SOC Technical Lead – Threat Hunting & Incident Response

Posted 24 Days Ago
Be an Early Applicant
Hiring Remotely in Emilio Vargas, La Galerita, Abasolo, Guanajuato, MEX
Remote
Mid level
Artificial Intelligence • Big Data • Information Technology • Security • Software
The Role
Lead threat hunting and incident response efforts, perform deep-dive forensics and root-cause analysis, mentor SOC engineers, architect security integrations with cloud and product teams, and drive automation and Security-as-Code to improve detection and response.
Summary Generated by Built In
Location: Madrid Emilio Vargas, Spain

Thales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billions of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more. More than 30,000 organizations already rely on us to verify the identities of people and things, grant access to digital services, analyze vast quantities of information and encrypt data to make the connected world more secure.

Thales in Spain is a leader in technological solutions applied to Defence, Aeronautics, Security, Transportation and Space and, furthermore, is a global centre for excellence in Space, Security of Critical Infrastructures and Transportation. With a turnover of €320 million and a staff of 1,200, it exports approximately 40% of its total production principally to the Middle East, North Africa and Latin America.

At Thales S21sec Spain, we are looking for a SOC Technical Lead – Threat Hunting & Incident Response with 4+ years of experience in cybersecurity to join our central services team.

We are seeking a highly motivated professional with strong expertise in cybersecurity infrastructures, capable of supporting and managing complex technological environments across leading security vendors.

Join the Team Defending Thales’ Future At Thales, we don't just respond to threats—we anticipate them. We are looking for a visionary SOC Technical Lead who thrives at the intersection of advanced threat hunting, rapid incident response, and team mentorship. If you are passionate about building resilient security architectures and want to lead a team that is defining the next generation of SOC services, this is your opportunity to make a lasting impact.

Key Responsibilities
  • Drive Proactive Defense: You will spearhead our threat hunting strategy, utilizing advanced telemetry and intelligence to uncover sophisticated attacker patterns before they impact our infrastructure.
  • Lead Through Crisis: You will be the technical force behind our Incident Response, guiding the team through high-pressure situations, conducting deep-dive forensics, and refining our defense playbook to stay ahead of the adversary.
  • Mentor and Innovate: You will elevate the talent around you. Through hands-on mentorship, technical workshops, and collaboration, you will cultivate a culture of continuous improvement and technical excellence.
  • Architect the Future: You will partner with our cloud and product teams to integrate security into every stage of the lifecycle. By championing "Security-as-Code" and automation, you will transform how we monitor and protect our global ecosystem.
Requirements
  • Experience: Minimum 2–5 years of experience in Cybersecurity, with a strong focus on Security Operations, Incident Response, or Threat Hunting.
  • Demonstrated experience in a technical lead or senior-level advisory role, guiding teams through complex technical challenges.
  • Proven background in managing security operations within high-scale, distributed environments (Cloud or Hybrid).
  • Advanced understanding of attacker TTPs (Tactics, Techniques, and Procedures) and the MITRE ATT&CK framework.
  • Deep expertise in SIEM/SOAR platforms, EDR/XDR tools, and network traffic analysis.
  • Experience with Cloud security (AWS, Azure, or GCP) and understanding of shared responsibility models.
  • Experience leading large-scale incident investigations and performing root-cause analysis.
  • Familiarity with forensic analysis tools and procedures.
Why Join Thales S21sec Spain?

At Thales S21sec, we pride ourselves on being innovative and flexible in how we work. We continuously evolve our policies to ensure a true work-life balance.

100% Flexible Hybrid Work
Work from home or come to the office whenever you choose.

Up to 41 Days Off Per Year

  • 24 vacation days + additional flexible days

  • Option to enjoy one free Friday per month (12 per year)

  • Choose between summer reduced hours or extra days of

Flexible Compensation Package

Optimize your net salary with benefits such as meal vouchers, transport cards, childcare vouchers, and training support.

Continuous Learning & Certifications
Access to an annual training plan including technical certifications, languages, and soft skills.

Knowledge Sharing Culture
Participate in our voluntary Speakers Program and share your expertise.

Performance-Based Bonuses
Clear and transparent objectives aligned with KPI-based annual bonuses.

Career Growth Your Way
Choose your path:

  • Leadership and team management

  • Deep technical specialization with top experts

💡 Join Us

If you are passionate about cybersecurity and want to make an impact, we are your company.

👉 We’re looking forward to meeting you!

At Thales we provide CAREERS and not only jobs. With Thales employing 80,000 employees in 68 countries our mobility policy enables thousands of employees each year to develop their careers at home and abroad, in their existing areas of expertise or by branching out into new fields. Together we believe that embracing flexibility is a smarter way of working. Great journeys start here, apply now!

Skills Required

  • Minimum 2-5 years of experience in Cybersecurity with focus on Security Operations, Incident Response, or Threat Hunting
  • Demonstrated experience in a technical lead or senior-level advisory role
  • Proven background managing security operations in high-scale, distributed (cloud or hybrid) environments
  • Advanced understanding of attacker TTPs and the MITRE ATT&CK framework
  • Deep expertise in SIEM and SOAR platforms, EDR/XDR tools, and network traffic analysis
  • Experience with cloud security (AWS, Azure or GCP) and shared responsibility models
  • Experience leading large-scale incident investigations and performing root-cause analysis
  • Familiarity with forensic analysis tools and procedures

Thales Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Thales and has not been reviewed or approved by Thales.

  • Retirement Support Retirement plans with employer contributions and matches, profit sharing, and share purchase opportunities are emphasized across multiple regions. These elements are positioned as competitive components of total rewards.
  • Leave & Time Off Breadth Generous PTO that increases with tenure, paid holidays, and paid military, maternity, and paternity leave are described. This breadth supports work–life balance across locations.
  • Flexible Benefits Hybrid work options, flexible schedules, and parental supports such as childcare benefits and leave for sick children are available in several markets. Flexibility is presented as a core part of the employee experience.

Thales Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Paris
63,258 Employees

What We Do

Thales is a global high technology leader investing in digital and “deep tech” innovations – connectivity, big data, artificial intelligence, cybersecurity and quantum technology – to build a future we can all trust, which is vital to the development of our societies. The company provides solutions, services and products that help its customers – businesses, organisations and states – in the defence, aeronautics, space, transportation and digital identity and security markets to fulfil their critical missions, by placing humans at the heart of the decision-making process.

Similar Jobs

McCain Foods Logo McCain Foods

KAM Retail

Food • Retail • Agriculture • Manufacturing
Remote
México
20000 Employees

Samsara Logo Samsara

Customer Success Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
México
4000 Employees
1M-1M Annually

Samsara Logo Samsara

Account Validation Specialist - MX

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
México
4000 Employees

Dropbox Logo Dropbox

Software Engineer

Artificial Intelligence • Cloud • Consumer Web • Productivity • Software • App development • Data Privacy
Remote
México
2500 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account