Tech - Level 1.5 Technician
Telefónica·Spain
What they offer
Hybrid
Office and home days — the ad has the split.
What they ask for
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Speak native-level Spanish
Listed as a requirement in the ad.
Work in English
English is required, per the ad.
Be near Spain for hybrid days
No relocation package mentioned.
Have 2+ years of experience
Mid-level role.
Pulled from the advert automatically — the full ad is what counts.
About the role
The Level 2 cybersecurity position requires a balance between advanced technical analysis and the management of more complex incidents. As a Level 2 specialist, you will focus on resolving security incidents escalated by the Level 1 team and will collaborate with other areas to strengthen organizational security.
What you'll do
Incident detection and advanced analysis:
Review, analyze, and prioritize security alerts received from SIEM systems, EDRs, and other advanced tools.
Investigate incidents escalated from Level 1, determining their severity, impact, and appropriate response.
Correlate security events and carry out deeper investigations to identify the root cause and scope of incidents.
Incident response and mitigation:
Coordinate and execute response actions for medium- and high-complexity incidents, ensuring proper containment, eradication, and recovery of affected systems.
Participate in defining procedures and guidelines for mitigating emerging threats, working alongside the Level 1 team to ensure an effective response.
Escalate critical incidents to the coordinator or specialized teams when necessary.
Collaboration and continuous improvement:
Collaborate with IT, development, and other key teams to implement improvements in network and application security.
Contribute to process optimization, identifying potential improvements in workflows and the automation of repetitive tasks through scripting (Python, PowerShell).
Support the training of the Level 1 team, providing feedback and guidance on handling advanced incidents.
Documentation and reporting:
Maintain detailed and up-to-date records of incidents, corrective actions, and lessons learned.
Participate in preparing technical and executive reports on incidents, detected vulnerabilities, and implemented improvements.
Continuous improvement and threat monitoring:
Contribute to the development and tuning of detection rules in SIEM systems, refining alerts to minimize false positives.
Stay up to date with the latest cybersecurity trends, vulnerabilities, and emerging threats to apply best practices in infrastructure defense.
What we're looking for
AND FOR THIS, WE BELIEVE IT WOULD BE IDEAL IF YOU HAD...
Experience
Minimum of 2 years of experience in a similar role or at Level 1, with the ability to manage complex incidents.
Solid knowledge of incident management, basic forensic analysis, and threat monitoring.
Required education:
Higher-level vocational training in computer systems administration, networks, or a related field.
Practical knowledge of SIEM, EDR, WAF, ticketing systems (JIRA, ServiceNow), and cybersecurity tool administration.
Nice to have
Desirable training:
Bachelor's degree or higher in computer engineering.
Master's degree in cybersecurity.
Cybersecurity certifications (CEH, CompTIA Security+, etc.).
Desired technical skills
Advanced knowledge of networks, operating systems, and detection and response tools.
Proficiency in ticketing and monitoring tools.
Knowledge of scripting (Python, PowerShell) and process automation.
Knowledge of advanced cybersecurity concepts and practices.
To perform the role, the skills that would best fit the team and the project would be:
Ability to investigate and resolve complex incidents in a dynamic environment.
Excellent organization and time management skills.
Ability to communicate effectively with different levels of the organization, both technical and non-technical.
Languages
Required: English
What you'll get
- Work-life balance measures and flexible working hours
- Ongoing training and certifications.
- Hybrid remote work model.
- Attractive social benefits package
- Excellent dynamic and multidisciplinary work environment
- Volunteering programs
About the company & team
WHAT IS TELEFÓNICA TECH?
Telefónica Tech is the leading digital transformation company of the Telefónica Group. We offer a wide range of integrated technological services and solutions in Cybersecurity, Cloud, IoT, Big Data, Artificial Intelligence, and Blockchain, with which we support our clients in their digital transformation.
We are a group of over 6,200 brave people who work every day from different points around the world to achieve excellence, through leadership based on transparency and team spirit. If you identify with our pillars, we can't wait to meet you!
www.telefonicatech.com
WHAT DO WE DO IN THE TEAM?
In Telefónica Cybersecurity & Cloud Tech's security monitoring unit, we are responsible for detecting, analyzing, and responding to all potential risk situations by executing actions to mitigate or contain a cybersecurity incident.
Additional information
#WeAreDiverse #WePromoteEquality
We are convinced that diverse and inclusive teams are more innovative, transformative, and achieve better results.
Therefore, we promote and guarantee the inclusion of all people regardless of gender, age, sexual orientation and identity, culture, disability, or any other condition.
We want to meet you! 😊
About the role
El puesto de N2 en ciberseguridad requiere un equilibrio entre el análisis técnico avanzado y la gestión de incidentes más complejos. Como especialista de Nivel 2, estarás enfocado en la resolución de incidentes de seguridad escalados por el equipo de N1 y colaborarás con otras áreas para fortalecer la seguridad organizacional.
What you'll do
Detección y análisis avanzado de incidentes:
Revisar, analizar y priorizar alertas de seguridad recibidas de sistemas SIEM, EDRs y otras herramientas avanzadas.
Investigar incidentes escalados desde el Nivel 1, determinando su gravedad, impacto y respuesta adecuada.
Correlacionar eventos de seguridad y ejecutar investigaciones más profundas para identificar la causa raíz y el alcance de los incidentes.
Respuesta y mitigación de incidentes:
Coordinar y ejecutar acciones de respuesta a incidentes de mediana y alta complejidad, asegurando la correcta contención, erradicación y recuperación de sistemas afectados.
Participar en la definición de procedimientos y guías para la mitigación de amenazas emergentes, trabajando junto con el equipo de N1 para garantizar una respuesta eficaz.
Escalar incidentes críticos al coordinador o a equipos especializados cuando sea necesario.
Colaboración y mejora continua:
Colaborar con equipos de IT, desarrollo y otras áreas clave para implementar mejoras en la seguridad de la red y las aplicaciones.
Contribuir a la optimización de procesos, identificando posibles mejoras en los flujos de trabajo y en la automatización de tareas repetitivas mediante scripting (Python, PowerShell).
Apoyar en la formación del equipo de N1, proporcionando feedback y capacitación en el manejo de incidentes avanzados.
Documentación y reportes:
Mantener registros detallados y actualizados de incidentes, acciones correctivas y lecciones aprendidas.
Participar en la elaboración de informes técnicos y ejecutivos sobre incidentes, vulnerabilidades detectadas y mejoras implementadas.
Mejora continua y monitoreo de amenazas:
Contribuir al desarrollo y ajuste de reglas de detección en sistemas SIEM, afinando alertas para minimizar falsos positivos.
Mantenerse al tanto de las últimas tendencias de ciberseguridad, vulnerabilidades y amenazas emergentes para aplicar las mejores prácticas en la defensa de la infraestructura.
What we're looking for
Y PARA ELLO, CREEMOS QUE SERÍA IDEAL QUE CONTARAS CON...
Experiencia
Experiencia mínima de 2 años en un rol similar o en N1, con capacidad de gestionar incidentes complejos.
Conocimientos sólidos en la gestión de incidentes, análisis forense básico y monitoreo de amenazas.
Formación necesaria:
Formación profesional de grado superior en administración de sistemas informáticos, redes o similar.
Conocimiento práctico de SIEM, EDR, WAF, sistemas de ticketing (JIRA, Service Now), y administración de herramientas de ciberseguridad.
Nice to have
Formación deseable:
Ingeniería técnica o superior en informática.
Máster en ciberseguridad.
Certificaciones en ciberseguridad (CEH, CompTIA Security+, etc.).
Conocimientos técnicos deseados
Conocimiento avanzado de redes, sistemas operativos y herramientas de detección y respuesta.
Manejo de herramientas de ticketing y monitoreo.
Conocimientos de scripting (Python, PowerShell) y automatización de procesos.
Conocimientos de conceptos y prácticas avanzadas de ciberseguridad.
Para desempeñar el rol, las skills que encajarían con el equipo y el proyecto serían:
Capacidad para investigar y resolver incidentes complejos en un entorno dinámico.
Excelente organización y gestión de tiempo.
Capacidad para comunicar de manera efectiva con diferentes niveles de la organización, tanto técnicos como no técnicos.
Languages
Necesario: Ingles
What you'll get
- Medidas de conciliación y flexibilidad horaria.
- Formación continua y certificaciones.
- Modelo híbrido de teletrabajo.
- Atractivo paquete de beneficios sociales.
- Excelente ambiente de trabajo dinámico y multidisciplinar.
- Programas de voluntariado.
About the company & team
¿QUÉ ES TELEFONICA TECH?
Telefónica Tech es la compañía líder en trasformación digital del Grupo Telefónica. Contamos con una amplia oferta de servicios y soluciones tecnológicas integradas de Ciberseguridad, Cloud, IoT, Big Data, Inteligencia Artificial y Blockchain, con la que acompañamos a nuestros clientes en su transformación digital.
Somos un grupo de más de 6200 personas valientes que trabajamos a diario desde distintos puntos del mundo para alcanzar la excelencia, a través de un liderazgo basado en la transparencia y en el espírItu de equipo. Si te identificas con nuestros pilares, ¡estamos deseando conocerte!
www.telefonicatech.com
¿QUÉ HACEMOS EN EL EQUIPO?
En la unidad de monitorización de seguridad de Telefónica Cybersecurity & Cloud Tech nos encargamos de la detección, análisis y respuesta a todas las posibles situaciones de riesgo mediante la ejecución de acciones para mitigar o contener un incidente de ciberseguridad.
Additional information
#SomosDiversos #Fomentamosigualdad
Estamos convencidos/as de que los equipos diversos e inclusivos son más innovadores, transformadores y consiguen mejores resultados.
Por ello promovemos y garantizamos la inclusión de todas las personas sin importar género, edad, orientación e identidad sexual, cultura, discapacidad o cualquier otra condición
¡Queremos conocerte! 😊
This job was automatically translated to English, .
About the company
Telefónica
Telecom