Назад
Company hidden
2 часа назад

SOC Engineer (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

SOC Engineer (AI): Building and owning detection and response capabilities for an AI infrastructure platform with an accent on high-signal detections, cloud and identity monitoring, and reliable SIEM log pipelines. Focus on mapping detections to MITRE ATT&CK, investigating alerts end-to-end, automating SOC operations, and establishing a scalable monitoring foundation.

Location: Hybrid work in Madrid or Barcelona, Spain

Company

hirify.global is a high-growth AI startup building infrastructure for enterprises to create and orchestrate autonomous AI workforces across voice, email, and enterprise systems.

What you will do

  • Design, write, tune, and expand high-signal detections mapped to MITRE ATT&CK techniques.
  • Build and maintain reliable SIEM log pipelines for cloud, identity, and Kubernetes sources.
  • Investigate alerts end-to-end, determine severity, create timelines, and drive clear dispositions.
  • Automate enrichment, response actions, and repetitive SOC workflows using Python or Go.
  • Write and maintain actionable triage runbooks for high- and critical-severity alerts.
  • Establish the monitoring architecture, coverage, and processes needed to guide the future SOC model.

Requirements

  • 3–5 years of experience in detection engineering, SOC engineering, or blue team roles.
  • Hands-on experience building detections in a modern SIEM such as RunReveal, Panther, Elastic, Splunk, or Sentinel.
  • Deep familiarity with CloudTrail, GuardDuty, Kubernetes audit logs, and identity provider or Okta logs.
  • Proficiency in Python or Go for scripting and automation.
  • Experience mapping detections to MITRE ATT&CK.
  • Professional English proficiency at B2+ level is required.

Nice to have

  • Detections-as-code managed in Git and deployed through CI/CD.
  • EDR experience with SentinelOne or CrowdStrike.
  • Incident response experience beyond initial triage.
  • CNAPP exposure, cloud security fundamentals, or certifications such as GCIA, GCDA, GCIH, or BTL2.
  • Experience at a SaaS or technology startup building monitoring capabilities from scratch.

Culture & Benefits

  • High-growth AI startup backed by Y Combinator, a16z, and Base10.
  • Ownership and autonomy with an emphasis on shipping quickly and taking responsibility for outcomes.
  • Engineering culture focused on craftsmanship, first-principles thinking, focused execution, and meritocracy.
  • Healthcare, dental, and vision coverage.
  • Competitive salary and equity package.
  • Opportunity to work with a world-class engineering team.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →