# SOC Analyst

**Company:** [HappyRobot](https://hotfix.jobs/companies/happyrobot)
**Location:** Madrid, Spain, Barcelona, Spain
**Role:** Security Engineering
**Experience:** 2+ years
**Skills:** SIEM, Edr, Mitre Att&Ck, Cloud Security, Identity Security, Endpoint Security, AWS, Azure, GCP, Python, Bash, Phishing Analysis, Detection Tuning, SOC 2, ISO 27001
**Posted:** 2026-08-06

> The SOC Analyst owns alert triage, investigates cloud, identity, and endpoint activity, and escalates incidents with actionable context. The role requires 2–3 years of SOC or blue-team experience, hands-on SIEM and EDR work, strong incident documentation, and English communication skills.

## Job Description

## Responsibilities

### Alert Triage
- Own the alert queue during coverage hours.
- Prioritize and disposition alerts accurately and quickly; acknowledge high-severity alerts within 15 minutes and disposition all alerts within SLA.
- Distinguish true positives from noise and act accordingly.

### Log and Threat Analysis
- Analyze cloud, identity, and endpoint log sources to build timelines for alerts requiring deeper investigation.
- Use MITRE ATT&CK to understand attack activity in context.

### Incident Escalation and Communication
- Escalate incidents with severity reasoning, timelines, affected systems, and recommended next steps.
- Write clear incident notes and escalations in English.

### Runbook Discipline and Improvement
- Follow runbooks rigorously.
- Identify incorrect steps, missing cases, and outdated assumptions, and propose fixes.

### Tuning Feedback Loop
- Participate in a weekly feedback cycle with the SOC Engineer.
- Report false positives, noise patterns, and detection logic requiring adjustment.

### Audit Readiness
- Keep monitoring and response evidence current and organized for SOC 2, ISO 27001, and customer incident-response commitments.

## Requirements
- 2–3 years of experience as a SOC analyst or in a blue-team, detection, or response role.
- Hands-on alert-triage experience with a SIEM and EDR, including investigation, disposition, and escalation.
- Log-analysis experience across cloud, identity, and endpoint sources.
- Working knowledge of MITRE ATT&CK and common attack patterns.
- Clear written incident notes and escalations in English at B2+ level.
- Ability to work a coverage-hours rotation.

## Nice to Have
- Familiarity with AWS, Azure, or Google Cloud consoles.
- Basic Python or Bash scripting.
- Phishing and email-threat analysis experience.
- BTL1, GCIH, Security+, or CySA+ certification.
- Exposure to detection tuning or writing simple detection rules.
- Experience at a SaaS or technology startup.

## Compensation and Benefits
- Competitive salary and equity.
- Healthcare, dental, and vision coverage.

## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Senior Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e6f5289c-9cb8-4a13-b321-e0ecc9a54c96) - Docker - Remote - €119k – €170k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Security Engineer - Product](https://hotfix.jobs/jobs/d32dc9fa-f31b-4fc4-a7c6-eade39acfb64) - Wiz - Berlin, Germany

**Apply:** https://hotfix.jobs/jobs/cc33792c-5bf3-4c38-b65d-be6c9c5c9b5e
**Canonical:** https://hotfix.jobs/jobs/cc33792c-5bf3-4c38-b65d-be6c9c5c9b5e