
Security Operations and Incident Response Analyst
Real job — pulled straight from Aleph’s careers page · Verified September 29, 2026 · No reposts.
Job description
Aleph is hiring a Security Operations and Incident Response Analyst — a full-time, based in Madrid, Spain role. Apply directly on Aleph's careers page below.
Security Operations & Incident Response Analyst
Team: Information Technology
Location: Madrid, Spain
Commitment: Full time
Workplace Type: hybrid
What you'll do:
-
Own and coordinate the end-to-end incident response process: identification, triage, containment, eradication, recovery, and post-incident review (lessons learned).
-
Serve as the primary point of contact for security incidents escalated from IT Operations, the Security Engineer, and external sources.
-
Maintain and continuously improve incident response playbooks for the most relevant threat scenarios (ransomware, phishing, account compromise, data breach, insider threat, etc.).
-
Manage the security incident log and register: track all incidents, document timelines and actions, and produce trend analysis and reporting for the CISO.
-
Coordinate with external SOC or MDR providers where applicable: review daily reports, validate alert quality, and manage escalation workflows.
-
Lead data breach investigations: scope the breach, gather and preserve evidence, assess PII exposure, and coordinate response with Legal, Privacy, and HR.
-
Produce breach investigation reports with findings, root cause, and recommendations.
-
Conduct proactive threat hunting across the environment: develop hypotheses based on threat intelligence, search for indicators of compromise (IoCs), and investigate anomalous behaviour.
-
Manage the Threat Intelligence function: track relevant threat actors, TTPs (MITRE ATT&CK), and sector-specific threat campaigns; integrate intelligence into SIEM/XDR detection rules and hunting queries.
-
Produce threat intelligence summaries and briefings for the CISO and relevant stakeholders.
-
Own the vulnerability management programme: schedule and execute periodic vulnerability scans across infrastructure, endpoints, and cloud environments.
-
Analyse scan results, prioritise findings by risk and exploitability, and coordinate remediation with IT Operations within agreed SLAs.
-
Track remediation progress, produce vulnerability metrics, and report status to the CISO.
-
Validate remediation effectiveness through re-scanning and spot-checks.
-
Manage periodic access reviews: coordinate with system owners and HR to review and certify user permissions across critical systems, ensuring least privilege is maintained.
-
Oversee the Privileged Access Management (PAM) programme: define PAM policies, monitor privileged account usage, and review access rights for administrator-level accounts.
-
Investigate and respond to identity-related anomalies and access policy violations.
Incident Response
Data Breach Management
Threat Hunting & Intelligence
Vulnerability Management
Identity & Access Management (IAM)
What we are looking for:
- 3–5 years in a SOC analyst, incident response, or security operations role, with at least 1–2 years at L3 level is a plus.
-
Experience implementing or managing IAM and PAM solutions
-
Experience working within international or multinational environments.
-
Hands-on experience with incident response engagements (internal or consulting) is strongly valued.
-
Relevant certifications: GCIH, GCFE, GCFA, CEH, CompTIA CySA+, or equivalent. OSCP is a plus.
-
Strong hands-on experience with SIEM platforms (alert triage, rule writing, query development) and EDR/XDR tools.
-
Solid knowledge of the MITRE ATT&CK framework and its application to threat hunting and incident response.
-
Experience conducting vulnerability scans using tools such as Tenable Nessus, Qualys, Rapid7, or similar.
-
Familiarity with IAM and PAM concepts and platforms (e.g. CyberArk, BeyondTrust, Azure PIM, or equivalent).
-
Experience with digital forensics and incident response (DFIR) methodologies: evidence collection, log analysis, and timeline reconstruction.
-
Knowledge of threat intelligence platforms and feeds (e.g. MISP, VirusTotal, threat intel feeds).
-
Understanding of ISO 27001 incident management controls, NIS2 incident reporting obligations, and PCI DSS requirement 12.10.
- Calm and decisive under pressure.
- Strong investigative mindset with structured problem-solving approach, excellent documentation skills.
- Ability to communicate incident status and findings clearly to both technical teams and executive stakeholders.
- Collaborative and proactive, comfortable working asynchronously across time zones.
-
English: full professional proficiency (C1/C2) — primary working language. Spanish: professional proficiency is a plus.
In line with the EU Pay Transparency Directive, we are committed to fair and open compensation practices. For this role, the minimum gross annual base salary is EUR 48,000 EUR.
In addition to base salary, this role includes a variable component, paid annually. The final offer will reflect your experience, skills, and the scope of the role.
#Aleph
Get Security Analyst jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Senior Information Security Engineer, Incident Response
Frequently asked questions
What skills are required for Security Operations and Incident Response Analyst at Aleph?
The required skills for Security Operations and Incident Response Analyst at Aleph include: SIEM, IAM, ISO 27001, PCI DSS.
What is the seniority level for Security Operations and Incident Response Analyst at Aleph?
Security Operations and Incident Response Analyst at Aleph is a Mid Level / Senior level position.
How do I apply for Security Operations and Incident Response Analyst at Aleph?
You can view the full description and apply for Security Operations and Incident Response Analyst at Aleph on EchoJobs: https://echojobs.io/job/aleph-security-operations-incident-response-analyst-jpvyy.