SOC L2 Security Analyst (16x5 Rotating Shifts / Hybrid)
Devoteam is a leading European consultancy focused on digital strategy, technological platforms, cybersecurity, and business transformation through technology. Centered on 6 areas of specialization, we address our clients' strategic challenges: Digital Business & Products, Data-driven Intelligence, Distributed Cloud, Business Automation, Cybersecurity, and Sustainability achieved through Digitalization. Technology is in our DNA and we believe in it as a lever capable of driving change for improvement, maintaining a balance that allows us to offer our clients top-tier technological tools while always providing the closeness and professionalism of a team that acts as a guide along the way. Our 25 years of experience make us an innovative, consolidated, and mature consultancy that enables the development of our 10,000 people, continuously certifying our consultants in the latest technologies and featuring experts in: Cloud, BI, Data Analytics, Business Process Excellence, Customer Relationship Management, Cybersecurity, Digital Marketing, Machine Learning, Software Engineering and development. Devoteam has been awarded as the 2021 Partner of the Year by the 5 cloud leaders: AWS, Google Cloud, Microsoft, Salesforce, and ServiceNow. #TecnologíaCreativaParaUnMejorCambio
Do you have experience in SOC L2 and are you looking to make the leap to next-generation SIEM/SOAR platforms? We are looking for an L2 Analyst for advanced threat detection in multicloud environments. What will you do? Investigate and resolve medium-high complexity alerts, working with autonomy relative to the L3 team.
Design and fine-tune detection use cases based on the MITRE ATT&CK matrix.
Operate with cutting-edge tools: Google Chronicle SecOps, CrowdStrike Falcon NG-SIEM, Palo Alto XSIAM, Microsoft Sentinel, and AWS Security Hub.
Automate detection and response tasks through scripting (Python / PowerShell).
Provide technical support and mentorship to L1 analysts.
Minimum requirements Experience: 2 to 4 years in SOC, with at least 1 year in an L2 role.
Platforms: Demonstrable practical experience in at least 2 of the following technologies: Google Chronicle SecOps, Palo Alto XSIAM, CrowdStrike NG-SIEM, or Microsoft Sentinel.
EDR/XDR: Management of CrowdStrike Falcon, Defender for Endpoint, SentinelOne, Cortex XDR, or Sophos.
Query languages: Proficiency in KQL, SPL, or SQL.
Languages: English C1/C2 (daily use with international clients).
It will be highly valued Deep knowledge of the MITRE ATT&CK matrix and script development (Python/PowerShell).
Industry certifications: SC-200, GCIH, CySA+, among others.
Modality: Hybrid (Tres Cantos, Madrid).
Schedule: Morning or afternoon shifts + availability for paid on-call duties outside of shifts.