C1.
What you'll do
Coordinarás y participarás en la gestión integral de incidentes de ciberseguridad en entornos IT y OT, desde la detección y el análisis inicial hasta la contención, mitigación, recuperación y cierre.
Analizarás alertas e incidentes para identificar alcance, impacto, causa raíz, activos afectados, vectores de ataque y medidas de respuesta.
Impulsarás la gestión de vulnerabilidades, priorizando en función del riesgo, coordinando la remediación y realizando seguimiento hasta su resolución.
Colaborarás con equipos técnicos y proveedores para ejecutar acciones de contención, mitigación, parcheo y controles compensatorios sobre infraestructuras, cloud, endpoint, redes, identidad, aplicaciones y entornos industriales.
Contribuirás a mejorar procedimientos, playbooks, criterios de escalado, reporting, automatización y gobierno del servicio SOC-IRT.
Información clave
Equipo: Digitalización y Servicios
Localización: Madrid, España
Nivel de experiencia: aprox. 4 años
Tipo de trabajo: híbrido
Requisitos: inglés B2 o superior + Licenciatura o superior
Requisitos Adicionales
Valorable máster/certificaciones en alguno de los ámbitos relacionados con Ciberseguridad.
Valorables certificaciones de seguridad en ámbito de infraestructura y tecnologías como IBM QRadar, Tenable Security Center, Microsoft Azure Sentinel, AWS Security Hub.
Se valorará experiencia en la gestión de incidentes de seguridad y análisis de vulnerabilidades, así como en criptografía cuántica.
Disponibilidad para viajar ocasionalmente.
Required skills
Automation, Communication, Coordinating Services, Cybersecurity, Data Reporting, English Language, Incident Response, IT Technologies, Linux, Microsoft Windows, Networks, Operational Technology (OT), Process Improvements, Report Writing, Technical Knowledge, Vulnerability Management, Works Under Pressure
Pay & benefits
What you'll get
Contrato indefinido
Trabajo retador a lo largo de toda la trayectoria profesional
Ambiente laboral motivador
Salario fijo más variable (incentivo cumplimiento de objetivos)
Seguro médico
Aportación a plan de pensiones
Desconexión digital
Medidas de conciliación
Servicios de apoyo al empleado
About Repsol
Repsol is a global energy company headquartered in Madrid, Spain, operating across the entire value chain from exploration and production to refining, chemicals, and marketing. With operations in over 30 countries and a workforce of more than 24,000 employees, it is one of the largest energy firms in the world and a leader in the Iberian energy market. The company is actively investing in renewable energy and digital transformation, positioning itself as a key player in the energy transition.
In Spain, Repsol has a strong presence with offices and industrial facilities across the country, including its headquarters in Madrid and major complexes in Tarragona, Cartagena, and A Coruña. The company is known for its commitment to innovation and sustainability, offering opportunities for international professionals in areas such as engineering, data science, and renewable energy. Repsol's work culture emphasizes safety, efficiency, and professional development, making it an attractive employer for those looking to build a career in the energy sector in Spain.
- Industry
- Energy
- Founded
- 1987
- Employees
- 10,000–50,000
- Headquarters
- Madrid, Spain
- In Spain
- Madrid, Tarragona, Cartagena and 1 more
- Website
- repsol.com
Good to know if you are moving
- Repsol is headquartered in Madrid, offering a central location with excellent international connectivity.
- The company has a strong focus on renewable energy and digital innovation, providing opportunities for engineers and data professionals.
- Repsol offers a multicultural work environment with employees from various nationalities, especially in its technology and innovation hubs.
- The company provides competitive benefits and supports professional development through training programs and career progression.
- Spain's energy sector is growing, and Repsol is a key player, offering stability and long-term career prospects.
In their own words
About the company & team
We need to recruit a specialized technical profile in cybersecurity incident response to reinforce the SOC-IRT / Security IRT team, within the D. CIO&CDO. The person will join the area responsible for detecting, analyzing, coordinating, and responding to cybersecurity incidents in IT and OT environments, as well as driving vulnerability management across corporate, industrial, cloud, and endpoint infrastructures.
The position requires a combination of technical capabilities, operational judgment, cross-functional coordination, and an orientation toward continuous improvement. We are looking for a person capable of participating in the complete management of the incident lifecycle, from initial analysis to containment, mitigation, recovery, closure, and the extraction of lessons learned.
Additionally, their participation in the prioritization and monitoring of vulnerabilities will be key, helping to translate technical risks into concrete remediation actions alongside infrastructure, cloud, network, identity, endpoint, application, industrial environment teams, and specialized providers.
Additional information
At Repsol, we are committed to equality and do not request personal information.
We believe that diversity contributes to innovative ideas and provides added value that enables us to benefit from mutual learning and perform our best work. Here, what counts is your experience and your ability to create value. We offer you the opportunity to grow professionally, develop your career with challenging projects and collaborate with talented people worldwide. As a company committed to diversity and inclusion, we encourage all professionals who meet the job description requirements to apply.
Additional job description
About the company & team
Necesitamos incorporar un perfil técnico especializado en respuesta a incidentes de ciberseguridad para reforzar el equipo SOC-IRT / Seguridad IRT, dentro de la D. CIO&CDO. La persona se integrará en el área encargada de detectar, analizar, coordinar y responder ante incidentes de ciberseguridad en entornos IT y OT, así como de impulsar la gestión de vulnerabilidades sobre infraestructuras corporativas, industriales, cloud y endpoint.
La posición requiere una combinación de capacidades técnicas, criterio operativo, coordinación transversal y orientación a la mejora continua. Buscamos una persona capaz de participar en la gestión completa del ciclo de vida de un incidente, desde el análisis inicial hasta la contención, mitigación, recuperación, cierre y extracción de lecciones aprendidas.
Además, será clave su participación en la priorización y seguimiento de vulnerabilidades, ayudando a traducir riesgos técnicos en acciones concretas de remediación junto con equipos de infraestructura, cloud, redes, identidad, endpoint, aplicaciones, entornos industriales y proveedores especializados.
Additional information
At Repsol, we are committed to equality and do not request personal information.
We believe that diversity contributes to innovative ideas and provides added value that enables us to benefit from mutual learning and perform our best work. Here, what counts is your experience and your ability to create value. We offer you the opportunity to grow professionally, develop your career with challenging projects and collaborate with talented people worldwide. As a company committed to diversity and inclusion, we encourage all professionals who meet the job description requirements to apply.
More jobs like this
or browse Madrid·Security·Security·Mid-level·Hybrid·IBEX 35·Energy & Renewables·Cybersecurity·Spanish Brands·Community of Madrid·Energy·Python·AWS·Azure·Linux





