Job Description
Principal Analyst Cyber Security Defense Center (m/f/d)
LOCATION

LOCATION

COMPANY

COMPANY

JOB FIELD

JOB FIELD


JOB TYPE


JOB TYPE

JOB ID


JOB ID


FLEXIBLE WORK OPTIONS


FLEXIBLE WORK OPTIONS

LOCATION

LOCATION


COMPANY

COMPANY


JOB FIELD

JOB FIELD


JOB TYPE

JOB TYPE


JOB ID

JOB ID


FLEXIBLE WORK OPTIONS

FLEXIBLE WORK OPTIONS

RESPONSIBILITIES

  • Lead the technical response to our most complex and high-risk security incidents as Case Lead - from triage and analysis through containment, eradication, resolution, and closure
  • Lead investigations and compromise assessments
  • Analyze complex malicious artifacts (binaries, scripts, documents) through static and dynamic analysis and reverse engineering to determine their underlying, often obfuscated, functionality
  • Drive our hypothesis-driven threat hunting program: design hunting campaigns, validate hypotheses against threat intelligence, and convert findings into durable detection coverage
  • Design, review, and continuously improve detection logic, correlation rules, and SOAR playbooks on our Elastic Security platform, applying Detection-as-Code practices
  • Shape the CSDC automation and AI roadmap: co-design AI-assisted triage and investigation workflows and supervise their operation with clear human-in-the-loop safeguards
  • Define the strategic roadmap for detection and response capabilities together with CSDC leadership; evaluate and recommend new technologies, tools, and methodologies
  • Act as technical advisor to CSDC leadership on capability development, and as senior escalation point and on-call resource for critical incidents
  • Mentor and train Tier 2 and Tier 3 analysts; develop advanced training content and drive knowledge transfer across the team
  • Lead cross-functional initiatives with adjacent teams (Cyber Threat Intelligence, Offensive Security, Vulnerability Management, Platform Engineering) and steer external service providers to meet BASF security requirements
  • Represent the CSDC in internal security governance bodies and in external communities and trusted networks (e.g., BSI, Deutscher CERT-Verbund, CSSA, FIRST)

QUALIFICATIONS

Education and Experience

  • Degree in computer science, IT security, or a comparable technical qualification
  • 8+ years of professional experience in cyber defense, incident response, with a track record as a recognized subject matter expert
  • Demonstrated experience leading technical teams and investigations under pressure in high-stakes situations

 

Technical Expertise

  • Expert-level knowledge of the internals of mainstream operating systems (Microsoft Windows, Linux) and of network protocols and traffic analysis
  • Deep understanding of current attacker tradecraft: advanced persistent threats, actors, infrastructures, and TTPs, structured along MITRE ATT&CK
  • Strong hands-on expertise with Elastic Security as SIEM and EDR: detection rule development and tuning, investigation and hunting; experience with Elastic automation capabilities (workflows, AI Assistant) and ES|QL is a strong plus
  • Proficiency with modern DFIR tooling (e.g., OSQuery, Velociraptor, Volatility, Suricata, Wireshark) and with malware analysis and reverse engineering tools (e.g., Ghidra, IDA Pro, x64dbg, WinDbg)
  • Solid experience in cloud and identity threat detection and response (Microsoft Entra ID / Active Directory, Azure, AWS)
  • Ability to program in Python and ideally Go; confident scripting in common shells (Bash, PowerShell); ability to read C and x86/x64 assembly in the context of reverse engineering
  • Working understanding of AI/ML applications in security operations (model-assisted triage, LLM-assisted investigation, explainability) is a plus

 

Leadership and Communication

  • Proven ability to lead technical experts through stressful situations and to remain a calm, structured decision-maker during critical incidents
  • Strong mentoring and coaching mindset; genuine motivation to grow the analysts around you
  • Confident communication in English, both spoken and written, up to executive level; German language skills are a plus
  • Excellent organizational and time management skills; willingness to participate in an on-call rotation

 

Certifications 

Relevant certifications are valued as supporting evidence of your expertise - none of them is a strict requirement. We particularly welcome:

  • GIAC / SANS: GCIH, GCFA, GNFA, GREM, GCTI, GDAT, or GCDA; the GIAC Security Expert (GSE) designation is a distinguishing qualification at this level
  • Elastic: Elastic Certified Analyst or Elastic Certified Engineer
  • Cloud security: Microsoft SC-200 or AZ-500, AWS Certified Security - Specialty, or GIAC GCLD
  • Offensive and intrusion analysis: OffSec OSCP or OSDA, or CREST Registered Intrusion Analyst (CRIA)

WHAT WE OFFER

  • A secure work environment because your health, safety and wellbeing is always our top priority.
  • Flexible work schedule and Home-office options, so that you can balance your working life and private life.
  • Learning and development opportunities
  • 23 holiday days per year
  • 5 additional days (readjustment)
  • 2 cultural days
  • A collaborative, trustful and innovative work environment
  • Being part of an international team and work in global projects
  • Relocation assistance to Madrid provided

At BASF, the chemistry is right

Because we are counting on innovative solutions, sustainable actions, connected thinking and on you, become a part of our formula for success and develop the future with us - in a global team that embraces diversity and equal opportunities irrespective of gender, age, origin, sexual orientation, disability or belief.At BASF, we are committed to upholding and ensuring compliance with company standards related to quality, environment, health, safety, and energy, in line with our global guidelines.We actively promote a culture of prevention and continuous improvement, encouraging collaboration in initiatives related to quality, environmental protection, health, safety, and energy performance.We foster responsible energy use, promoting efficiency in daily operations and supporting the identification of improvement projects and energy-saving opportunities

Madrid, ESP
BASF Digital Solutions S.L.
Digitalization
Permanent
144454
IT and Digitalization
Spain
Work model:  Hybrid