Tech - Level 1 Monitoring Technician
Spain·Competitive·Hybrid·Entry · 1+ years·English: Required
Need a visa?No sponsorship mentioned, and this kind of work is rarely sponsored in Spain. See which routes exist.
Education & certifications
Required:
- Higher-level vocational training in computer systems and network administration.
Desirable
- Technical or higher engineering in Computer Science
- Master's in cybersecurity
- +1 year in the field of cybersecurity
Languages
- Required: English
What you'll get
• Work-life balance measures and flexible working hours.
• Ongoing training and certifications.
• Hybrid remote work model.
• Attractive benefits package.
• Excellent dynamic and multidisciplinary work environment.
• Volunteer programs.
#WeAreDiverse #WePromoteEquality
We are convinced that diverse and inclusive teams are more innovative, transformative, and achieve better results.
That is why we promote and guarantee the inclusion of all people regardless of gender, age, sexual orientation and identity, culture, disability, or any other condition.
We want to meet you! 😊
About the company & team
In the SIEM TO unit of Telefónica Tech, we are responsible for the detection, analysis, and response to all possible risk situations by executing actions to mitigate or contain a cybersecurity incident.
WHAT IS TELEFÓNICA TECH?
Telefónica Tech is the leading digital transformation company of the Telefónica Group. We offer a wide range of integrated technological services and solutions in Cybersecurity, Cloud, IoT, Big Data, Artificial Intelligence, and Blockchain, with which we support our clients in their digital transformation.
We are a group of over 6,200 brave people who work every day from different points around the world to achieve excellence, through leadership based on transparency and team spirit. If you identify with our pillars, we can't wait to meet you!
Incident detection
- Review and analyze alerts generated by security systems, such as network intrusions, suspicious user behaviors, malware, among others, to determine their relevance and severity.
- Respond to low-complexity security incidents, following established procedures, and escalate those incidents that require additional intervention.
- Conduct initial investigations into security events, identifying the root cause and scope of an incident, as well as collecting forensic evidence for later analysis.
- Record activity related to service development through the ticketing tool.
Incident response: Depending on the nature of each situation, these actions can be carried out both in a planned manner and immediately and urgently, ensuring security in all cases.
Some examples of actions to be carried out may include
● Communications: request to block malicious IP addresses in WAF.
● Endpoint: request for antivirus scan and containment of devices with EDR agent
● Mail: request to include addresses in the whitelist/blacklist, redirect emails to quarantine, and delete emails.
● Access: request to block users, reset credentials, and session token on devices.
AND FOR THIS, WE BELIEVE IT WOULD BE IDEAL IF YOU HAD...
Experience
- +1 year in the field of cybersecurity (not essential)
Technical knowledge
- Knowledge of cybersecurity concepts and practices.
- Handling of ticketing tools
- Operation of SIEMs
Education & certifications
Necesario:
- Formación profesional de grado superior en administración de sistemas informáticos y redes.
Deseables
- ingeniería técnica o superior en Informática
- Máster en ciberseguridad
- + de 1 año en el ámbito de la ciberseguridad
Languages
- Necesario: Ingles
What you'll get
• Medidas de conciliación y flexibilidad horaria.
• Formación continua y certificaciones.
• Modelo híbrido de teletrabajo.
• Atractivo paquete de beneficios sociales.
• Excelente ambiente de trabajo dinámico y multidisciplinar.
• Programas de voluntariado.
#SomosDiversos #Fomentamosigualdad
Estamos convencidos/as de que los equipos diversos e inclusivos son más innovadores, transformadores y consiguen mejores resultados.
Por ello promovemos y garantizamos la inclusión de todas las personas sin importar género, edad, orientación e identidad sexual, cultura, discapacidad o cualquier otra condición
¡Queremos conocerte! 😊
About the company & team
En la unidad de SIEM TO de Telefónica Tech nos encargamos de la detección, análisis y respuesta a todas las posibles situaciones de riesgo mediante la ejecución de acciones para mitigar o contener un incidente de ciberseguridad.
¿QUÉ ES TELEFONICA TECH?
Telefónica Tech es la compañía líder en trasformación digital del Grupo Telefónica. Contamos con una amplia oferta de servicios y soluciones tecnológicas integradas de Ciberseguridad, Cloud, IoT, Big Data, Inteligencia Artificial y Blockchain, con la que acompañamos a nuestros clientes en su transformación digital.
Somos un grupo de más de 6200 personas valientes que trabajamos a diario desde distintos puntos del mundo para alcanzar la excelencia, a través de un liderazgo basado en la transparencia y en el espírItu de equipo. Si te identificas con nuestros pilares, ¡estamos deseando conocerte!
Detección de incidentes
- Revisar y analizar las alertas generadas por sistemas de seguridad, como intrusiones de red, comportamientos sospechosos de usuarios, malware, entre otros, para determinar su relevancia y gravedad.
- Responder a incidentes de seguridad de baja complejidad, siguiendo los procedimientos establecidos, y escalando aquellos incidentes que requieran intervención adicional.
- Realizar investigaciones iniciales sobre eventos de seguridad, identificando la causa raíz y el alcance de un incidente, así como recopilando evidencia forense para su análisis posterior.
- Registro de actividad propia del desarrollo del servicio mediante la herramienta de ticketing.
Respuesta a incidentes: Dependiendo de la naturaleza de cada situación, estas acciones pueden ser realizadas tanto de manera planificada, como con carácter inmediato y urgente, garantizando en todos los casos la seguridad.
Algunos ejemplos de acciones a llevar a cabo podrán ser
● Comunicaciones: solicitud de bloqueo de direcciones IP maliciosas en WAF.
● Endpoint: solicitud de escaneo con el antivirus y contención de equipos con agente EDR
● Mail: solicitud de incluir direcciones a la whitelist/blacklist, redirección de mails a la cuarentena y borrado de mails.
● Accesos: solicitud de bloqueo de usuarios, reseteo de credenciales y token de sesión en dispositivos.
Y PARA ELLO, CREEMOS QUE SERÍA IDEAL QUE CONTARAS CON...
Experiencia
- + de 1 año en el ámbito de la ciberseguridad(no indispensable)
Conocimientos técnicos
- Conocimiento de conceptos y práctica de ciberseguridad.
- Manejo en herramientas de Ticketing
- Operación de SIEMS
This job was automatically translated to English, .
About the company
Telefónica
Telecom