Cybersecurity Automation SOC SIEM/SOAR Engineer (M/F)

T-Systems Iberia·Madrid, Spain

What they offer

  • Full-time hours

    Per the ad.

  • Hybrid

    Office and home days — the ad has the split.

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Speak native-level Spanish

    Listed as a requirement in the ad.

  • Be near Madrid for hybrid days

    No relocation package mentioned.

  • Have 3+ years of experience

    Mid-level role.

Pulled from the advert automatically — the full ad is what counts.

This job was published 2 years ago

Read the full advert

About the role

T-Systems, a leading multinational in Information and Communication Technologies, is looking to hire a Cybersecurity Automation Engineer in Madrid, Barcelona, or Granada.

You will belong to the Cybersecurity area of T-Systems, which encompasses IT_Security, Network_Security, and Cybersecurity SOC. Specifically, you will be part of the T-Systems SOC. Your main function will be to support the automation of SOC operations currently underway in the area, through the use and integration of multiple tools that support SOC processes. To do this, as a SOC cybersecurity engineer, you will carry out tasks related to the implementation and maintenance of SIEM/SOAR platforms to analyze security events, configure alerts for proactive threat detection, and collaborate on adapting configurations. You will use SOAR tools to automate incident responses, improving the efficiency and effectiveness of cybersecurity operations. A deep understanding of cybersecurity principles and SIEM/SOAR systems is crucial to implementing effective automated solutions and improving defense against cyber threats.

What you'll do

  • Performing SIEM configurations and use cases: developing and implementing complex configurations within the SIEM system to ensure optimal detection and response capabilities, including correlation rules, filters, and data source integrations.
  • Developing automations and playbooks in the SOAR: developing custom scripts or automation workflows to enhance the automation capabilities of the SOAR platform, enabling more efficient incident response and mitigation.
  • Integrating SOC tools via APIs to automate and improve the efficiency and effectiveness of SOC processes.
  • Developing scripting and programming: scripting in languages such as Python, PowerShell, or Bash to develop custom scripts for automation, integration, and data manipulation.
  • Optimization: continuously adjusting and optimizing SIEM/SOAR modules to improve their effectiveness over time, adapting to changes in the threat landscape and organizational needs.
  • Collaboration with SOC teams, Cybersecurity architecture, CuSM, and other IT teams: you will work closely with IT and other security teams to understand the infrastructure, applications, and network architecture of the organization, ensuring effective SIEM/SOAR integration.

What you'll get

What do we offer?

- International, positive, dynamic, and motivated work environment.
- Hybrid work model (remote/on-site).
- Flexible working hours.
- Continuous training.
- Flexible compensation plan.
- Life and accident insurance.
- More than 25 working days of vacation per year.
And many more benefits of being part of T-Systems!

If you are looking for a new challenge, do not hesitate to send us your CV. Join our team!

T-Systems Iberia will only process CVs from candidates who meet the requirements specified for each position.

About the company & team

At T-Systems, you will find groundbreaking projects that contribute to social and ecological well-being. We want to welcome new talent like you, who bring fresh ideas, different perspectives, who embrace challenges and continuous learning, to grow and impact society... All of this, in a fun way!
It doesn't matter when or where you work. It's about doing work that matters to move society forward. For this reason, we will do everything possible to ensure you have every development opportunity by offering you a support network, excellent technology, a new work environment, and the freedom to work autonomously. We support you to grow constantly, both personally and professionally, so you can leave a notable mark on society.

T-Systems is a team of around 28,000 employees worldwide, making us one of the leading providers of integrated end-to-end solutions. We develop hybrid cloud solutions, artificial intelligence, and drive the digital transformation of businesses, industry, the public sector, and ultimately, all of society.

Requirements

Languages: Spanish, intermediate English; advanced English is valued.

  • University education in Computer Engineering, Telecommunications Engineering, or a similar technical degree. A master's degree or specialization in cybersecurity or a related field is highly valued.
  • Demonstrable experience of at least 3 years in the cybersecurity field, with at least 2 of those years in a SOC or similar role performing functions similar to those described for this position.
  • Technical Knowledge
    1. Cybersecurity Fundamentals and Basic Knowledge:
      • Security Principles: Confidentiality, integrity, and availability (CIA).
      • Threat Types: Knowledge of malware, phishing, denial-of-service (DoS) attacks, APTs (Advanced Persistent Threats), TTPs (Tactics, Techniques, and Procedures), etc.
      • Incident Analysis:
        • Understanding the complete incident management lifecycle, from detection to remediation and post-incident reporting.
        • Identification and Containment: Ability to quickly identify the nature of a security incident and take initial containment measures.
        • Investigation: Ability to delve into the technical details of an incident using logs, network traffic analysis, and forensic analysis tools.
      • Cloud Security: Familiarity with cloud computing environments (AWS, Azure, GCP) and experience protecting cloud-based infrastructure and services.
      • Networks and Systems Knowledge: Understanding of network architecture and topologies. Knowledge of common protocols such as TCP/IP, HTTP, HTTPS, DNS, etc.
      • Operating Systems: Familiarity with Windows, Linux, and Unix operating systems.
      • Event Logging: Knowledge of event logging systems across different operating systems (e.g., Event Viewer on Windows, syslog on Linux).
    2. SIEM (Security Information and Event Management) Knowledge and Experience:
      • SIEM Tools: Familiarity with SIEM tools. Knowledge and experience with SPLUNK SIEM and/or Azure Sentinel is highly valued.
      • Data Ingestion and Normalization: Understanding of how log data is collected, normalized, and stored.
      • Event Rules and Correlation: Ability to create and adjust correlation rules to detect attack patterns and suspicious activities.
      • Alert Analysis: Ability to analyze alerts and events generated by the SIEM, identify false positives, and prioritize incidents.
    3. SOAR (Security Orchestration, Automation, and Response) Knowledge and Experience:
      • SOAR Platforms: Experience with SOAR tools such as SPLUNK SOAR; Palo Alto Cortex XSOAR and/or XSIAM, automation in Azure Sentinel, etc.
      • Workflow Automation: Knowledge of creating and managing playbooks and automated workflows to respond to security incidents.
      • Orchestration: Ability to integrate multiple security tools and systems through SOAR to improve incident response.
  • Automation and Scripting Knowledge
    1. Scripting Languages
      • Python: Ability to write Python scripts to automate security tasks.
      • Bash/PowerShell: Experience with scripting in Bash (for Linux systems) and PowerShell (for Windows systems).
      • Security APIs: Ability to interact with APIs of security tools to integrate and automate workflows.
      • Task Automation: Knowledge of how to automate repetitive tasks and workflows through scripting and automation tools.
  • Soft Skills
    • Team Interaction: Ability to communicate effectively with other technical teams.
    • Ability to write reports and documentation within the scope of their duties and tasks.
    • Problem Solving
      • Critical Thinking: Ability to approach and solve complex security problems.
      • Adaptability: Ability to adapt to new threats and emerging security technologies.

You'll most likely need Spanish to apply.This job was automatically translated to English, .

About the company

T-Systems Iberia

T-Systems Iberia

IT Services

View company profile
International company
27000 employees