
Job Overview
Location
Madrid
Job Type
Full-time
Category
DevOps & SysAdmin
Date Posted
August 8, 2026
Full Job Description
đź“‹ Description
- • We are looking for a SOC Engineer to join our team. You will build and own our detection and response capability from the ground up — bringing the engineering depth and operational discipline to establish real monitoring across our cloud and identity stack, reduce mean-time-to-detect on security events, and set a foundation that scales into whatever SOC model we choose.
- • This is not an analyst role. Your deepest strength is detection engineering: designing high-signal detections mapped to ATT&CK, managing the tuning loop that keeps false positive rates in check, and building the log pipeline that makes everything else possible. That said, you operate end-to-end — you investigate alerts yourself, write runbooks an analyst can execute without hand-holding, and automate the repetitive work out of existence.
- • Detection Engineering Design, write, and tune detections mapped to MITRE ATT&CK techniques. Own the false-positive loop — track noise per detection, tune aggressively, and grow coverage across prioritized techniques quarter over quarter. Detections should be high-signal from the start, not high-volume problems to manage later.
- • Log Pipeline Engineering Onboard, parse, and normalize log sources into the SIEM reliably. Get all tier-1 sources live within the first two quarters and keep the pipeline clean as new sources are added. Deep familiarity with cloud and identity logs — CloudTrail, GuardDuty, Kubernetes audit logs, Okta — is the foundation this work is built on.
- • Incident Triage & Response Investigate alerts end-to-end. Escalate with clear severity reasoning, complete timeline, and actionable context. Don't hand off half-investigated alerts — own the triage process through to a clear disposition.
- • Automation Script enrichment, response actions, and repetitive SOC tasks in Python or Go. If something is done manually more than twice, it should be automated. Reduce toil systematically rather than absorbing it.
- • Runbooks & Documentation Write triage runbooks for all high and critical alert types — documented well enough that an analyst can execute them without asking for clarification. Keep runbooks current as detections and infrastructure evolve.
- • SOC Foundation Build the monitoring capability that positions us to make an informed in-house vs. hybrid SOC decision by end of September. The architecture, coverage, and process you establish now directly shapes what that model looks like.
🎯 Requirements
- • 3–5 years in detection engineering, SOC engineering, or blue team roles.
- • Hands-on experience building detections in a modern SIEM — RunReveal, Panther, Elastic, Splunk, Sentinel, or similar — not just operating one.
- • Deep familiarity with cloud and identity log sources: CloudTrail, GuardDuty, Kubernetes audit logs, and IdP/Okta logs.
- • Scripting and automation proficiency in Python or Go.
- • Experience mapping detections to MITRE ATT&CK.
- • English B2+ (professional working proficiency).
🏖️ Benefits
- • Join a world-class team of engineers and builders.
- • Backed by top investors including a16z, Y Combinator, Base10, Prysm Capital and Eurazeo.
- • Have ownership and autonomy of projects and are encouraged to ship.
- • Comprehensive Benefits including healthcare, dental, vision coverage.
- • Competitive salary + equity in a high-growth startup.
Skills & Technologies
See exactly how your profile matches this role — strengths, skill gaps, and what to do about them.
About HappyRobot AI Inc.
HappyRobot AI builds voice AI agents that automate repetitive phone calls for logistics, freight, and supply-chain companies. Its cloud platform lets shippers, brokers, and carriers offload tasks like appointment scheduling, check calls, and rate negotiation to conversational bots that integrate with TMS, ELD, and CRM systems via API. The company targets mid-market and enterprise freight operations seeking to cut labor costs and accelerate data entry without sacrificing accuracy or carrier relationships.
Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.
Newsletter
Weekly remote jobs and featured talent.
No spam. Only curated remote roles and product updates. You can unsubscribe anytime.
Similar Opportunities

Pragmatike Soluciones TecnolĂłgicas S.L.
2 months ago

Nexus Mutual
3 months ago

Skydropx
3 months ago

Pragmatike Soluciones TecnolĂłgicas S.L.
3 months ago