Logo for Var Group

SOC L3 Engineer

Role overview

Qualifications

  • Bachelor's degree in Computer Engineering, Telecommunications, or equivalent studies
  • Minimum 5 years of experience in cybersecurity teams, ideally 2 years as L3
  • Solid knowledge in log analysis, event correlation, and threat detection
  • Advanced knowledge of SIEM tools (Sentinel and DEVO) and EDR

Responsibilities

  • Lead the investigation and resolution of security incidents
  • Generate reports documenting incidents and lessons learned
  • Participate in detecting improvements in detection rules and use cases for SOC tools
  • Provide technical support to L1 and L2 analysts, including case reviews and technical advice

Key facts

Hard skills

Other skills

  • Microsoft Windows
  • Communication
  • Problem Solving
  • Teamwork

About the company

Var Group logo

Var Group

Var Group, www.vargroup.it, with a 480 million euros turnover as of 30 April 2021, more than 2700 employees in 23 offices throughout Italy, 8 foreign offices in France, Spain, Germany, Romania, Switzerland, Austria and China, is one of the main partners for innovation in the ICT sector. It supports Italian businesses’ competitiveness, offering dedicated solution to major Italian sectors: Manufacturing, Food & Wine, Industrial Mechanics, Automotive, Fashion, Furniture, Retail & Mass Distribution. Var Group constantly renews its offering thanks to continuous research activity and close collaboration with Start-ups and University Centers. Companies have to face increasingly complex challenges and they must be able to count on innovative and specialized solutions. Var Group’s offering draws its strength from the deep knowledge of business processes and the integration of several elements. It is the result of the work carried out by several Business Units focusing on projects development in terms of: Business & Industry Solutions, Digital Cloud, Digital Industries, Digital Process Engineering, Customer Experience, Digital Security, Business Technology Solutions, Smart Services, Data Science. Var Group is fully owned by Gruppo Sesa S.p.A., a leading Italian Group in the field of value-added IT solutions for business segment. The parent company Sesa S.p.A. is listed on the STAR segment of the MTA market of the Italian Stock Exchange.

Company details

Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Nos encontramos en la búsqueda de un perfil como SOC L3 para que se sume a nuestro SOC, en la sub-área de D&R.

✨ Cual será tu misión?

Proporcionar defensa avanzada frente a amenazas de ciberseguridad, realizando liderazgo técnico en la gestión y resolución de alertas e incidentes críticos, así como llevar a cabo análisis profundo de amenazas 🛡️

🔮 ¿Qué buscamos?

  • Grado en Ingeniería Informática, Telecomunicaciones, o estudios equivalentes.

  • Certificaciones valoradas: GCIA, GCIH, CISSP o similares

  • Mínimo 5 años de experiencia en equipos de ciberseguridad. Ideal mínimo 2 años como L3.

  • Sólidos conocimientos en análisis de logs, correlación de eventos y detección de amenazas.

  • Conocimientos en análisis de malware

  • Conocimiento y capacidad de análisis en herramientas EDR

  • Manejo avanzado de herramientas SIEM (Sentinel y DEVO)

  • Experiencia operativa en soluciones SOAR (GoogleSecOps SOAR)

  • Ingles: B2+ (Be prepared to talk 🗣)

👌 Nice-to-have:

  • Conocimientos de scripting para automatización de tareas y de herramientas de CTI (MISP, Cynet, etc)

  • Conocimiento de entornos Windows, Linux y arquitecturas de red empresariales

  • Experiencia en entornos cloud

🎯 ¿Qué retos y tareas puedes encontrar en este puesto?

Gestión de incidentes:

  • Liderar la investigación y resolución de incidentes de seguridad

  • Coordinar acciones de contención, erradicación y recuperación en colaboración con los equipos internos del cliente.

  • Generar informes donde se documente el incidente y lecciones aprendidas

Mejora continua de herramientas y procesos:

  • Participar en la detección de mejoras de reglas de detección y casos de uso para las distintas herramientas del SOC (SIEM, SOAR, EDRs…)

  • Identificar y realizar mejoras avanzadas en procedimientos de actuación.

Análisis Técnico de Amenazas:

  • Realizar investigaciones técnicas profundas y avanzadas de eventos y/o alertas de seguridad escalados desde niveles inferiores.

  • Correlacionar actividades sospechosas con el framework MITRE ATT&CK para la correcta categorización y detección de patrones de ataque y amenazas avanzadas.

  • Identificar, categorizar y mitigar campañas de amenazas persistentes (APTs), o elementos que pudieran indicar la presencia de las mismas.

Coordinación y Mentoría:

  • Proporcionar soporte técnico a analistas L1 y L2, incluyendo revisión de casos y asesoramiento técnico.

💼 ¿Qué ofrecemos?

  • Tipo de contrato: a tiempo completo.

  • Ubicación: remoto desde cualquier parte de España.

  • Modalidad de trabajo: 100% remoto o hibrido desde Madrid/Barcelona.

  • Participación en un proyecto innovador, donde puedes aportar tu talento de forma autónoma y dinámica 💥

  • Oportunidades de crecimiento profesional de forma rápida, en función del desarrollo del mercado.

¿Crees que tienes lo que buscamos? Apply now 🙌

Now that I've applied, what's next? 🤔

1️⃣ Filtrado de solicitudes - Revisaremos tu perfil.

2️⃣ Phone Screening/Entrevista Talent - Si pasas el primer filtro, tendremos una entrevista por teams para indagar un poco más sobre tu perfil, culture fit y check del ingles.

3️⃣ Entrevista Técnica - Con el equipo para evaluar tus conocimientos más técnicos asociados al rol.

4️⃣Fase final: solicitaremos tu vida laboral y/o referencias personales para corroborar la información suministrada.

Valoramos positivamente las solicitudes de personas con certificado de discapacidad igual o mayor al 33%, en cumplimiento de la legislación vigente, Ley General de Derechos de las Personas con Discapacidad y de su inclusión social (LGD). Igualmente, en nuestro objetivo de invertir la tónica de nuestro sector y fomentar el equilibro en nuestro equipo, animamos a potenciales candidatas a aplicar a nuestra vacante para que podamos considerar el mayor número de candidaturas de este género*

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

SOC Analyst Related jobs

Other jobs at Var Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.