SOC Technical Lead – Threat Hunting & Incident Response

Thales
Spain
Workplace: HybridFull timeFunction: Administration & Executive AssistanceExperience: 2-5 yearsSkills: ["Mentorship","Teamwork","Technical leadership","Continuous improvement","Collaboration"]

Lead proactive cyber defense by driving threat-hunting using advanced telemetry and intelligence, and oversee rapid incident response with deep-dive forensics and continuous refinement of the defense playbook. Serve as a technical force for a SOC central services team, mentoring engineers through workshops and hands-on guidance while partnering with cloud and product teams to advance Security-as-Code automation across the global ecosystem.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Thales
Thales
1 month ago

SOC Technical Lead – Threat Hunting & Incident Response

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Lead proactive cyber defense by driving threat-hunting using advanced telemetry and intelligence, and oversee rapid incident response with deep-dive forensics and continuous refinement of the defense playbook. Serve as a technical force for a SOC central services team, mentoring engineers through workshops and hands-on guidance while partnering with cloud and product teams to advance Security-as-Code automation across the global ecosystem.
Location: Spain
Workplace: Hybrid
Employment Type: Full time
Job Function: Administration & Executive Assistance

Key Responsibilities

  • •Drive the threat-hunting strategy using telemetry and intelligence to identify attacker patterns before they impact infrastructure.
  • •Lead incident response during high-pressure situations, including deep-dive forensics and defense playbook refinement.
  • •Mentor the team through hands-on guidance, technical workshops, and collaboration to foster continuous improvement.
  • •Partner with cloud and product teams to integrate security across the lifecycle using Security-as-Code and automation.
  • •Support and manage complex cybersecurity infrastructure across leading security vendors.

Pay and Benefits

Perks:Meal VouchersCommuter BenefitsChildcare VouchersTraining SupportPaid LeaveAnnual TrainingAnnual Bonus

Key Requirements

  • •Minimum 2–5 years of cybersecurity experience focused on Security Operations, Incident Response, or Threat Hunting.
  • •Experience in a technical lead or senior-level advisory role guiding teams through complex technical challenges.
  • •Experience managing security operations in high-scale, distributed environments (cloud or hybrid).
  • •Advanced knowledge of attacker TTPs and the MITRE ATT&CK framework.
  • •Deep expertise in SIEM/SOAR platforms, EDR/XDR tools, and network traffic analysis; familiarity with forensics tools and root-cause analysis.
Experience:2-5 yearsCybersecuritySecurity operationsIncident responseThreat huntingSOCSIEM/SOAREDR/XDRCloud security
Skills:MentorshipTeamworkTechnical leadershipContinuous improvementCollaboration
Tech Stack:MITRE ATT&CKSIEMSOAREDRXDRNetwork traffic analysisAWSAzureGCPSecurity-as-Code

Company Brief

Thales
Designs and delivers advanced systems and services for aerospace, defence, security, and digital identity and cybersecurity markets, serving government and commercial customers worldwide.
Industry: Defense Technology
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Paris, France
Founded: 2000
WebsiteLinkedIn