Tech - Level 1.5 Technician

Telefónica·Spain

What they offer

  • Hybrid

    Office and home days — the ad has the split.

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Speak native-level Spanish

    Listed as a requirement in the ad.

  • Work in English

    English is required, per the ad.

  • Be near Spain for hybrid days

    No relocation package mentioned.

  • Have 2+ years of experience

    Mid-level role.

Pulled from the advert automatically — the full ad is what counts.

Added 2 months ago
Read the full advert

About the role

The Level 2 cybersecurity position requires a balance between advanced technical analysis and the management of more complex incidents. As a Level 2 specialist, you will focus on resolving security incidents escalated by the Level 1 team and will collaborate with other areas to strengthen organizational security.

What you'll do

Incident detection and advanced analysis:

Review, analyze, and prioritize security alerts received from SIEM systems, EDRs, and other advanced tools.

Investigate incidents escalated from Level 1, determining their severity, impact, and appropriate response.

Correlate security events and carry out deeper investigations to identify the root cause and scope of incidents.

Incident response and mitigation:

Coordinate and execute response actions for medium- and high-complexity incidents, ensuring proper containment, eradication, and recovery of affected systems.

Participate in defining procedures and guidelines for mitigating emerging threats, working alongside the Level 1 team to ensure an effective response.

Escalate critical incidents to the coordinator or specialized teams when necessary.

Collaboration and continuous improvement:

Collaborate with IT, development, and other key teams to implement improvements in network and application security.

Contribute to process optimization, identifying potential improvements in workflows and the automation of repetitive tasks through scripting (Python, PowerShell).

Support the training of the Level 1 team, providing feedback and guidance on handling advanced incidents.

Documentation and reporting:

Maintain detailed and up-to-date records of incidents, corrective actions, and lessons learned.

Participate in preparing technical and executive reports on incidents, detected vulnerabilities, and implemented improvements.

Continuous improvement and threat monitoring:

Contribute to the development and tuning of detection rules in SIEM systems, refining alerts to minimize false positives.

Stay up to date with the latest cybersecurity trends, vulnerabilities, and emerging threats to apply best practices in infrastructure defense.

What we're looking for

AND FOR THIS, WE BELIEVE IT WOULD BE IDEAL IF YOU HAD...

Experience

Minimum of 2 years of experience in a similar role or at Level 1, with the ability to manage complex incidents.

Solid knowledge of incident management, basic forensic analysis, and threat monitoring.

Required education:

Higher-level vocational training in computer systems administration, networks, or a related field.

Practical knowledge of SIEM, EDR, WAF, ticketing systems (JIRA, ServiceNow), and cybersecurity tool administration.

Nice to have

Desirable training:

Bachelor's degree or higher in computer engineering.

Master's degree in cybersecurity.

Cybersecurity certifications (CEH, CompTIA Security+, etc.).

Desired technical skills

Advanced knowledge of networks, operating systems, and detection and response tools.

Proficiency in ticketing and monitoring tools.

Knowledge of scripting (Python, PowerShell) and process automation.

Knowledge of advanced cybersecurity concepts and practices.

To perform the role, the skills that would best fit the team and the project would be:

Ability to investigate and resolve complex incidents in a dynamic environment.

Excellent organization and time management skills.

Ability to communicate effectively with different levels of the organization, both technical and non-technical.

Languages

Required: English

What you'll get

  • Work-life balance measures and flexible working hours
  • Ongoing training and certifications.
  • Hybrid remote work model.
  • Attractive social benefits package
  • Excellent dynamic and multidisciplinary work environment
  • Volunteering programs

About the company & team

WHAT IS TELEFÓNICA TECH?

Telefónica Tech is the leading digital transformation company of the Telefónica Group. We offer a wide range of integrated technological services and solutions in Cybersecurity, Cloud, IoT, Big Data, Artificial Intelligence, and Blockchain, with which we support our clients in their digital transformation.

We are a group of over 6,200 brave people who work every day from different points around the world to achieve excellence, through leadership based on transparency and team spirit. If you identify with our pillars, we can't wait to meet you!

www.telefonicatech.com

WHAT DO WE DO IN THE TEAM?

In Telefónica Cybersecurity & Cloud Tech's security monitoring unit, we are responsible for detecting, analyzing, and responding to all potential risk situations by executing actions to mitigate or contain a cybersecurity incident.

Additional information

#WeAreDiverse #WePromoteEquality

We are convinced that diverse and inclusive teams are more innovative, transformative, and achieve better results.

Therefore, we promote and guarantee the inclusion of all people regardless of gender, age, sexual orientation and identity, culture, disability, or any other condition.

We want to meet you! 😊

This job was automatically translated to English, .

About the company

Telefónica

Telefónica

Telecom

View company profile
Spanish company
100000 employees