SOC Engineer

HappyRobot
Madrid, Barcelona
Workplace: HybridFull timeFunction: CybersecurityExperience: 3-5 yearsSkills: ["Ownership","Operational discipline","Automation mindset","Documentation","Extreme ownership"]

Build and own detection and response capabilities end-to-end, designing high-signal detections mapped to MITRE ATT&CK while tuning false-positive rates and expanding coverage. Engineer a reliable log pipeline into the SIEM using cloud and identity sources (CloudTrail, GuardDuty, Kubernetes audit logs, Okta). Triage incidents yourself with clear severity reasoning, automate repetitive SOC tasks in Python or Go, and maintain runbooks to enable analyst execution. Help shape the in-house vs hybrid SOC foundation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
HappyRobot
HappyRobot
1 day ago

SOC Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 19 hours agoStatus: Live

Job Summary

Build and own detection and response capabilities end-to-end, designing high-signal detections mapped to MITRE ATT&CK while tuning false-positive rates and expanding coverage. Engineer a reliable log pipeline into the SIEM using cloud and identity sources (CloudTrail, GuardDuty, Kubernetes audit logs, Okta). Triage incidents yourself with clear severity reasoning, automate repetitive SOC tasks in Python or Go, and maintain runbooks to enable analyst execution. Help shape the in-house vs hybrid SOC foundation.
Location: Madrid, Barcelona
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Design, write, and tune detections mapped to MITRE ATT&CK; own the false-positive tuning loop and expand coverage over time.
  • •Onboard, parse, and normalize log sources into the SIEM, prioritizing tier-1 sources early and keeping the pipeline clean.
  • •Investigate alerts end-to-end, escalating with clear severity reasoning, timelines, and actionable context until a clear disposition.
  • •Automate SOC tasks and response actions in Python or Go to systematically reduce toil.
  • •Write and maintain triage runbooks for high and critical alerts so analysts can execute without clarification.

Pay and Benefits

Equity and Bonus:Equity
Perks:Health InsuranceDentalVision

Key Requirements

  • •3–5 years in detection engineering, SOC engineering, or blue team roles.
  • •Hands-on experience building detections in a modern SIEM (RunReveal, Panther, Elastic, Splunk, Sentinel, or similar).
  • •Deep familiarity with cloud and identity log sources: CloudTrail, GuardDuty, Kubernetes audit logs, and IdP/Okta logs.
  • •Scripting and automation proficiency in Python or Go.
  • •Experience mapping detections to MITRE ATT&CK; English B2+ (professional working proficiency).
Experience:3-5 yearsSOCBlue teamSaaS
Skills:OwnershipOperational disciplineAutomation mindsetDocumentationExtreme ownership
Certifications:GCIAGCDAGCIHBTL2
Languages:English
Tech Stack:MITRE ATT&CKSIEMRunRevealPantherElasticSplunkSentinelCloudTrailGuardDutyKubernetes audit logsOktaIdP logsPythonGoGitCI/CDEDRSentinelOneCrowdStrikeCNAPP

Company Brief

HappyRobot
Builds and manages enterprise AI workers (conversational and document-processing agents) to automate operational workflows for supply chain and logistics companies, integrating with systems to execute tasks, collect real-time data, and drive operational insights.
Industry: Supply Chain Technology
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Valuation: USD 250M to 500M
Funding: Series B
Headquarters: San Francisco, United States
Founded: 2022
WebsiteLinkedInGlassdoor