SOC Engineer
Job description
About the role
HappyRobot is constructing the foundational layer that allows enterprises to design, manage, and scale AI workforces that operate with genuine autonomy. As our first SOC Engineer, you will architect and own the entire detection and response stack that protects this infrastructure. You are responsible for establishing the monitoring discipline that turns raw telemetry into actionable security intelligence. Your work will directly determine our ability to detect sophisticated threats and respond with speed and precision. You will own the end-to-end lifecycle of security signals, from data ingestion through alert triage to automated remediation. This role requires deep operational rigor to reduce noise while expanding coverage across the most critical attack surfaces. Ultimately, you will set the standard for how this company detects, investigates, and responds to security events at scale.
Key facts
What you'll do
- Detect and map adversarial behavior by engineering high-fidelity detections aligned with MITRE ATT&CK techniques, owning the lifecycle from hypothesis to production.
- Construct and maintain the log ingestion pipeline that ensures CloudTrail, GuardDuty, Kubernetes audit logs, and identity feeds are normalized and searchable in the SIEM.
- Triage security alerts end-to-end, determining severity and impact with clear reasoning, and drive investigations to a complete and documented disposition.
- Script enrichment and response actions using Python or Go to automate manual workflows, systematically eliminating repetitive tasks that create analyst toil.
- Author precise runbooks that enable any analyst to execute complex triage and response steps without requiring additional guidance or hand-offs.
- Evaluate and reduce false positives relentlessly, ensuring each detection delivers high signal value and does not distract from active threats.
- Build the monitoring architecture and operational playbooks that position the company to choose between in-house or hybrid SOC models by the end of September.
- Partner closely with platform and cloud teams to onboard new log sources and ensure data quality, integrity, and coverage as the product footprint grows.
- Maintain deep expertise in cloud and identity log sources, ensuring that detection logic reflects the realities of our infrastructure and threat landscape.
- Continuously measure detection efficacy, tune rules, and document changes so that the security control set evolves with the business.
Requirements
- Bring 3 to 5 years of hands-on experience in detection engineering, SOC engineering, or blue team functions focused on building security controls.
- Demonstrate practical experience building detections in a modern SIEM such as RunReveal, Panther, Elastic, Splunk, or Sentinel, rather than only consuming an interface.
- Show deep familiarity with cloud and identity log sources including CloudTrail, GuardDuty, Kubernetes audit logs, and identity platforms like Okta.
- Prove scripting and automation competence in either Python or Go to build tools that scale and integrate with existing workflows.
- Illustrate experience with the MITRE ATT&CK framework, including mapping techniques, prioritizing coverage, and measuring detection maturity.
- Maintain professional working proficiency in English (B2+) to communicate clearly with stakeholders and document processes.
Nice to have
- Manage detections as code, storing content in Git and deploying changes through CI/CD pipelines to enforce version control and peer review.
- Operate EDR platforms such as SentinelOne or CrowdStrike to understand endpoint telemetry and response capabilities.
- Apply incident response practices beyond triage, including containment, eradication, and recovery coordination.
- Understand CNAPP tools like Wiz and foundational cloud security principles to evaluate misconfigurations and compliance risks.
- Hold industry certifications such as GCIA, GCDA, GCIH, or BTL2 that validate technical security skills.
- Have prior experience at a SaaS or technology startup where you built monitoring capabilities from the ground up under resource constraints.
Practical notes
Work is based in Madrid, and the engagement is full-time. No additional information regarding hours, travel, visa requirements, or application deadlines is provided in the source material.