CSIRT/SOC Manager

Telefónica·Spain

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Speak native-level Spanish

    Listed as a requirement in the ad.

  • Work in English

    English is required, per the ad.

  • Work on-site in Spain

    No relocation package mentioned.

  • Have senior-level experience

    Lead-level role.

Pulled from the advert automatically — the full ad is what counts.

Added 1 month ago
Read the full advert

About the role

What will your mission be? 🎯

The person joining this position will assume responsibility for the CSIRT/SOC for the Global CSIRT. They will be in charge of the 24x7 detection and response service across the corporate perimeter, leading the operations analysis team and taking on incident management functions within the corporate scope.

They will actively contribute to the company's resilience, the standardization of essential detection and response processes, and their progressive adoption by business units.

This role is crucial for minimizing the impact of incidents on the corporate perimeter, ensuring service maturity, and acting as a reference in process standardization for the CSIRT capabilities of business units.

What you'll do

How will you contribute with your skills to the purpose of the role? 💼

CSIRT/SOC service management.

Incident management: incident declaration, prioritization, triage, and coordination of containment and eradication actions on corporate assets, as well as requesting updates from the involved areas.

Responsibility for case and evidence management, ensuring case quality and conducting post-incident reviews.

Responsibility for service content, including the knowledge base, operational procedures, and processes: creation, maintenance, and approval of changes.

Definition, maintenance, and publication of baseline essential detection and response processes for business units, with support from more experienced analysis profiles and driving their progressive adoption.

Operational coordination with business units regarding incidents and critical threats affecting several of them.

Activation of the crisis protocol and support for executive communications during high-severity incidents.

Continuous review of service performance through key performance indicators.

Translating the operational needs of the service (visibility, detection, and automation) to the detection and response engineering area.

Overseeing the cadence of review and updating of published baselines.

Promoting continuous improvement through lessons learned and follow-up on post-incident actions.

Contributing to the supervised adoption of AI capabilities in monitoring, initial classification, and response processes.

What we're looking for

What skills are we looking for? 🔎

The candidate must have leadership skills, proven operational judgment, the ability to make decisions under pressure, prioritization skills, and effective communication with both technical and executive audiences. They will be expected to ensure quality and compliance within their scope of responsibility, provide advice to different teams, influence decision-making, and manage operational risks.

Knowledge of reference frameworks: SIM3 v2, MITRE ATT&CK®, and the NIST Cybersecurity Framework.

Demonstrated experience in managing incident response teams (CSIRT/SOC) and in incident management.

High level of integrity and discretion in handling confidential information.

Strong oral and written communication skills, with the ability to present complex information to technical and executive audiences.

Ability to build trusting relationships with interested areas and stakeholders.

Demonstrated ability to work autonomously and lead multidisciplinary teams.

Strategic vision, strong organizational skills, and the ability to balance competing priorities in dynamic and demanding environments.

Advanced level of English, both oral and written (C1 or higher).

What you'll get

What benefits will you enjoy as part of our team? 💙

Transformative projects. At Telefónica, you will be part of high-impact projects that set trends and respond to the connectivity and digital transformation challenges of our society.

Professional development. You will have a long career path and global-scale learning, thanks to our presence in different geographies. We will share development opportunities, training, and mobility options with you. We want to grow and build a future together!

Flexibility. We believe in the balance between professional and personal life. At Telefónica, we care about flexibility, positioning ourselves as a benchmark in new ways of working and work-life balance measures.

27 working days of vacation to enjoy.

Social benefits. You will enjoy a comprehensive social benefits package, including:

Life and accident insurance

Medical insurance for you and your family unit (spouse and children)

Meal voucher card

Flexible compensation plan with numerous options to choose from.

Pension plan

And much more!

About the company & team

We connect the present. We shape the future.

Have you ever wondered what makes it possible for millions of people to be connected at the same time, from anywhere in the world, without anything failing?

At Telefónica, we make it possible.

We are a global telecommunications and technology company that connects people, businesses, and communities through next-generation networks and advanced digital solutions such as cloud, artificial intelligence, IoT, and cybersecurity.

With over 100 years of history, we work every day to put innovation at the service of society, driving a responsible, sustainable digital transformation with real impact.

Here we don't just design infrastructure—we design the future. We are looking for people who are curious, enthusiastic, and passionate about what they do, who are never satisfied with the status quo and want to build the Telefónica of tomorrow.

If you are passionate about technology that transforms lives, this is your place.

What other aspects are relevant? 📚

University degree (Master's) in STEM fields. Alternatively, equivalent professional experience.

Desirable Certifications (valuable for strengthening the profile)

Previous experience in CSIRT/SOC 24x7 service management or incident management functions.

Experience in defining and governing operational procedures, processes, and detection and response content catalogs.

Experience with applicable regulatory compliance: NIS2, GDPR, and SOX.

Experience in coordinating multi-entity incidents or those affecting several business units.

Familiarity with the integration of AI solutions based on assistants and agents in security operations with human supervision.

Availability to handle critical incidents outside regular working hours.

Additional information

At Telefónica, we are committed to building a diverse, inclusive, and sustainable work environment where every person feels valued, respected, and free. Our culture is based on equal opportunity and inclusion because we have the responsibility to transform society and make the world a better place.

If you want to be part of an innovative team and contribute to a better future, we are waiting for you!

This job was automatically translated to English, .

About the company

Telefónica

Telefónica

Telecom

View company profile
Spanish company
100000 employees