€850
🇬🇧EDR Administration and Monitoring Expert (CrowdStrike)
Hybrid in Spain·Added today
222 open roles
What they offer
Hybrid
Office and home days — the ad has the split.
What they ask for
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Be near Spain for hybrid days
No relocation package mentioned.
Have 3+ years of experience
Mid-level role.
You'll most likely need Spanish to apply.This job was automatically translated to English,.
The role
What you'll do
Your mission will be to manage the Crowdstrike NG-SIEM platform as well as the threats generated within it.
Your day-to-day:
- Administration and management of the CrowdStrike NG-SIEM platform.
- Continuous monitoring and investigation of security alerts.
- Analysis and correlation of events for threat detection.
- Preparation of technical reports, metrics, and presentations for clients.
- Analysis, classification, and response to security incidents.
- Optimization of correlation rules and detection use cases.
- Integration and validation of new log and telemetry sources.
- Implementation of continuous improvements in the service and detection capabilities.
- Definition, documentation, and transfer of operating procedures for N1 teams.
- Collaboration with Threat Intelligence and incident response teams to improve security posture.
AND FOR THIS, WE BELIEVE IT WOULD BE IDEAL IF YOU HAD...
Requirements
What we're looking for
- 3 years in analysis and administration of security environments (EDR - SIEM)
- Administration and management of the CrowdStrike NG-SIEM platform.
- Mass deployment and integration of sensors, connectors, and data sources.
- Administration and optimization of the CrowdStrike Falcon EDR/XDR platform.
- Continuous monitoring and analysis of security alerts.
- Investigation, contextualization, and validation of threats through Threat Intelligence.
- Management, analysis, and response to security incidents.
- Correlation of events and creation of detection use cases.
- Knowledge and analysis of network communications and protocols for incident investigation.
- Automation of monitoring, response, and remediation processes.
- Preparation of technical and executive reports for clients.
- Implementation of continuous improvements in detection and response capabilities.
Required:
- Knowledge of SIEM platforms.
- Knowledge of event correlation.
- Knowledge in the creation of use cases for security events.
- Capacity for administration, support, and deployment.
- Knowledge in incident management
- Knowledge of cybersecurity.
Nice to have
To perform this role, the skills that would fit well with the team and the project are:
- Passionate about security and technology.
- Willingness to always do your best, grow, and take on new responsibilities.
- Ability to learn and grow in an evolving environment.
- Excellent oral and written communication skills.
- Ability to work in an environment that requires a high level of detail and confidentiality.
- Proactive, self-motivated with the ability to work independently and as a member of a team in a challenging environment.
- Able to work both autonomously and collaboratively with colleagues in the same area or others, carrying out teamwork.
- Strong focus toward the internal client and results orientation.
Education & certifications
- Higher vocational training in computer systems
Desirable:
- University Degree / Licentiate / Engineering / Computer Science Technical Engineering / Telecommunications or similar.
- Security certifications (OSCP, CEH or related)
- Certifications in SIEM technologies (Splunk, NG-SIEM Crowdstrike)
Languages
- Required: Intermediate English
Pay & benefits
What you'll get
• Work-life balance measures and flexible working hours.
• Ongoing training and certifications.
• Hybrid remote work model.
• Attractive social benefits package.
• Excellent dynamic and multidisciplinary work environment.
• Volunteering programs.
#WeAreDiverse #WePromoteEquality
We are convinced that diverse and inclusive teams are more innovative, transformative, and achieve better results.
That is why we promote and guarantee the inclusion of all people regardless of gender, age, sexual orientation and identity, culture, disability, or any other condition.
We want to meet you! 😊
The role
What you'll do
Tu misión será gestionar la plataforma NG-SIEM de Crowdstrike así como las amenazas que en ella se generan.
Tu día a día:
- Administración y gestión de la plataforma NG-SIEM de CrowdStrike.
- Monitorización continua e investigación de alertas de seguridad.
- Análisis y correlación de eventos para la detección de amenazas.
- Elaboración de informes técnicos, métricas y presentaciones a cliente.
- Análisis, clasificación y respuesta ante incidentes de seguridad.
- Optimización de reglas de correlación y casos de uso de detección.
- Integración y validación de nuevas fuentes de logs y telemetría.
- Implementación de mejoras continuas en el servicio y las capacidades de detección.
- Definición, documentación y transferencia de procedimientos operativos para equipos N1.
- Colaboración con equipos de Threat Intelligence y respuesta ante incidentes para la mejora de la postura de seguridad.
Y PARA ELLO, CREEMOS QUE SERÍA IDEAL QUE CONTARAS CON...
Requirements
What we're looking for
- 3 años en análisis y administración de entornos de seguridad (EDR - SIEM)
- Administración y gestión de la plataforma NG-SIEM de CrowdStrike.
- Despliegue e integración masiva de sensores, conectores y fuentes de datos.
- Administración y optimización de la plataforma EDR/XDR de CrowdStrike Falcon.
- Monitorización continua y análisis de alertas de seguridad.
- Investigación, contextualización y validación de amenazas mediante Threat Intelligence.
- Gestión, análisis y respuesta ante incidentes de seguridad.
- Correlación de eventos y creación de casos de uso de detección.
- Conocimientos y análisis de comunicaciones y protocolos de red para la investigación de incidentes.
- Automatización de procesos de monitorización, respuesta y remediación.
- Elaboración de informes técnicos y ejecutivos para clientes.
- Implementación de mejoras continuas en las capacidades de detección y respuesta.
Necesario:
- Conocimientos de plataformas SIEM.
- Conocimientos de correlación de eventos.
- Conocimientos en la creación de casos de uso en eventos de seguridad.
- Capacidad de administración, soporte y despliegue.
- Conocimientos en gestión de incidentes
- Conocimientos de ciberseguridad.
Nice to have
Para desempeñar el rol, las skills que encajarían con el equipo y el proyecto serían:
- Apasionado/a de la seguridad y la tecnología.
- Voluntad de hacer siempre lo mejor, crecer y asumir nuevas responsabilidades.
- Capacidad para aprender y crecer en un entorno en evolución.
- Excelentes habilidades de comunicación oral y escrita.
- Capacidad para trabajar en un entorno que requiere un alto nivel de detalle y confidencialidad.
- Proactivo/a, automotivado con la capacidad de trabajar de forma independiente y como miembro de un equipo en un entorno desafiante.
- Capaz de trabajar tanto de forma autónoma, como coordinado con compañeros de la misma área, u otras, realizando trabajo en equipo.
- Fuerte enfoque hacia el cliente interno y orientación a resultados.
Education & certifications
- Formación profesional superior sobre sistemas informáticos
Deseables:
- Grado Universitario / Licenciatura / Ingeniería / Ingeniería Técnica Informática \ Telecomunicaciones o similares.
- Certificaciones sobre seguridad (OSCP, CEH o relacionadas)
- Certificaciones sobre tecnologías SIEM (Splunk, NG-SIEM Crowdstrike)
Languages
- Necesario: Inglés medio
Pay & benefits
What you'll get
• Medidas de conciliación y flexibilidad horaria.
• Formación continua y certificaciones.
• Modelo híbrido de teletrabajo.
• Atractivo paquete de beneficios sociales.
• Excelente ambiente de trabajo dinámico y multidisciplinar.
• Programas de voluntariado.
#SomosDiversos #Fomentamosigualdad
Estamos convencidos/as de que los equipos diversos e inclusivos son más innovadores, transformadores y consiguen mejores resultados.
Por ello promovemos y garantizamos la inclusión de todas las personas sin importar género, edad, orientación e identidad sexual, cultura, discapacidad o cualquier otra condición
¡Queremos conocerte! 😊
About Telefónica
Telefónica is one of the world's largest telecommunications companies, providing fixed and mobile connectivity, digital services, and technology solutions to consumers and businesses across Europe and Latin America. With over 100,000 employees and a strong presence in Spain, the UK, Germany, and Brazil, the company operates through brands such as Movistar, O2, and Vivo, and has expanded into areas like cybersecurity, cloud, IoT, and AI through its innovation units.
In Spain, Telefónica is headquartered in Madrid and is a major employer of tech talent, with a strong focus on cybersecurity, data, and AI. The company actively hires international professionals, offering roles in English and fostering a diverse, innovative culture. Its Spanish operations are central to its global strategy, making it a relevant option for internationals seeking to work in a large, established tech and telecom player in Spain.
- Industry
- Telecom
- Founded
- 1924
- Employees
- 100,000+
- Headquarters
- Madrid, Spain
- In Spain
- Madrid, Barcelona
- Website
- telefonica.com
Good to know if you are moving
- Telefónica's Spanish offices are largely based in Madrid and Barcelona, with a significant tech hub in the Distrito Telefónica complex in Madrid.
- The company frequently hires international tech talent and many roles are offered in English, making it accessible for non-Spanish speakers.
- Telefónica has a strong commitment to innovation, with dedicated units like gAIt and Wayra focusing on AI and startups.
- The company offers a comprehensive relocation package and support for international hires, including visa assistance.
- With a global presence and a large Spanish operation, Telefónica provides opportunities for internal mobility across countries and roles.
In their own words
About the company & team
Telefónica Tech is the leading digital transformation company of the Telefónica Group. We offer a wide range of integrated technological services and solutions in Cybersecurity, Cloud, IoT, Big Data, Artificial Intelligence, and Blockchain, with which we support our clients in their digital transformation.
We are a group of over 6,200 brave people who work every day from different points around the world to achieve excellence, through leadership based on transparency and team spirit. If you identify with our pillars, we can't wait to meet you!
In Telefónica Tech's Detection and Response unit, we work on the administration and monitoring of NG-SIEM platform events. The department operates in constant improvement of detection and mitigation capabilities for client environments.
About the company & team
Telefónica Tech es la compañía líder en trasformación digital del Grupo Telefónica. Contamos con una amplia oferta de servicios y soluciones tecnológicas integradas de Ciberseguridad, Cloud, IoT, Big Data, Inteligencia Artificial y Blockchain, con la que acompañamos a nuestros clientes en su transformación digital.
Somos un grupo de más de 6200 personas valientes que trabajamos a diario desde distintos puntos del mundo para alcanzar la excelencia, a través de un liderazgo basado en la transparencia y en el espírItu de equipo. Si te identificas con nuestros pilares, ¡estamos deseando conocerte!
En la unidad de Detección y Respuesta de Telefónica Tech trabajamos en la administración y monitorización de eventos de plataformas NG-SIEM. El departamento se desenvuelve en constante mejora de las capacidades de detección y mitigación de los entornos de cliente.
More jobs like this
or browse Security·Mid-level·Hybrid·IBEX 35·Telecommunications & Connectivity·Cybersecurity·Spanish Brands·Telecom



