···
Log in / Register

SOC Specialist - Data/Analytics/SIEM, Madrid

Indeed
Full-time
Onsite
No experience limit
No degree limit
Puerta del Sol, 4, Centro, 28013 Madrid, Spain
Favourites
Share
Some content was automatically translatedView Original

Description

Job Summary: We are seeking an SOC transformation specialist with a focus on automation, advanced analytics, and AI to enhance threat detection and optimize rules and playbooks. Key Highlights: 1. Focus on automation, advanced analytics, and AI 2. Improved threat detection and SOC optimization 3. Development and operation of AI/ML models SOC Specialist \- Data/Analytics/SIEM We are seeking an SOC transformation specialist with a strong focus on automation, advanced analytics, and artificial intelligence applied to threat detection. The role aims to improve the quality, coverage, and effectiveness of detection capabilities through AI/ML/NLP models, continuous optimization of rules and playbooks, and constant measurement of SOC performance metrics. **Responsibilities:** * Measurement and analysis of detection efficacy (TPR, FPR, Precision/Recall, MTTA, MTTR). * Continuous tuning of rules and analysis of coverage gaps by threat/kill chain. * Conversion of Sigma rules to SIEM/XDR environments (XSIAM, Sentinel, Devo, Elastic). * Automated classification of URLs and emails (phishing/malicious). * Contextual enrichment with CTI (WHOIS, reputation, TTPs). * Development, deployment, and operation of AI/ML models in production environments (MLOps). * Creation of SOC dashboards and reporting (Power BI / Grafana). * Optimization of SOAR playbooks and processes. * Generation of reproducible technical documentation (notebooks, datasets, metrics). **Requirements:** 4–6 years of experience in Data/Analytics. * Experience operating SIEM (alerts, searches, correlation rules). * Advanced Python (pandas, numpy, scikit\-learn). * Knowledge of NLP (spaCy, transformers). * SQL and/or KQL / XQL / SPL / DQL. * Familiarity with CTI (MITRE ATT&CK, NIST, TTPs, IOC lifecycle). * Experience in phishing detection and email analysis. * Use of Git and data pipelines. SIEM, XDR XSIAM, Sentinel, Devo, Elastic , Sigma/SigmaHQ, SQL, KQL, XQL, SPL, DQL, Python pandas, numpy, scikit learn , spaCy, transformers, MLflow, DVC, SOAR, Azure, GCP, Docker, Kubernetes, Power BI, Grafana, Git, MITRE ATT\&CK, NIST.

Source:  indeed View original post
David Muñoz
Indeed · HR

Company

Indeed
Cookie
Cookie Settings
Our Apps
Download
Download on the
APP Store
Download
Get it on
Google Play
© 2025 Servanan International Pte. Ltd.