# SOC Engineer

**Company:** [HappyRobot](https://hotfix.jobs/companies/happyrobot)
**Location:** Madrid, Spain, Barcelona, Spain
**Role:** Security Engineering
**Experience:** 3+ years
**Skills:** Mitre Att&Ck, SIEM, Cloudtrail, Guardduty, Kubernetes, Okta, Python, Go, Runreveal, Panther, Elastic, Splunk, Microsoft Sentinel, Git, CI/CD
**Posted:** 2026-08-06

> The SOC Engineer will build detection and response capabilities, including SIEM log pipelines, ATT&CK-mapped detections, alert investigation, automation, and runbooks. The role requires 3–5 years of SOC or detection-engineering experience plus strong cloud, identity, scripting, and SIEM expertise.

## Job Description

## Responsibilities

### Detection Engineering
- Design, write, and tune detections mapped to MITRE ATT&CK techniques.
- Track and reduce false positives while expanding coverage of prioritized techniques.

### Log Pipeline Engineering
- Onboard, parse, and normalize log sources into the SIEM.
- Bring tier-1 sources online and maintain reliable pipelines as new sources are added.
- Work with cloud and identity logs, including CloudTrail, GuardDuty, Kubernetes audit logs, and Okta.

### Incident Triage and Response
- Investigate alerts end-to-end.
- Escalate with clear severity reasoning, complete timelines, and actionable context.
- Own the triage process through to a clear disposition.

### Automation
- Script enrichment, response actions, and repetitive SOC tasks in Python or Go.
- Automate recurring manual work to systematically reduce toil.

### Runbooks and Documentation
- Write triage runbooks for all high- and critical-severity alert types.
- Keep runbooks current as detections and infrastructure evolve.

### SOC Foundation
- Build the monitoring capability needed to inform an in-house versus hybrid SOC decision.
- Establish scalable architecture, coverage, and processes.

## Requirements
- 3–5 years of experience in detection engineering, SOC engineering, or blue-team roles.
- Hands-on experience building detections in a modern SIEM such as RunReveal, Panther, Elastic, Splunk, Sentinel, or similar.
- Deep familiarity with cloud and identity log sources, including CloudTrail, GuardDuty, Kubernetes audit logs, and Okta or other identity-provider logs.
- Proficiency in Python or Go scripting and automation.
- Experience mapping detections to MITRE ATT&CK.
- English proficiency at B2 or higher.

## Nice-to-Haves
- Experience with detections-as-code managed in Git and deployed through CI/CD.
- EDR experience with SentinelOne or CrowdStrike.
- Incident-response experience beyond triage.
- CNAPP exposure, such as Wiz, and cloud-security fundamentals.
- Certifications such as GCIA, GCDA, GCIH, or BTL2.
- Experience building monitoring from scratch at a SaaS company or technology startup.

## Compensation and Benefits
- Competitive salary and equity in a high-growth startup.
- Healthcare, dental, and vision coverage.
- Ownership and autonomy over projects.

## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Senior Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e6f5289c-9cb8-4a13-b321-e0ecc9a54c96) - Docker - Remote - €119k – €170k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Security Engineer - Product](https://hotfix.jobs/jobs/d32dc9fa-f31b-4fc4-a7c6-eade39acfb64) - Wiz - Berlin, Germany

**Apply:** https://hotfix.jobs/jobs/2291dfd2-1810-4405-a380-117ffa218165
**Canonical:** https://hotfix.jobs/jobs/2291dfd2-1810-4405-a380-117ffa218165