{"id":1353636,"url":"https://alion.io/job/six-soc-analyst","title":"SOC Analyst","company":{"id":47665,"name":"SIX","domain":"six-group.com","url":"https://alion.io/company/six","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SuccessFactors","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Madrid, Spain"],"countries":["ES"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":41000,"max_usd":101000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":414},"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Azure DevOps","optional":false},{"name":"CI/CD","optional":false},{"name":"Cortex","optional":false},{"name":"Cortex XSOAR","optional":false},{"name":"GitLab","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"Azure","optional":true},{"name":"Prometheus","optional":true}],"status":"live","first_seen_at":"2026-09-13T02:00:00Z","employer_posted_date":"2026-09-13","last_verified_at":"2026-10-02T12:27:13Z","board_verified":true,"closed_at":null,"days_open":20,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":20},"description":"BME - Bolsas y Mercados Españoles - drives the transformation of financial markets and belongs to SIX, the third largest exchange group in Europe.\nWhat sets us apart drives us ahead: between local roots and global relevance, we are a unique blend of tradition and future, of foundation and growth. We value bright minds and inspire them to grow with their ideas. Come and shape the future of finance with us.\n SOC Analyst\nMadrid|Working from home up to 40%| Reference8166\nThe Security Operations Center (SOC) is a critical Line of Defense 1 function at SIX, responsible for detecting, investigating, and responding to cyber threats across endpoint, identity, network, cloud, and email environments. We are looking for a hands-on security professional with experience in incident response, threat hunting, and security monitoring. In this role, you will investigate complex alerts, develop and tune detection use cases, support containment and remediation efforts, improve automation and playbooks, and proactively identify threats to strengthen SIX's overall security posture.\nDoes it sound interesting for you? Apply now with your CV in English. We are looking forward to hearing for you.\nWhat You Will Do\nDevelop, tune, and maintain threat detections and SIEM use cases across endpoint, network, identity, cloud, mail, and M365 environments.\nInvestigate complex security incidents, lead threat analysis, and coordinate containment and remediation activities.\nDesign and improve detection content, SOC automation, SOAR workflows, and incident response playbooks.\nConduct proactive threat hunting using threat intelligence and the MITRE ATT&CK framework.\nIdentify detection gaps and continuously enhance SOC capabilities and security posture.\nMentor junior analysts and contribute to SOC process improvements and knowledge sharing.\nWhat You Bring\n4+ years of experience in SOC operations, detection engineering, threat hunting, and incident response.\nHands-on experience with SIEM, EDR, and SOAR platforms (preferably Sentinel, Elastic, Defender for Endpoint, and Cortex XSOAR).\nStrong background in detection rule development, security investigations, and threat hunting across multiple telemetry sources.\nExperience with scripting, automation, APIs, and tools such as Python, GitLab, Azure DevOps, and CI/CD practices.\nKnowledge of security query languages and frameworks, including MITRE ATT&CK.\nStrong analytical, communication, collaboration, and mentoring skills.\nIf you have any questions, check out our FAQ page or call Sara Perez de la Cuestaat +34 91 709 56 80.\nFor this vacancy we only accept direct applications in English.\nDiversity is important to us. Therefore, we are looking to receiving applications regardless of any personal background.","description_format":"text","description_chars":2756,"description_truncated":false,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response","Payment Processing & Gateways","Stock Exchanges & Market Infrastructure","Financial Data & Market Intelligence"],"lifecycle":[{"event":"open","at":"2026-09-27T20:50:26Z"}],"liveness":{"score":69,"band":"ok","label":"Likely open","p_open":1,"p_active":0.762,"p_room":0.9,"age_days":19,"expected_fill_days":29,"reasons":["conf:7","velocity","win:mid"],"computed_at":"2026-10-02T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/six-soc-analyst","json_url":"https://alion.io/job/six-soc-analyst.json","meta":{"generated_at":"2026-10-03T04:14:55Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4397,"day_limit":5000,"remaining_today":603,"minute_limit":60,"resets_at":"2026-10-04T00:00:00Z"}}}