955,510open jobs
57,746companies
157,915added this week
Browse all
Salary
≈ $29k – $83k per year (Estimated)
Location
Hybrid (Madrid, Spain)
Seniority
Junior · 1+ year exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 29, 2026. First seen by Alion on Sep 26, 2026. Aleph scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Headquartered in Miami, Florida, Aleph is a global digital advertising and ad-tech solutions provider that connects major media platforms with advertisers across emerging and international markets. The company serves as an official advertising sales partner for leading global platforms - including Meta, X, TikTok, and Snapchat - enabling brands to execute localized digital ad campaigns in markets where those platforms do not maintain a physical operational presence.

We are looking for an experienced and operationally sharp Security Operations & Incident Response Analyst (L3) to join Aleph's global IT Security team.

Reporting to the Global CISO, you will be the first line of defence when incidents occur and the engine behind the team's threat detection and response capabilities. You will own the end-to-end incident response process, lead threat hunting and intelligence activities, and manage the vulnerability and identity governance programmes - ensuring Aleph is both able to detect threats quickly and respond to them effectively across a complex, globally distributed environment.

What you'll do:

    Incident Response

  • Own and coordinate the end-to-end incident response process: identification, triage, containment, eradication, recovery, and post-incident review (lessons learned).

  • Serve as the primary point of contact for security incidents escalated from IT Operations, the Security Engineer, and external sources.

  • Maintain and continuously improve incident response playbooks for the most relevant threat scenarios (ransomware, phishing, account compromise, data breach, insider threat, etc.).

  • Manage the security incident log and register: track all incidents, document timelines and actions, and produce trend analysis and reporting for the CISO.

  • Coordinate with external SOC or MDR providers where applicable: review daily reports, validate alert quality, and manage escalation workflows.

  • Data Breach Management

  • Lead data breach investigations: scope the breach, gather and preserve evidence, assess PII exposure, and coordinate response with Legal, Privacy, and HR.

  • Produce breach investigation reports with findings, root cause, and recommendations.

  • Threat Hunting & Intelligence

  • Conduct proactive threat hunting across the environment: develop hypotheses based on threat intelligence, search for indicators of compromise (IoCs), and investigate anomalous behaviour.

  • Manage the Threat Intelligence function: track relevant threat actors, TTPs (MITRE ATT&CK), and sector-specific threat campaigns; integrate intelligence into SIEM/XDR detection rules and hunting queries.

  • Produce threat intelligence summaries and briefings for the CISO and relevant stakeholders.

  • Vulnerability Management

  • Own the vulnerability management programme: schedule and execute periodic vulnerability scans across infrastructure, endpoints, and cloud environments.

  • Analyse scan results, prioritise findings by risk and exploitability, and coordinate remediation with IT Operations within agreed SLAs.

  • Track remediation progress, produce vulnerability metrics, and report status to the CISO.

  • Validate remediation effectiveness through re-scanning and spot-checks.

  • Identity & Access Management (IAM)

  • Manage periodic access reviews: coordinate with system owners and HR to review and certify user permissions across critical systems, ensuring least privilege is maintained.

  • Oversee the Privileged Access Management (PAM) programme: define PAM policies, monitor privileged account usage, and review access rights for administrator-level accounts.

  • Investigate and respond to identity-related anomalies and access policy violations.

What we are looking for:

  • 3-5 years in a SOC analyst, incident response, or security operations role, with at least 1-2 years at L3 level is a plus.
  • Experience implementing or managing IAM and PAM solutions

  • Experience working within international or multinational environments.

  • Hands-on experience with incident response engagements (internal or consulting) is strongly valued.

  • Relevant certifications: GCIH, GCFE, GCFA, CEH, CompTIA CySA+, or equivalent. OSCP is a plus.

  • Strong hands-on experience with SIEM platforms (alert triage, rule writing, query development) and EDR/XDR tools.

  • Solid knowledge of the MITRE ATT&CK framework and its application to threat hunting and incident response.

  • Experience conducting vulnerability scans using tools such as Tenable Nessus, Qualys, Rapid7, or similar.

  • Familiarity with IAM and PAM concepts and platforms (e.g. CyberArk, BeyondTrust, Azure PIM, or equivalent).

  • Experience with digital forensics and incident response (DFIR) methodologies: evidence collection, log analysis, and timeline reconstruction.

  • Knowledge of threat intelligence platforms and feeds (e.g. MISP, VirusTotal, threat intel feeds).

  • Understanding of ISO 27001 incident management controls, NIS2 incident reporting obligations, and PCI DSS requirement 12.10.

  • Calm and decisive under pressure.
  • Strong investigative mindset with structured problem-solving approach, excellent documentation skills.
  • Ability to communicate incident status and findings clearly to both technical teams and executive stakeholders.
  • Collaborative and proactive, comfortable working asynchronously across time zones.
  • English: full professional proficiency (C1/C2) - primary working language. Spanish: professional proficiency is a plus.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
955,510 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Madrid
≈ $30k – $84k per year (Estimated) • Remote (Bulgaria, Poland, Spain) • 2+ years exp • Bachelor's Degree
DevOps
GCP
Heroku
Azure
AWS
Cybersecurity
ISO 27001
SOC 2
GDPR
Management
Jira
Apply
≈ $53k – $148k per year (Estimated) • Hybrid • Full-Time • 2+ years exp • Madrid
Cybersecurity
SIEM
DLP
Apply
$60k – $121k per year • In office • 2+ years exp • Bachelor's Degree • Madrid
DevOps
Azure
Management
OneDrive
Apply
≈ $50k – $127k per year (Estimated) • In office • Sant Cugat del Vallès
Cybersecurity
MISP
MITRE ATT&CK
ThreatConnect
Apply
SOC Leader 12 days ago
≈ $56k – $149k per year (Estimated) • In office • Sant Cugat del Vallès
Cybersecurity
MITRE ATT&CK
SIEM
Apply
$145k – $185k per year • Hybrid • 6+ years exp • Bachelor's Degree
Python
PowerShell
Databases
ElasticSearch
AI/ML
Cursor
Claude Code
LLM
Anomaly Detection
DevOps
Terraform
Ansible
Azure DevOps
GitHub Actions
Kibana
New Relic
AWS CDK
Datadog
Logstash
Azure
CI/CD
Windows Server
AWS
Docker
Kubernetes
Nginx
Chaos Engineering
Configuration Management
Graylog
Amazon EKS
AWS Lambda
Amazon EC2
Incident Management
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
AWS Step Functions
Windows
DNS
Cybersecurity
HashiCorp Vault
SOC 2
NIST 800-53
Least Privilege
Sumo Logic
Active Directory
Cryptography
Vault
Apply
$145k – $185k per year • Hybrid • 2+ years exp • Bachelor's Degree
Python
Java
PowerShell
Java
Flyway
Databases
DynamoDB
OpenSearch
Amazon Aurora
AI/ML
Cursor
Claude Code
Langfuse
LLM
LLM Guardrails
DevOps
Rest API
Terraform
Ansible
Helm
Azure DevOps
GitHub Actions
New Relic
Datadog
Azure
CI/CD
AWS
Docker
Kubernetes
Platform Engineering
Configuration Management
Amazon EKS
AWS Fargate
AWS Lambda
Incident Management
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
AWS Step Functions
API Gateway
DNS
Cybersecurity
SOC 2
NIST 800-53
Least Privilege
Sumo Logic
Apply
DevOps Engineer 6 hours ago
≈ $17k – $43k per year (Estimated) • Remote (Vietnam) • Full-Time • 5+ years exp • Bachelor's Degree • Ho Chi Minh City
Python
Databases
OpenSearch
DevOps
Splunk
Terraform
Helm
CI/CD
ArgoCD
Jenkins
Git
AWS
Docker
Kubernetes
Platform Engineering
Service Mesh
Amazon EKS
Amazon EC2
Amazon S3
IAM
Amazon ECS
Cybersecurity
HashiCorp Vault
Management
Agile
Apply
$128k – $214k per year • In office • TS/SCI • 15+ years exp • Bachelor's Degree • Annapolis Junction
Python
Bash
DevOps
Ansible
CI/CD
Windows Server
AWS
SaltStack
Configuration Management
Amazon EC2
Amazon S3
IAM
Linux
Windows
DNS
Cybersecurity
Active Directory
Apply
≈ $22k – $55k per year (Estimated) • In office • Full-Time • Pune
Python
PowerShell
DevOps
VMWare
Kubernetes
Incident Management
SLI/SLO/SLA
Cybersecurity
Least Privilege
Management
ITIL
Apply
Client Partner 1 day ago
Hybrid • Full-Time • 3+ years exp • Zagreb
Marketing
Salesforce
Apply
In office • Full-Time • Warsaw
Apply
Hybrid • Full-Time • Madrid
Apply
≈ $43k – $98k per year (Estimated) • Hybrid • Full-Time • Madrid
Apply
Hybrid • Full-Time • Madrid
Apply
$45k – $85k per year • Remote (Spain) • Madrid
DevOps
IAM
Apply
$45k – $57k per year • Remote (Spain) • Madrid
Apply
≈ $54k – $100k per year (Estimated) • Remote (Spain) • Madrid
Apply
≈ $49k – $91k per year (Estimated) • Remote (Spain) • Bachelor's Degree • Madrid
Management
Outlook
Microsoft Office
Apply
≈ $32k – $76k per year (Estimated) • Remote (Spain) • 2+ years exp • Madrid
PHP
PHP
WordPress
Management
Microsoft Office
Apply
See all jobs
This is one of many
955,510 more open roles from verified company boards, updated every day.