InterviewHack.ai
Start free
Jobs / Happyrobot.ai

SOC Engineer

Happyrobot.ai · MadridRemotemid

In short

  • ▸Ingeniero de seguridad que construye detecciones y pipelines de logs desde cero en entornos cloud e identidad.
  • ▸Diseña alertas de alto valor, automatiza tareas repetitivas y tiene propiedad total del proceso de triage y respuesta.
  • ▸Se espera crear la base para decidir si el SOC será interno o híbrido antes de septiembre.

English B2+

Apply on company site ↗Share on WhatsApp

In ~1 minute you get: who interviews you, the likely questions answered from your CV, and your CV tailored to this job. Free, no card.

🎧Land the interview? Bring the copilot. Our free extension listens to the live interview and flashes 3-4-word anchors from your resume and prep — glance, connect, talk. Get the extension →

What they ask for

  • ✓3–5 años en ingeniería de detección, SOC o roles de equipo azul.
  • ✓Experiencia práctica construyendo detecciones en SIEM modernos (Panther, Splunk, Sentinel, etc.).
  • ✓Familiaridad profunda con logs de cloud e identidad: CloudTrail, GuardDuty, Kubernetes audit logs, Okta.
  • ✓Habilidad en automatización con Python o Go.
  • ✓Experiencia mapeando detecciones a MITRE ATT&CK.
  • ✓Inglés B2+ (proficiencia profesional).

Don't tick every box? That's normal — your free dossier shows your gaps and how to cover them in the interview.

CloudTrailGuardDutyKubernetes audit logsOktaSIEMRunRevealPantherElasticSplunkSentinel

Who should you write to at Happyrobot.ai?

Your free dossier identifies the people who'd interview you — their background, what they value, and how to reach out so you stand out before applying.

ABOUT HAPPYROBOT HappyRobot is the infrastructure for enterprises to build and orchestrate AI workforces. Our AI workers don't just communicate through voice and email - they make decisions, take action, and run operations autonomously across entire enterprise systems. Born in Y Combinator (S23) and backed by a16z, Base10, Prysm Capital and Eurazeo with over $150M raised, we power critical operations for global enterprises worldwide. Our platform is battle-tested in the most demanding environments, where AI has real consequences. We started in logistics, built our own voice stack, models, and orchestration layer from the ground up, and are now bringing that infrastructure to every enterprise that runs the real economy. Learn more about our vision in our manifesto. https://www.happyrobot.ai/blog/manifesto   ROLE OVERVIEW We are looking for a SOC Engineer to join our team. You will build and own our detection and response capability from the ground up — bringing the engineering depth and operational discipline to establish real monitoring across our cloud and identity stack, reduce mean-time-to-detect on security events, and set a foundation that scales into whatever SOC model we choose. This is not an analyst role. Your deepest strength is detection engineering: designing high-signal detections mapped to ATT&CK, managing the tuning loop that keeps false positive rates in check, and building the log pipeline that makes everything else possible. That said, you operate end-to-end — you investigate alerts yourself, write runbooks an analyst can execute without hand-holding, and automate the repetitive work out of existence. What You'll Do - Detection Engineering Design, write, and tune detections mapped to MITRE ATT&CK techniques. Own the false-positive loop — track noise per detection, tune aggressively, and grow coverage across prioritized techniques quarter over quarter. Detections should be high-signal from the start, not high-volume problems to manage later. - Log Pipeline Engineering Onboard, parse, and normalize log sources into the SIEM reliably. Get all tier-1 sources live within the first two quarters and keep the pipeline clean as new sources are added. Deep familiarity with cloud and identity logs — CloudTrail, GuardDuty, Kubernetes audit logs, Okta — is the foundation this work is built on. - Incident Triage & Response Investigate alerts end-to-end. Escalate with clear severity reasoning, complete timeline, and actionable context. Don't hand off half-investigated alerts — own the triage process through to a clear disposition. - Automation Script enrichment, response actions, and repetitive SOC tasks in Python or Go. If something is done manually more than twice, it should be automated. Reduce toil systematically rather than absorbing it. - Runbooks & Documentation Write triage runbooks for all high and critical alert types — documented well enough that an analyst can execute them without asking for clarification. Keep runbooks current as detections and infrastructure evolve. - SOC Foundation Build the monitoring capability that positions us to make an informed in-house vs. hybrid SOC decision by end of September. The architecture, coverage, and process you establish now directly shapes what that model looks like. Must Have - 3–5 years in detection engineering, SOC engineering, or blue team roles. - Hands-on experience building detections in a modern SIEM — RunReveal, Panther, Elastic, Splunk, Sentinel, or similar — not just operating one. - Deep familiarity with cloud and identity log sources: CloudTrail, GuardDuty, Kubernetes audit logs, and IdP/Okta logs. - Scripting and automation proficiency in Python or Go. - Experience mapping detections to MITRE ATT&CK. - English B2+ (professional working proficiency). Nice to Have - Detections-as-code with detection content managed in Git and deployed via CI/CD. - EDR experience with SentinelOne or CrowdStrike. - Incide

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.

InterviewHack.ai

Prepare for the exact interview: who's interviewing you, a tailored CV, and a real coach.

Product

JobsFree ATS checkerInterview-English checkSalary checkLATAM salary reportFree coursesBlogTailored CVSpoken practiceIt's free

Remote jobs

ReactPythonFull-StackLATAMArgentinaMexicoSee all →

Prepare

Spoken practiceFrontendBackendAI EngineerBy companySell with your CV

Company

For employersAboutContactPrivacyTerms

© 2026 InterviewHack.ai · Your CV is yours. Never used to train anything. · A product of IA-PTY

Similar open roles

SOC Analyst

Happyrobot.ai · Madrid

→

Enterprise Account Executive

Happyrobot.ai · Bonn

→

Enterprise Account Executive

Happyrobot.ai · Brazil

→

Machine Learning Engineer

Happyrobot.ai · San Francisco

→