Security Operations & Incident Response Analyst

Posted 11 Days Ago
Be an Early Applicant
Madrid, Comunidad de Madrid, ESP
Hybrid
48K-48K Annually
Mid level
AdTech • Marketing Tech
The Role
Owns end-to-end incident response, including triage, containment, eradication, recovery, breach investigations, and post-incident reviews. Leads threat hunting and intelligence activities, manages SIEM and EDR/XDR detection workflows, and oversees vulnerability management, IAM, and PAM programs. Coordinates with SOC/MDR providers and internal stakeholders, conducts forensic investigations, tracks remediation, maintains playbooks, and reports security risks and incidents to the CISO.
Summary Generated by Built In
Are you ready to join our digital revolution journey? 
 
At Aleph, we’re not just part of the digital advertising landscape—we’re shaping its future. Representing the world’s leading platforms, including TikTok, Amazon, Google, and nearly 55 others, we operate in 130+ markets across new and existing geographies.
 
Our mission is to empower advertisers and brands to unlock the full potential of these platforms' advertising capabilities. By fostering long-lasting partnerships, we create limitless opportunities for people and businesses to advertise effectively at both local and global levels.
 
With a presence spanning continents, Aleph offers you the chance to be part of a fast-growing, innovative team where your work makes a direct impact. If you’re ambitious, forward-thinking, and eager to thrive in a dynamic, global environment, Aleph is the perfect place to build your career.

We are looking for an experienced and operationally sharp Security Operations & Incident Response Analyst (L3) to join Aleph's global IT Security team.
Reporting to the Global CISO, you will be the first line of defence when incidents occur and the engine behind the team's threat detection and response capabilities. You will own the end-to-end incident response process, lead threat hunting and intelligence activities, and manage the vulnerability and identity governance programmes — ensuring Aleph is both able to detect threats quickly and respond to them effectively across a complex, globally distributed environment. 

What you'll do:

    Incident Response

  • Own and coordinate the end-to-end incident response process: identification, triage, containment, eradication, recovery, and post-incident review (lessons learned).

  • Serve as the primary point of contact for security incidents escalated from IT Operations, the Security Engineer, and external sources.

  • Maintain and continuously improve incident response playbooks for the most relevant threat scenarios (ransomware, phishing, account compromise, data breach, insider threat, etc.).

  • Manage the security incident log and register: track all incidents, document timelines and actions, and produce trend analysis and reporting for the CISO.

  • Coordinate with external SOC or MDR providers where applicable: review daily reports, validate alert quality, and manage escalation workflows.

  • Data Breach Management

  • Lead data breach investigations: scope the breach, gather and preserve evidence, assess PII exposure, and coordinate response with Legal, Privacy, and HR.

  • Produce breach investigation reports with findings, root cause, and recommendations.

  • Threat Hunting & Intelligence

  • Conduct proactive threat hunting across the environment: develop hypotheses based on threat intelligence, search for indicators of compromise (IoCs), and investigate anomalous behaviour.

  • Manage the Threat Intelligence function: track relevant threat actors, TTPs (MITRE ATT&CK), and sector-specific threat campaigns; integrate intelligence into SIEM/XDR detection rules and hunting queries.

  • Produce threat intelligence summaries and briefings for the CISO and relevant stakeholders.

  • Vulnerability Management

  • Own the vulnerability management programme: schedule and execute periodic vulnerability scans across infrastructure, endpoints, and cloud environments.

  • Analyse scan results, prioritise findings by risk and exploitability, and coordinate remediation with IT Operations within agreed SLAs.

  • Track remediation progress, produce vulnerability metrics, and report status to the CISO.

  • Validate remediation effectiveness through re-scanning and spot-checks.

  • Identity & Access Management (IAM)

  • Manage periodic access reviews: coordinate with system owners and HR to review and certify user permissions across critical systems, ensuring least privilege is maintained.

  • Oversee the Privileged Access Management (PAM) programme: define PAM policies, monitor privileged account usage, and review access rights for administrator-level accounts.

  • Investigate and respond to identity-related anomalies and access policy violations.

What we are looking for:

  • 3–5 years in a SOC analyst, incident response, or security operations role, with at least 1–2 years at L3 level is a plus.
  • Experience implementing or managing IAM and PAM solutions

  • Experience working within international or multinational environments.

  • Hands-on experience with incident response engagements (internal or consulting) is strongly valued.

  • Relevant certifications: GCIH, GCFE, GCFA, CEH, CompTIA CySA+, or equivalent. OSCP is a plus.

  • Strong hands-on experience with SIEM platforms (alert triage, rule writing, query development) and EDR/XDR tools.

  • Solid knowledge of the MITRE ATT&CK framework and its application to threat hunting and incident response.

  • Experience conducting vulnerability scans using tools such as Tenable Nessus, Qualys, Rapid7, or similar.

  • Familiarity with IAM and PAM concepts and platforms (e.g. CyberArk, BeyondTrust, Azure PIM, or equivalent).

  • Experience with digital forensics and incident response (DFIR) methodologies: evidence collection, log analysis, and timeline reconstruction.

  • Knowledge of threat intelligence platforms and feeds (e.g. MISP, VirusTotal, threat intel feeds).

  • Understanding of ISO 27001 incident management controls, NIS2 incident reporting obligations, and PCI DSS requirement 12.10.

  • Calm and decisive under pressure.
  • Strong investigative mindset with structured problem-solving approach, excellent documentation skills.
  • Ability to communicate incident status and findings clearly to both technical teams and executive stakeholders.
  • Collaborative and proactive, comfortable working asynchronously across time zones. 
  • English: full professional proficiency (C1/C2) — primary working language. Spanish: professional proficiency is a plus.

In line with the EU Pay Transparency Directive, we are committed to fair and open compensation practices. For this role, the minimum gross annual base salary is EUR 48,000 EUR.

In addition to base salary, this role includes a variable component, paid annually. The final offer will reflect your experience, skills, and the scope of the role.


#Aleph


Why Join Us?
 
Aleph is a place of many cultures, perspectives, and talents. We support each other, creating an environment of giving and receiving. We value partnership and communication because we believe it takes a group of people to achieve great things. We are energized by our ever-changing industry, our curiosity keeps us learning and seeking out new opportunities.  
 
We stay flexible and adaptable, and believe in moving with the speed of change. We encourage everyone to strive for more, providing our internal talent with growth opportunities and the ability to learn together. 
 
#ALEPH

Skills Required

  • 3-5 years of experience in a SOC analyst, incident response, or security operations role
  • At least 1-2 years of L3 experience
  • Experience implementing or managing IAM and PAM solutions
  • Experience working in international or multinational environments
  • Hands-on experience with incident response engagements
  • Relevant certification such as GCIH, GCFE, GCFA, CEH, CompTIA CySA+, or equivalent
  • OSCP certification
  • Strong hands-on experience with SIEM platforms, including alert triage, rule writing, and query development
  • Experience with EDR/XDR tools
  • Knowledge of the MITRE ATT&CK framework and its application to threat hunting and incident response
  • Experience conducting vulnerability scans using Tenable Nessus, Qualys, Rapid7, or similar tools
  • Familiarity with IAM and PAM concepts and platforms such as CyberArk, BeyondTrust, or Azure PIM
  • Experience with digital forensics and incident response methodologies
  • Knowledge of threat intelligence platforms and feeds such as MISP and VirusTotal
  • Understanding of ISO 27001 incident management controls, NIS2 incident reporting obligations, and PCI DSS requirement 12.10
  • Full professional English proficiency at C1/C2 level
  • Professional Spanish proficiency

Aleph Group, Inc Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Aleph Group, Inc and has not been reviewed or approved by Aleph Group, Inc.

  • Wellbeing & Lifestyle Benefits — Feedback suggests flexible working hours and hybrid/remote options are available in multiple markets. These arrangements are valued by some as part of the overall package.
  • Strong & Reliable Incentives — Feedback suggests a decent bonus structure exists in some groups, contributing meaningful variable compensation. This helps certain roles view total pay more favorably.
  • Fair & Transparent Compensation — In specific teams and locations, pay is described as fair or decent relative to expectations. This indicates pockets where cash compensation feels competitive.

Aleph Group, Inc Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Riverside, CA
872 Employees

What We Do

Aleph is a team of digital experts, growing markets around the world. Our solutions make local and global advertising possible, without limits. Our teams are equipped with the local knowledge and global capabilities to get tens of thousands of businesses up and running on digital media and advertising platforms. By connecting advertisers with top digital media platforms, Aleph is shaping the future for businesses big and small. When local markets have access to global digital capabilities, economies rise. The world of global digital advertising is always transforming; we’ve built our offerings to evolve and solve at pace. With our proprietary technologies and support from our fast-moving teams, our partners stay ahead of what’s next. We’re a global tech company powered by local experts. Aleph: Digital advertising for all

Similar Jobs

Cencora Logo Cencora

Project Manager

Healthtech • Logistics • Pharmaceutical
In-Office
Madrid, Comunidad de Madrid, ESP
51000 Employees

ServiceNow Logo ServiceNow

Consultant

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
Madrid, Comunidad de Madrid, ESP
29000 Employees

Morningstar Logo Morningstar

Data Analyst

Artificial Intelligence • Big Data • Enterprise Web • Fintech • Software • Financial Services
Hybrid
Madrid, Comunidad de Madrid, ESP
11500 Employees
29K-39K Annually

Legora Logo Legora

Head of Legal Engineering, Spain

Artificial Intelligence • Legal Tech • Software
In-Office
Madrid, Comunidad de Madrid, ESP
900 Employees

Similar Companies Hiring

MFour Data Research Thumbnail
Marketing Tech • Software
Irvine, CA
98 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account