SlipstreamJobsFresh Startup & VC-Backed Jobs

SOC Analyst

HappyRobot - Madrid, Madrid, Spain - In-office - posted 2026-08-06

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

HappyRobot is infrastructure for enterprises to build and orchestrate AI workforces, backed by a16z and Y Combinator with $150M+ raised. The company powers critical operations for global enterprises, with battle-tested systems in demanding environments. As a SOC Analyst, you will own alert triage during coverage hours, serving as the consistent, accountable owner of security monitoring. Your core strength is rapid triage: prioritizing alerts accurately, distinguishing signal from noise, and escalating with complete context that enables engineers to act immediately without re-investigation. Key responsibilities include: - Alert Triage: Own the queue during coverage hours, prioritizing and dispositioning alerts accurately and fast. High-severity alerts acknowledged within 15 minutes; all alerts dispositioned within SLA. - Log & Threat Analysis: Pivot across cloud, identity, and endpoint log sources to build clear timelines for alerts warranting deeper investigation. Use MITRE ATT&CK as a reference frame. - Incident Escalation & Communication: Escalate incidents with complete, actionable context including severity reasoning, timeline, affected systems, and recommended next steps. Write clearly in English so engineers can act without follow-up questions. - Runbook Discipline & Improvement: Follow runbooks rigorously and flag shortcomings (wrong steps, missing cases, outdated assumptions) with proposed fixes. Drive continuous improvement through critical use of runbooks. - Tuning Feedback Loop: Run weekly feedback cycles with the SOC Engineer, reporting false positives, noise patterns, and cases where detection logic needs adjustment to improve signal quality. - Audit Readiness: Keep monitoring and response evidence current and organized for SOC 2, ISO 27001, and customer incident response commitments. Required: 2–3 years as SOC analyst or blue team/detection and response role; hands-on alert triage with SIEM and EDR; log analysis across cloud, identity, and endpoint sources; MITRE ATT&CK knowledge; clear written English (B2+); comfort with coverage-hours rotation. Nice to have: AWS/Azure/GCP console familiarity; Python or Bash scripting; phishing/email threat analysis; certifications (BTL1, GCIH, Security+, CySA+); detection tuning experience; SaaS/tech startup background.

Similar roles