About this role
<div class="rmk-main-content"> <p class="rmk-introduction"><p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">The <strong>SOC Specialist (m/f/d)</strong> is responsible for the design, maintenance, and enhancement of Security Operations Center (SOC) infrastructure and processes. They work closely with incident responders, analysts, and threat intelligence teams to optimize detection capabilities, improve SOC workflows, and ensure rapid incident triage and response. </span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt"><span>The working location for this position will be in Madrid city where we are currently setting up a new office. We operate a hybrid model, requiring at least 40% of the working time on-site.</span> </span></p></p> <h2 class="rmk-responsibilites-header">Creating passion: your responsibilities</h2> <div class="rmk-resposibilities-content"><ul> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Use Case Development: Design and test new security use cases to enhance the detection and response capabilities of Liebherr’s SIEM system</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Log Source Onboarding: Onboard and integrate various log sources into the SIEM system, ensuring comprehensive visibility across the organization’s IT environment</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">SOAR Playbook Implementation: Design, implement, and maintain SOAR playbooks to automate incident response processes and improve operational efficiency</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">System Optimization: Continuously evaluate and optimize the performance of the SIEM and SOAR systems to ensure they meet the evolving security needs of the organization. Also optimize costs in regards to Log sources and their retention</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Threat Detection Engineering: Design and implement advanced detection techniques and perform threat hunting as well as lead tuning exercises and detection gap analysis</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Collaboration: Work closely with the SOC team and other IT departments to ensure seamless integration of security tools and processes</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Documentation: Maintain thorough documentation of use cases, log source configurations, and SOAR playbooks for future reference and compliance purposes</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Note that this role requires time on-call every 6 to 8 weeks. </span></li> </ul></div> <h2 class="rmk-qualification-header">Contributing your strengths: your qualifications</h2> <div class="rmk-qualification-content"><ul> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">3+ years in cybersecurity, ideally as SOC-Engineer</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Hands-on knowledge of SIEM, and security analytics tools (e.g. Microsoft Sentinel, Microsoft Defender XDR, Elastic SIEM)</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Familiarity with SOAR platforms and automation processes (especially Microsoft Logic Apps, Microsoft Sentinel Automations)</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Experience in security log source onboarding & automation of security tasks</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Proficiency in scripting and programming languages (e.g. Python, PowerShell) for automation tasks</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">English is a Must, German and French are a plus</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Understanding of cybersecurity frameworks and standards (e.g. ISO27001, NIST, GDPR)</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Strong analytical, problem-solving skills and communication skills</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Following certificates are a plus: GIAC Python Coder (GPYC), GIAC Cloud Security Automation (GCSA), GIAC Security Operations Certified (GSOC), Cloud certifications (AWS, Azure, or GCP)</span></li> </ul></div> <h2 class="rmk-our-offer-header">Our commitment to you: your benefits</h2> <div class="rmk-our-offer-content"><p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">At Liebherr, we believe people are at the heart of our success. As part of our international team, you’ll enjoy a secure role in a family-owned company that values innovation, collaboration, and long-term career growth:</span></p> <p> </p> <ul> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Competitive compensation and benefits package that recognizes your expertise</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Flexible and hybrid working model</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Creative freedom and responsibility to shape processes and solutions in our global transformation</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Continuous learning and development with tailored training and certification opportunities</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Meal vouchers</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Life and accident insurance</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Option to include a premium private health insurance package as part of the flexible remuneration</span></li> <li><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">A safe, stable and international workplace within a trusted family business that invests in people</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Please only use the online application option.</span></p> <p><br><span style="font-family:arial, helvetica, sans-serif;font-size:14.0pt">Please note that we do not accept applications via recruitment agencies for this position.</span></p> <p> </p></div> <div class="rmk-posting-closure"> <p class="rmk-closure-content">Have we awoken your interest? Then we look forward to receiving your online application. If you have any questions, please contact Michelle Grünwald.</p> <p class="rmk-closure-claim"><b>One Passion. Many Opportunities.</b></p> </div> </div> <h2 class="rmk-company-header">The company</h2> <p class="rmk-company-content">Liebherr is a family-run technology company that is not only one of the largest construction machinery manufacturers in the world, but also offers high-quality, user-oriented products and services in many other areas. The Group employs nearly 50,000 people in more than 140 companies on all continents.<span id="cke_bm_1976S" style="display:none"> </span> </p> <h2 class="rmk-address-header">Location</h2> <div class="rmk-address-content"> <p class="rmk-company-name">Liebherr IT Shared Service Centre Ibérica, S.L.</p> <p class="rmk-adressline"></p> <p><span class="rmk-postal-code"></span> <span class="rmk-city">Madrid</span></p> <p class="rmk-country">Spain (ES)</p> </div> <h2 class="rmk-recruiter-header">Contact</h2> <div class="rmk-recruiter"> <p class="rmk-recruiter-name">Michelle Grünwald</p> <p class="rmk-recruiter-contact">[email protected]</p> <p class="rmk-recruiter-contact-additional"></p> </div>