Security Operations Analyst (Cyber Defense Operations)
- triage
- Incident Response
- SIEM
- EDR
- Windows
- Linux
- TCP/IP
- Microsoft Sentinel
- Defender
- Azure
- AWS
- GCP
- Splunk
- Microsoft Defender
- CrowdStrike
- MacOS
- Python
- PowerShell
- Bash
- Ruby
- GCIH
- CEH
- GCFA
- CCNA
- MCSE
- GDPR
Location: Valencia, Spain, Hybrid OR Remote across EMEA
Employment: Full-Time Contract
Duration: 6 months, with potential extension
Language: Fluent English required
Industry: Cybersecurity / Cloud / Enterprise Security
About the Opportunity
Pragmatike is recruiting on behalf of a major international organization for aSecurity Operations Analyst to join a global Cybersecurity Operations team.
You’ll be part of a24/7 Security Operations Centre (SOC) responsible for monitoring, detecting, investigating, and responding to cyber threats across enterprise, cloud, network, and endpoint environments.
This is a hands-on security role focused onalert triage, threat investigation, log analysis, incident response, and security monitoring, working alongside cybersecurity specialists distributed across multiple regions.
What You’ll Do
Monitor, triage, and investigate security alerts acrossSIEM, EDR, Microsoft security tools, and cloud platforms.
Analyze host and network logs fromWindows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS.
Investigate suspicious activity, identify root causes, and determine appropriate remediation or escalation.
Supportincident response, remediation, and recovery activities.
Work closely with Incident Response and other cybersecurity teams to manage security threats.
Analyze network and security events usingTCP/IP, syslog, firewall, and network monitoring data.
Identify opportunities to improve detection quality and reduce false positives through tuning and optimization.
Gather technical information from clients to improve security monitoring and detection.
Prepare and present security reports, summaries, and technical findings.
Contribute to SOC procedures, documentation, knowledge bases, and quality-control processes.
Review operational feedback and implement corrective actions to continuously improve service quality.
What We’re Looking For
5+ years of relevant experience in IT/cybersecurity, including security alert triage and incident support.
Hands-on experience working in aSOC environment.
Strong experience withSIEM and EDR platforms.
Advanced log analysis skills across Windows/Linux, databases, applications, and infrastructure.
Strong knowledge ofMicrosoft Security technologies, including Microsoft Sentinel and Defender.
Experience with cloud security acrossAzure, AWS, and/or GCP.
Experience with SIEM platforms such asSplunk, QRadar, ArcSight, Microsoft Sentinel, or ELK.
Experience with at least one EDR solution such asMicrosoft Defender for Endpoint or CrowdStrike.
Knowledge of email security, network monitoring, and incident response.
Strong knowledge ofLinux, macOS, and Windows.
Fluent English with excellent written and verbal communication skills.
Nice to Have
Experience working on an Incident Response team withTier-1/Tier-2 incident triage.
AWS security monitoring experience across IaaS, PaaS, or SaaS environments.
Scripting experience withPython, PowerShell, Bash, Ruby, or similar.
Certifications such asMicrosoft SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.
Customer-facing cybersecurity experience.
Why Join
Work inside aglobal 24/7 cybersecurity operation protecting international organizations.
Gain exposure to large-scalecloud, SIEM, EDR, network, and endpoint security environments.
Collaborate with cybersecurity specialists across multiple regions and disciplines.
Work directly on real-world threat detection and incident response.
Build experience across a broad enterprise security technology stack.
Pragmatike is committed to a fair, transparent, and inclusive recruitment process. We do not discriminate based on age, disability, gender, gender identity or expression, marital or civil partner status, pregnancy or maternity, race, religion or belief, sex, or sexual orientation.
In accordance with GDPR, your personal data will be processed lawfully, fairly, and securely and used solely for recruitment purposes, including sharing it with our client(s) for employment consideration.
Security Operations Analyst (Cyber Defense Operations) · Pragmatike