Aleph Group, Inc
Aleph Group, Inc
1,001 – 5,000 Employees
AdvertisingFintechMarketing
Aleph Group, Inc. operates at the intersection of digital advertising, marketing, and fintech, helping businesses and digital platforms reach customers in markets around the world. The company works with leading digital platforms to support expansion into new regions, combining local market expertise across five continents with technology for managing digital advertising. Its services also include credit and payment solutions that make digital advertising accessible in more than 50 currencies, along with educational programs designed to train and certify digital marketing professionals.

Security Operations Analyst – Incident Response, Madrid Hybrid

L3 security operations and incident response role protecting Aleph’s global digital advertising infrastructure. Leads incident handling, threat hunting, vulnerability management, and identity governance.

Description

  • Lead the full incident response lifecycle from detection and triage through recovery and post-incident review
  • Act as the main contact for incidents escalated by IT Operations, the Security Engineer, and external sources
  • Maintain and enhance response playbooks covering ransomware, phishing, account compromise, data breaches, insider threats, and related scenarios
  • Maintain incident records, document timelines and actions, and prepare trend reports for the CISO
  • Coordinate with external SOC and MDR providers, assess report quality, and manage escalations
  • Lead data breach investigations, including scope definition, evidence preservation, PII exposure assessment, and coordination with Legal, Privacy, and HR
  • Prepare breach reports detailing findings, root cause, and recommended actions
  • Perform proactive threat hunting and investigate unusual activity
  • Direct threat intelligence work by tracking actors, TTPs, and campaigns and applying intelligence to SIEM/XDR detections and hunting queries
  • Deliver threat intelligence briefings and summaries to the CISO and relevant stakeholders
  • Manage vulnerability operations, including scan planning and execution across infrastructure, endpoints, and cloud environments
  • Assess scan results, prioritise risks, coordinate remediation, monitor progress, and report metrics to the CISO
  • Confirm remediation effectiveness through follow-up scans and spot checks
  • Run recurring access reviews and certify permissions for critical systems
  • Oversee PAM operations, establish policies, monitor privileged accounts, and review administrator access
  • Investigate and address identity anomalies and violations of access policies

Requirements

  • 3–5 years of experience in a SOC, incident response, or security operations position
  • L3-level experience for at least 1–2 years is advantageous
  • Experience deploying or administering IAM and PAM solutions
  • Background working in international or multinational organisations
  • Practical experience handling incident response engagements is highly valued
  • Relevant certifications include GCIH, GCFE, GCFA, CEH, CompTIA CySA+, or equivalent
  • OSCP certification is advantageous
  • Strong practical experience with SIEM platforms and EDR/XDR tools
  • Good working knowledge of the MITRE ATT&CK framework
  • Experience running vulnerability scans with Tenable Nessus, Qualys, Rapid7, or comparable tools
  • Understanding of IAM and PAM principles and platforms such as CyberArk, BeyondTrust, Azure PIM, or equivalent
  • Experience applying DFIR methods, including evidence collection, log analysis, and timeline reconstruction
  • Knowledge of threat intelligence platforms and feeds such as MISP and VirusTotal
  • Understanding of ISO 27001 incident management controls, NIS2 reporting obligations, and PCI DSS requirement 12.10
  • Remain composed and make sound decisions under pressure
  • Investigative approach with structured problem-solving skills
  • Strong ability to document technical work clearly
  • Able to communicate incident updates and findings effectively to technical teams and executive stakeholders
  • Collaborative and proactive, with confidence working asynchronously across time zones
  • English at full professional proficiency (C1/C2) as the primary working language; Spanish proficiency is advantageous.
  • benefits_placeholder

Benefits

  • Annual variable compensation
  • Opportunities for internal career development
  • Shared learning opportunities
  • Collaborative and multicultural workplace
  • Flexible and adaptable working culture

Related Jobs