Security Operations Analyst (SIEM & Threat Detection)

Posted Yesterday
Be an Early Applicant
12 Locations
In-Office or Remote
Senior level
Information Technology • Software
The Role
Administer and optimize SIEM platforms, develop and tune threat-detection capabilities, manage detection use cases, onboard security data sources, and improve monitoring effectiveness. The role collaborates with threat intelligence and incident response teams, supports cloud security architecture, builds dashboards and metrics, reduces false positives, and maintains SOC procedures and documentation across multiple customer environments.
Summary Generated by Built In

Location: Valencia, Spain, Hybrid OR Remote across EMEA
Employment: Full-Time Contract
Duration: 6 months, with potential extension
Language: Fluent English required
Industry: Cybersecurity / SIEM / Cloud Security

About the Opportunity

Pragmatike is recruiting on behalf of a major international organization for a Security Operations Analyst specializing in SIEM and Threat Detection.

You’ll join a global Cybersecurity Operations team focused on building, operating, and continuously improving the security monitoring capabilities protecting international organizations and their technology environments.

Unlike a traditional SOC monitoring role, this position has a strong focus on SIEM administration, detection engineering, security content, data-source onboarding, use-case lifecycle management, and detection optimization.

You’ll work closely with Threat Intelligence, Incident Response, and Cybersecurity Operations teams to turn security requirements and emerging threats into effective, measurable detection capabilities.

What You’ll Do
  • Develop, implement, validate, tune, and maintain security monitoring and detection capabilities.

  • Administer and optimize SIEM platforms across multiple customer environments.

  • Manage security detection rules and use cases throughout their lifecycle.

  • Onboard, integrate, test, and validate new security data sources and telemetry feeds.

  • Review and improve detection logic, security content, and monitoring configurations.

  • Collaborate with Threat Intelligence and Incident Response teams to translate threats into actionable detection capabilities.

  • Support cybersecurity architecture reviews and provide recommendations to improve security monitoring.

  • Build and maintain security metrics, dashboards, KPIs, and service-performance reports.

  • Evaluate detection effectiveness and identify opportunities to reduce false positives.

  • Contribute to quality assurance, process reviews, control validation, and corrective actions.

  • Maintain SOC procedures, standards, documentation, knowledge bases, and operational guidance.

  • Prepare technical reports, findings, and recommendations for internal and external stakeholders.

What We’re Looking For
  • 5+ years of relevant IT/cybersecurity experience.

  • Proven hands-on experience administering a SIEM platform, ideally Splunk or Microsoft Sentinel.

  • Strong experience with SIEM/EDR environments and technical security analysis.

  • Deep knowledge of Microsoft Security technologies.

  • Strong cloud security knowledge across Azure, AWS, and/or GCP.

  • Experience with platforms such as Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK.

  • Experience with at least one EDR platform such as Microsoft Defender for Endpoint or CrowdStrike.

  • Knowledge of email security, network monitoring, and incident response.

  • Strong Linux, macOS, and Windows knowledge.

  • Fluent English with excellent written and verbal communication skills.

Nice to Have
  • Experience designing SIEM architecture from initial design through implementation.

  • Experience building data-ingestion pipelines for diverse cloud and on-premise log sources.

  • AWS security monitoring experience.

  • Scripting experience with Python, PowerShell, Bash, Ruby, or similar.

  • Security certifications such as SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.

  • Experience working across multiple customer environments.

Why Join
  • Work beyond traditional SOC monitoring and contribute to the engineering and optimization of security detection capabilities.

  • Gain exposure to large-scale SIEM, EDR, cloud, and threat-detection environments.

  • Work directly with Threat Intelligence, Incident Response, and Cybersecurity Operations teams.

  • Help shape detection use cases, monitoring architecture, and operational processes.

  • Work on cybersecurity services supporting multiple international organizations.

Pragmatike is committed to a fair, transparent, and inclusive recruitment process. We do not discriminate based on age, disability, gender, gender identity or expression, marital or civil partner status, pregnancy or maternity, race, religion or belief, sex, or sexual orientation.

In accordance with GDPR, your personal data will be processed lawfully, fairly, and securely and used solely for recruitment purposes, including sharing it with our client(s) for employment consideration.

Skills Required

  • 5+ years of relevant IT or cybersecurity experience
  • Hands-on experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel
  • Strong experience with SIEM and EDR environments and technical security analysis
  • Deep knowledge of Microsoft Security technologies
  • Strong cloud security knowledge across Azure, AWS, and/or GCP
  • Experience with Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK
  • Experience with at least one EDR platform, such as Microsoft Defender for Endpoint or CrowdStrike
  • Knowledge of email security, network monitoring, and incident response
  • Strong Linux, macOS, and Windows knowledge
  • Fluent English with excellent written and verbal communication skills
  • Experience designing SIEM architecture from initial design through implementation
  • Experience building data-ingestion pipelines for diverse cloud and on-premise log sources
  • AWS security monitoring experience
  • Scripting experience with Python, PowerShell, Bash, Ruby, or similar
  • Security certifications such as SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE
  • Experience working across multiple customer environments
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Marseille
11 Employees
Year Founded: 2022

What We Do

Trusted by remote-first companies worldwide. Completing tech projects for startups and scaleups.

Similar Jobs

Pfizer Logo Pfizer

Senior Manager, HTA, Value and Evidence (HV&E), Genitourinary Cancer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
30 Locations
121990 Employees
139K-232K Annually

Mastercard Logo Mastercard

Consultant

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Remote or Hybrid
Athens, GRC
38800 Employees

Pfizer Logo Pfizer

Staff Software Engineer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
36 Locations
121990 Employees

Mondelēz International Logo Mondelēz International

Brand Manager

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
Athens, GRC
90000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account