Security Monitoring Analyst

AXA

Madrid, ESonsitePosted Aug 13, 2026
Posting intelligenceActively listed

About the role

Job Description:

About the job

Job purpose

Security Operations Center (SOC) delivers the following capabilities to the AXA entities around the globe: Security Incident Detection, Threat Hunting, Security Incident Response and Threat Intelligence.

As a Job title, your main objective is to:

We believe the best person to write a detection rule is someone who knows exactly how to bypass it.

We are looking for an experienced Red Teamer who wants to pivot into our primary Detection Strategist. You will own the quality and direction of our detection logic: assess our telemetry and logging posture, identify visibility gaps, define detection requirements, and author high-fidelity detection content that holds up against real-world bypass techniques.

You will be the connective tissue between offensive tradecraft and SOC outcomes - translating attacker behavior into durable, actionable detections.

Main missions

Your main responsibility is to ensure that when an adversary moves, we see it. You will spend most of your time inside our SIEM, crafting high-fidelity alerts based on your knowledge of offensive TTPs.

Your responsibilities include:

Logic Creation: You will author complex KQL queries to detect sophisticated behaviors (e.g., Token manipulation, C2 jitter, etc.) rather than simple IOC matching.

Telemetry Analysis: You will deeply analyze raw logs from EDR, Identity Providers, and Cloud infrastructure to determine what data is missing and work to enable the right logging policies.

False Positive Reduction: You will apply your knowledge of "normal" vs. "malicious" administrative behavior to tune existing rules, ensuring the SOC is not flooded with noise.

Secondary Focus: Targeted Adversary Emulation

You will still get your hands on the keyboard to attack, but the goal is different. you are generating data.

Validation Attacks: You will execute specific, manual attack sequences to verify that a new detection rule triggers.

Gap Analysis: You will simulate specific techniques (mapped to MITRE ATT&CK) to prove where our blind spots are, then immediately switch gears to fix them.

Translate complex threat intelligence and known Red Team techniques into actionable detection logic (KQL).

Review and optimize the current library of detection rules for accuracy and coverage.

Collaborate with the Incident Response team to understand why previous attacks were missed and engineer rules to prevent recurrence.

What we offer

We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.

About the entity

AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.

We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.

We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.

At AXA Group Operations, we want to be recognized in three fields of action:

State-of-the-art Data Technology to drive customer experience

State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks

High-Performing Global Team for stronger partnerships with AXA entities

About AXA

As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on AXA's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Security Engineer roles in Spain varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for Spain medians across recent openings.

You never touch the form - the application is filled and submitted for you on AXA's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.