InterviewHack.ai
Empezar gratis
Vacantes / Happyrobot.ai

SOC Engineer

Happyrobot.ai · MadridRemotomid

En corto

  • ▸Ingeniero de seguridad que construye detecciones y pipelines de logs desde cero en entornos cloud e identidad.
  • ▸Diseña alertas de alto valor, automatiza tareas repetitivas y tiene propiedad total del proceso de triage y respuesta.
  • ▸Se espera crear la base para decidir si el SOC será interno o híbrido antes de septiembre.

English B2+

Postularme en la empresa ↗Compartir por WhatsApp

En ~1 minuto te damos: quién te entrevista, las preguntas probables con respuestas desde tu CV, y tu CV adaptado a esta vacante. Gratis, sin tarjeta.

🎧¿Llegás a la entrevista? Llevá el copiloto. Nuestra extensión escucha la entrevista en vivo y te muestra anclas de 3-4 palabras desde tu CV y tu preparación — mirás, conectás, hablás. Gratis. Ver la extensión →

¿Qué piden?

  • ✓3–5 años en ingeniería de detección, SOC o roles de equipo azul.
  • ✓Experiencia práctica construyendo detecciones en SIEM modernos (Panther, Splunk, Sentinel, etc.).
  • ✓Familiaridad profunda con logs de cloud e identidad: CloudTrail, GuardDuty, Kubernetes audit logs, Okta.
  • ✓Habilidad en automatización con Python o Go.
  • ✓Experiencia mapeando detecciones a MITRE ATT&CK.
  • ✓Inglés B2+ (proficiencia profesional).

¿No cumplís todo? Es lo normal — tu dossier gratis te dice qué gaps tenés y cómo cubrirlos en la entrevista.

CloudTrailGuardDutyKubernetes audit logsOktaSIEMRunRevealPantherElasticSplunkSentinel

¿A quién escribirle en Happyrobot.ai?

Tu dossier gratis identifica a las personas que te entrevistarían — con su background, qué valoran y cómo escribirles para destacar antes de aplicar.

ABOUT HAPPYROBOT HappyRobot is the infrastructure for enterprises to build and orchestrate AI workforces. Our AI workers don't just communicate through voice and email - they make decisions, take action, and run operations autonomously across entire enterprise systems. Born in Y Combinator (S23) and backed by a16z, Base10, Prysm Capital and Eurazeo with over $150M raised, we power critical operations for global enterprises worldwide. Our platform is battle-tested in the most demanding environments, where AI has real consequences. We started in logistics, built our own voice stack, models, and orchestration layer from the ground up, and are now bringing that infrastructure to every enterprise that runs the real economy. Learn more about our vision in our manifesto. https://www.happyrobot.ai/blog/manifesto   ROLE OVERVIEW We are looking for a SOC Engineer to join our team. You will build and own our detection and response capability from the ground up — bringing the engineering depth and operational discipline to establish real monitoring across our cloud and identity stack, reduce mean-time-to-detect on security events, and set a foundation that scales into whatever SOC model we choose. This is not an analyst role. Your deepest strength is detection engineering: designing high-signal detections mapped to ATT&CK, managing the tuning loop that keeps false positive rates in check, and building the log pipeline that makes everything else possible. That said, you operate end-to-end — you investigate alerts yourself, write runbooks an analyst can execute without hand-holding, and automate the repetitive work out of existence. What You'll Do - Detection Engineering Design, write, and tune detections mapped to MITRE ATT&CK techniques. Own the false-positive loop — track noise per detection, tune aggressively, and grow coverage across prioritized techniques quarter over quarter. Detections should be high-signal from the start, not high-volume problems to manage later. - Log Pipeline Engineering Onboard, parse, and normalize log sources into the SIEM reliably. Get all tier-1 sources live within the first two quarters and keep the pipeline clean as new sources are added. Deep familiarity with cloud and identity logs — CloudTrail, GuardDuty, Kubernetes audit logs, Okta — is the foundation this work is built on. - Incident Triage & Response Investigate alerts end-to-end. Escalate with clear severity reasoning, complete timeline, and actionable context. Don't hand off half-investigated alerts — own the triage process through to a clear disposition. - Automation Script enrichment, response actions, and repetitive SOC tasks in Python or Go. If something is done manually more than twice, it should be automated. Reduce toil systematically rather than absorbing it. - Runbooks & Documentation Write triage runbooks for all high and critical alert types — documented well enough that an analyst can execute them without asking for clarification. Keep runbooks current as detections and infrastructure evolve. - SOC Foundation Build the monitoring capability that positions us to make an informed in-house vs. hybrid SOC decision by end of September. The architecture, coverage, and process you establish now directly shapes what that model looks like. Must Have - 3–5 years in detection engineering, SOC engineering, or blue team roles. - Hands-on experience building detections in a modern SIEM — RunReveal, Panther, Elastic, Splunk, Sentinel, or similar — not just operating one. - Deep familiarity with cloud and identity log sources: CloudTrail, GuardDuty, Kubernetes audit logs, and IdP/Okta logs. - Scripting and automation proficiency in Python or Go. - Experience mapping detections to MITRE ATT&CK. - English B2+ (professional working proficiency). Nice to Have - Detections-as-code with detection content managed in Git and deployed via CI/CD. - EDR experience with SentinelOne or CrowdStrike. - Incide

No apliques sin prepararte

Investigamos quién te entrevista, adaptamos tu CV y te ensayamos en vivo — gratis la primera.

InterviewHack.ai

Preparate para la entrevista exacta: quién te entrevista, tu CV a medida y coach real.

Producto

VacantesRevisar CV (ATS) gratis¿Cómo suena tu inglés?¿Te pagan bien?Reporte de sueldos LATAMCursos gratisBlogCV a medidaPráctica habladaEs gratis

Empleos remotos

ReactPythonFull-StackLATAMArgentinaMéxicoVer todas →

Preparate

Práctica habladaFrontendBackendAI EngineerPor empresaVendete con tu CV

Empresa

Buscás talentoAcerca deContactoPrivacidadTérminos

© 2026 InterviewHack.ai · Tu CV es tuyo. Nunca se usa para entrenar nada. · Un producto de IA-PTY

Vacantes similares activas

SOC Analyst

Happyrobot.ai · Madrid

→

Enterprise Account Executive

Happyrobot.ai · Bonn

→

Enterprise Account Executive

Happyrobot.ai · Brazil

→

Machine Learning Engineer

Happyrobot.ai · San Francisco

→