About Aleph

At Aleph, we’re not just part of the digital advertising landscape—we’re shaping its future. Representing the world’s leading platforms, including TikTok, Amazon, Google, and nearly 55 others, we operate in 130+ markets across new and existing geographies. Our mission is to empower advertisers and brands to unlock the full potential of these platforms' advertising capabilities. With a presence spanning continents, Aleph offers you the chance to be part of a fast-growing, innovative team where your work makes a direct impact.

Role Overview

We are looking for an experienced and operationally sharp Security Operations & Incident Response Analyst (L3) to join Aleph's global IT Security team. Reporting to the Global CISO, you will be the first line of defence when incidents occur and the engine behind the team's threat detection and response capabilities. You will own the end-to-end incident response process, lead threat hunting and intelligence activities, and manage the vulnerability and identity governance programmes.

Responsibilities

  • Incident Response: Own and coordinate the end-to-end incident response process (identification, triage, containment, eradication, recovery, and post-incident review). Serve as the primary point of contact for security incidents, maintain incident response playbooks, manage the security incident log, and coordinate with external SOC or MDR providers.
  • Data Breach Management: Lead data breach investigations, scope the breach, gather and preserve evidence, assess PII exposure, and coordinate response with Legal, Privacy, and HR. Produce investigation reports with findings, root cause, and recommendations.
  • Threat Hunting & Intelligence: Conduct proactive threat hunting, manage the Threat Intelligence function, and integrate intelligence into SIEM/XDR detection rules. Produce threat intelligence summaries for the CISO.
  • Vulnerability Management: Own the vulnerability management programme, execute periodic scans, analyse results, prioritise findings, and coordinate remediation with IT Operations.
  • Identity & Access Management (IAM): Manage periodic access reviews, oversee the Privileged Access Management (PAM) programme, and investigate identity-related anomalies.

Aleph offers the chance to be part of a fast-growing, innovative team where your work makes a direct impact in a dynamic, global environment.

  • 3–5 years in a SOC analyst, incident response, or security operations role, with at least 1–2 years at L3 level is a plus.
  • Experience implementing or managing IAM and PAM solutions.
  • Experience working within international or multinational environments.
  • Hands-on experience with incident response engagements (internal or consulting) is strongly valued.
  • Relevant certifications: GCIH, GCFE, GCFA, CEH, CompTIA CySA+, or equivalent. OSCP is a plus.
  • Strong hands-on experience with SIEM platforms (alert triage, rule writing, query development) and EDR/XDR tools.
  • Solid knowledge of the MITRE ATT&CK framework.
  • Experience conducting vulnerability scans using tools such as Tenable Nessus, Qualys, Rapid7, or similar.
  • Familiarity with IAM and PAM concepts and platforms (e.g. CyberArk, BeyondTrust, Azure PIM, or equivalent).
  • Experience with digital forensics and incident response (DFIR) methodologies.
  • Knowledge of threat intelligence platforms and feeds (e.g. MISP, VirusTotal).
  • Understanding of ISO 27001 incident management controls, NIS2 incident reporting obligations, and PCI DSS requirement 12.10.
  • Calm and decisive under pressure.
  • Strong investigative mindset with structured problem-solving approach, excellent documentation skills.
  • Ability to communicate incident status and findings clearly to both technical teams and executive stakeholders.
  • Collaborative and proactive, comfortable working asynchronously across time zones.
  • English: full professional proficiency (C1/C2). Spanish: professional proficiency is a plus.