Senior SOC Engineer
PharmaBiotechQuality Assurancegmppythoncrorave
Job description
Syntegon Telstar S.R.U is a company belonging to the Syntegon Group, which operates worldwide with 7,300 colleagues at 49 locations in over 20 countries.is a company belonging to the Syntegon Group, which operates worldwide. As a brand specialising in the development of GMP consulting, engineering, construction and integrated process equipment projects, we serve companies linked to the life sciences market (pharmaceutical and biotechnology, healthcare, cosmetics, veterinary and food industries), as well as hospitals, laboratories and research centres. We also offer solutions using vacuum and high vacuum technologies for traditional and high-tech industries in the energy and aerospace sectors, as well as scientific experimentation. We are looking for a hands-on  Senior SOC Engineer  to join our team at our offices in  Terrassa (Barcelona)  to help design, build, and continuously improve the technology that powers our Security Operations Center. In this role, you’ll own the engineering backlog across SIEM, SOAR, EDR/XDR, and log pipelines—developing high-fidelity detections, efficient workflows, and resilient security data infrastructure. Working closely with the SOC Leader and analyst teams, you’ll serve as a technical escalation point for complex incidents and help strengthen the SOC through automation, process improvement, and reliable engineering solutions. The ideal candidate combines strong security engineering expertise with a practical, collaborative approach and a passion for enabling analysts to respond more effectively. Key Responsibilities Design, develop, and maintain detection content across SIEM, EDR/XDR, and NDR platforms, aligned to MITRE ATT&CK TTPs, owning the full use case lifecycle from requirements through to tuning and deprecation. Build and optimise SOAR playbooks and automated response workflows, identifying and implementing automation opportunities across triage, enrichment, containment, and evidence collection. Own the onboarding of new log sources and manage data ingestion pipelines for cost-effectiveness, completeness, and reliability. Act as Tier 3 technical escalation for complex investigations and high-severity incidents, supporting forensic analysis, malware triage, and root cause determination. Maintain the health, performance, and reliability of core SOC platforms and evaluate new tooling aligned to the SOC's maturity roadmap. Partner with IT, Cloud, Network, and Identity teams to improve log coverage and response integration, and mentor Tier 1–2 analysts on detection logic and tooling. Ensure detection and engineering controls support relevant compliance requirements and maintain audit-ready documentation across platforms and pipelines. Required Qualifications: 5–8+ years in cybersecurity with 3+ years in a SOC engineering, detection engineering, or senior analyst role. Deep hands-on expertise with SIEM platforms including query authoring and detection rule development. Proven experience building SOAR playbooks and automating security workflows. Strong knowledge of attacker TTPs and the MITRE ATT&CK framework, with the ability to translate them into detection logic. Experience with log onboarding, data normalisation, and pipeline management at scale. Solid understanding of EDR/XDR, NDR, cloud telemetry, and identity signals. Scripting or development skills (e.g., Python, PowerShell, KQL) for automation and tooling integration. Clear written and verbal communication with the ability to document technical content for varied audiences. Preferred Qualifications: Certifications: GIAC (GCIA, GCED, GCIH, GCFA, GMON), Microsoft SC-200, or equivalent cloud security certifications. Experience with threat hunting methodologies and proactive adversary detection. Exposure to offensive security, red teaming, or purple team exercises. Experience in OT/ICS security environments (if relevant to the business). Familiarity with data privacy, eDiscovery, and chain-of-custody requirements during investigations. We kindly ask you to apply in English. Availability to travel ( approximately 10–20% ) when required (HQ in Germany). Por Syntegon y sus subsidiarias, la diversidad es una preocupación clave. Exclusivamente promovemos un ambiente donde todos los empleados, independientemente de su género, edad, origen, religión, orientación sexual, identidad de género o necesidades especiales, sean tratados de manera equitativa. Si esta oferta de trabajo utiliza únicamente la forma masculina, es por razones de legibilidad y se refiere a individuos de todos los géneros.
Stand out for this role
NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.
Tailor my CV now — free to trySimilar Pharma jobs
Associate, Project Management (Pharmaceutical Labeling)
Open Scientific — Hauppauge, us
Maintenance Coordinator
Open Scientific — Bohemia, us
Manufacturing Operators - Pharmaceutical
Open Scientific — Melville, us
Pharmaceutical Mechanics - Packaging, Production, Maintanence
Open Scientific — Hauppauge, us
Warehouse - Pharmaceutical
Open Scientific — Hauppauge, us
Pharmaceutical Machine Operators
Open Scientific — Hauppauge, us