Skip to main content

SOC Engineer

HappyRobot
Madrid, Spain
Full Time

Job Description

About HappyRobot

HappyRobot is the infrastructure for enterprises to build and orchestrate AI workforces. Our AI workers don't just communicate - they make decisions, take action, and run operations autonomously across voice, email, and enterprise systems. Born in Y Combinator (S23) and backed by a16z and Base10 with over $60M raised, we power critical operations for global enterprises worldwide.

 

Our platform is battle-tested in the most demanding environments - where AI has real consequences. We started in logistics, built our own voice stack, models, and orchestration layer from the ground up, and are now bringing that infrastructure to every enterprise that runs the real economy. Learn more about our vision in our manifesto.

 

Role Overview

We are looking for a SOC Engineer to join our team. You will build and own our detection and response capability from the ground up — bringing the engineering depth and operational discipline to establish real monitoring across our cloud and identity stack, reduce mean-time-to-detect on security events, and set a foundation that scales into whatever SOC model we choose.

This is not an analyst role. Your deepest strength is detection engineering: designing high-signal detections mapped to ATT&CK, managing the tuning loop that keeps false positive rates in check, and building the log pipeline that makes everything else possible. That said, you operate end-to-end — you investigate alerts yourself, write runbooks an analyst can execute without hand-holding, and automate the repetitive work out of existence.


What You'll Do

  • Detection Engineering Design, write, and tune detections mapped to MITRE ATT&CK techniques. Own the false-positive loop — track noise per detection, tune aggressively, and grow coverage across prioritized techniques quarter over quarter. Detections should be high-signal from the start, not high-volume problems to manage later.

  • Log Pipeline Engineering Onboard, parse, and normalize log sources into the SIEM reliably. Get all tier-1 sources live within the first two quarters and keep the pipeline clean as new sources are added. Deep familiarity with cloud and identity logs — CloudTrail, GuardDuty, Kubernetes audit logs, Okta — is the foundation this work is built on.

  • Incident Triage & Response Investigate alerts end-to-end. Escalate with clear severity reasoning, complete timeline, and actionable context. Don't hand off half-investigated alerts — own the triage process through to a clear disposition.

  • Automation Script enrichment, response actions, and repetitive SOC tasks in Python or Go. If something is done manually more than twice, it should be automated. Reduce toil systematically rather than absorbing it.

  • Runbooks & Documentation Write triage runbooks for all high and critical alert types — documented well enough that an analyst can execute them without asking for clarification. Keep runbooks current as detections and infrastructure evolve.

  • SOC Foundation Build the monitoring capability that positions us to make an informed in-house vs. hybrid SOC decision by end of September. The architecture, coverage, and process you establish now directly shapes what that model looks like.


Must Have

  • 3–5 years in detection engineering, SOC engineering, or blue team roles.

  • Hands-on experience building detections in a modern SIEM — RunReveal, Panther, Elastic, Splunk, Sentinel, or similar — not just operating one.

  • Deep familiarity with cloud and identity log sources: CloudTrail, GuardDuty, Kubernetes audit logs, and IdP/Okta logs.

  • Scripting and automation proficiency in Python or Go.

  • Experience mapping detections to MITRE ATT&CK.

  • English B2+ (professional working proficiency).


Nice to Have

  • Detections-as-code with detection content managed in Git and deployed via CI/CD.

  • EDR experience with SentinelOne or CrowdStrike.

  • Incident response experience beyond triage.

  • CNAPP exposure (Wiz or similar) and cloud security fundamentals.

  • Certifications: GCIA, GCDA, GCIH, or BTL2.

  • Prior experience at a SaaS or tech startup building monitoring from scratch.

 

Why join us?

  • Opportunity to work at a high-growth AI startup, backed by top investors.

  • Rapidly growing and backed by top investors including a16z, Y Combinator, and Base10.

  • Ownership & Autonomy - Take full ownership of projects and ship fast.

  • Comprehensive Benefits - Healthcare, dental, vision coverage.

  • Top-Tier Compensation - Competitive salary + equity in a high-growth startup.

  • Work With the Best - Join a world-class team of engineers and builders.

 

Our Operating Principles


Extreme Ownership — We take full responsibility for our work and outcomes. No excuses, no blame-shifting. If something needs fixing, we own it.

Craftsmanship — We sweat the details because details compound. We never settle for "just fine" — whether it's a scoping document, a prototype demo, or a customer conversation.

We are "majos" — Be a good human. Friendly, genuine, kind. We're building something ambitious and it's better when we enjoy it together.

Urgency with Focus — Move fast, but in the right direction. Prioritize ruthlessly. Act decisively. Aim for the highest leverage action.

Talent Density and Meritocracy — Every hire raises the bar. Ability over seniority. Ownership goes to those who earn it.

First-Principles Thinking — Strip problems to their fundamentals, ignore industry dogma, and rebuild from scratch when needed. It's how we build what others think is impossible.

 
 
 

The personal data provided in your application and during the selection process will be processed by Happyrobot, Inc., acting as Data Controller.

By sending us your CV, you consent to the processing of your personal data for the purpose of evaluating and selecting you as a candidate for the position. Your personal data will be treated confidentially and will only be used for the recruitment process of the selected job offer.

In relation to the period of conservation of your personal data, these will be eliminated after three months of inactivity in compliance with the GDPR and legislation on the protection of personal data.

If you wish to exercise your rights of access, rectification, deletion, portability or opposition in relation to your personal data, you can do so through [email protected] subject to the GDPR.

For more information, visit https://www.happyrobot.ai/privacy-policy

By submitting your request, you confirm that you have read and understood this clause and that you agree to the processing of your personal data as described.

Optimize Your Resume for This Job

Get a match score and see exactly which keywords you're missing

Optimize Resume

Job Details

Category
Security
Employment Type
Full Time
Location
Madrid, Spain (Hybrid)
Posted

About HappyRobot

HappyRobot provides a system that creates and manages a workforce of AI workers. The platform builds fully custom workflows and integrates with a variety of systems. The service helps businesses remove data silos and automate tasks in real time.

Found this role interesting?

SOC Engineer
HappyRobot
Apply