Job Description
Este es un puesto de trabajo remoto.
Responsibilities
Monitor, detect, and analyze cybersecurity incidents affecting insured clients or MDR service alerts.
Conduct incident response investigations, including malware analysis, phishing, ransomware, vulnerabilities, and intrusion attempts.
Manage crisis situations and support threat actor negotiations in ransomware incidents.
Triage and prioritize alerts, escalate critical threats, and provide actionable recommendations.
Develop and maintain detection use cases : rules, playbooks, and indicators of compromise (IOCs).
Contribute to threat intelligence collection and analysis (TTPs, IOCs, campaigns, CVEs).
Draft clear and structured incident reports, including executive summaries and technical deep-dives.
Collaborate with internal teams (broker managers, customer support, developers) and external stakeholders (brokers, partners, law enforcement).
Drive continuous improvement of CERT processes, automation, and tooling.
Requisitos
Requirements
Bachelor’s degree in Cybersecurity, Computer Science, or equivalent experience.
Strong hands-on experience in SOC operations and SIEM / EPP tools (CrowdStrike, SentinelOne, or similar).
Proven expertise in incident response and digital forensics (log, disk, and memory analysis; tools such as Velociraptor or KAPE).
Knowledge of threat intelligence practices, ATT&CK mapping, and vulnerability management.
Proficiency in scripting and automation (Python, Bash, PowerShell).
Solid understanding of Windows / Linux systems and cloud environments.
Excellent analytical, communication, and reporting skills.
Languages : fluent Spanish and English; Portuguese is highly valued.
Previous experience working in fully remote environments is a strong plus.
Ventajas
Benefits
100% remote role with flexibility and autonomy.
Opportunity to join a CERT team with direct impact on protecting against critical cyber threats.
International environment, working closely with brokers, partners, and law enforcement.
Work with cutting-edge cybersecurity technologies and contribute to continuous process and tooling improvements.
Career development within a strategic sector where cybersecurity and insurance converge.
#LI-JM1
#Li-onsite
Requirements
Cert, Soc
Analyst • Madrid, M, es