Why choose AstraZeneca Spain?
AstraZeneca Spain is a rising force in our global business. With headquarters in Madrid and our global hub in Barcelona, we’ve become an important international centre of excellence in the fight against critical disease. Boasting vibrant universities and business schools, the Barcelona ecosystem is a place where scientists can thrive. We attract a diverse workforce from across the globe, shining a beacon for innovation in a country that’s committed to clinical development.
We invite you to bring your talents to Barcelona where our respiratory medicine R&D and Global Marketing centre offers opportunities in R&D, IT, Commercial and HR. Or join us in Madrid and shape our growth in our BUs (Respiratory, Oncology & CVRM ), and a range of Corporate functions. Additionally, you can find sales roles throughout the country. Together, we’re contributing to a world-leading pipeline of therapeutics and delivering life-changing medicines to patients.
Who do we look for?
Calling all tech innovators, ownership takers, challenge seekers and proactive collaborators. At AstraZeneca Spain, breakthroughs born in the lab become transformative medicine for the world's most complex diseases. Alongside technical expertise, colleagues have the resilience, energy and collaborative mindset to change lanes, work with different teams and start projects from scratch.
Here, diverse minds and bold disruptors can meaningfully impact the future of healthcare using cutting-edge technology. Whether you join us in Madrid or Barcelona, you can make a tangible impact within a global biopharmaceutical company that invests in your future. Join a talented global team that's powering AstraZeneca to better serve patients every day.
Success Profile
Ready to make an impact in your career? If you're passionate, growth-orientated and a true team player, we'll help you succeed. Here are some of the skills and capabilities we look for.
Diverse collaborators
This is a speak-up culture that values collaboration. You’ll proactively bring your unique perspectives, experiences and skills to the table and seek the same from others. With our international team composition and the need for fast-paced collaboration, you’ll always be building new connections with colleagues.
Cutting-edge innovators
When you join us, you’ll be part of a team that embraces digital technology and data to transform the way we work and the work we do. Every day, you’ll help make history, empowered to ignite your creativity and build something enduring.
Resilient trailblazers
Here, the answers aren’t always available. So, you’ll need to bring a fearless, self-starter mindset to navigate uncharted territories. You’ll harness your ceaseless energy to discover and make the necessary connections with colleagues to shape the future and achieve maximum impact.
Agile movers
Seize ownership and excel with autonomy to enjoy the constant rush of ground-breaking discovery. Your ability to anticipate sudden shifts and adapt swiftly will prove critical as you make your mark in an environment that rewards initiative and resilience.
Responsibilities
Role based in Barcelona - 3 days onsite office / 2 days at home
Evinovadelivers market-leading digital health solutions that are science-based, evidence-led, and human experience-driven. Thoughtful risks and quick decisions come together to accelerate innovation across the life sciences sector. Be part of a diverse team that pushes the boundaries of science by digitally empowering a deeper understanding of the patientswe’rehelping. Launch pioneering digital solutions that improvethe patients’ experience and deliver better health outcomes.Together, we have the opportunity to combine deep scientific expertise with digital and artificial intelligence to serve the wider healthcare community and create new standards across the sector.
The Cyber Defense Engineer atEvinovais positionedas an internal subject matter expert for cyber threat detection, analysis,and response.The successful candidatewill bespecifically accountable for the design, engineering, and operational execution of our cyber threat detection and response capabilities across a globalmulti-cloud environmentand will be exposed to several leading technologies such as Amazon Web Services, Microsoft 365,SalesForce, Splunk Cloud, and several others.
This roleoperatesas the primary technical escalation point for all cyber threatsidentifiedby our Security Operations Center(SOC)andis responsible forvalidating, investigating, and directing responses to escalated security incidents. This role provides a unique blend of technical detection engineering with threat-informed cyber defense strategy ownership.
WithEvinovapositioned asa trusted technology partner to Life Sciences and Pharmaceutical Research focused organizations, this role will be exposed to regulated workloads, clinical data, andGxP-relevant systems. Considering our business context, success in this role requires adequate understanding of system assurance principles, data integrity controls, and relevant externalguidance /compliance requirements (e.g., ISO 27001, SOC2, NIST CSF, UK / EU GDPR, etc.).
This position is ideal for technically skilled cybersecurity professionals who thrive in fastpaced global organizations and enjoy solving complex operational challenges with innovative approaches. In addition to supporting the Cyber Defense pillar, this role will have daily exposure across our entire cybersecurityfunctionand working collaboratively to secureEvinova'sDigital Health Suite.
This position will report directly to theEvinovaHead of Cybersecuritywith a dotted line to the Head of Cybersecurity Engineeringand will have several peers to collaboratewith;ensuring adequate leadership visibility and cross-functional exposure across adjacent cyber domains.If you are a cyber defense pro looking to gaincyberleadershipexperience, this is the perfect role for you.
Due to thebusiness criticalnature of this role, there may be times whereafter-hourssupport is needed to addresscybersecurityincidents.Evinovacybersecurity is a globally distributed team with team memberslocatedin both the United States and Spain.
Key Responsibilities:
SIEM Platform Management (Splunk Focus)
Oversee the work of our outsourcedserviceprovider whoprovidesSIEM maintenancesupport
Provide architectural and operational ownership of Splunk ES as the enterprise detection platform
Design data ingestion strategies covering cloud telemetry, identities, SaaS services, and system audit logs
Engineer compliant data models to normalize security telemetry and enable scalable detection use case development
Build operational dashboards supporting SOC monitoring, incident tracking, regulatory reporting, and executive cyber risk metrics
Optimizesearch performance, indexing strategies, and storageutilizationto balance detection depth with cost efficiency
Integrate third-party and native security tooling into Splunk via APIs, forwarders, and data pipeline engineering
Cloud Detection and Response Architectures (AWS-focused)
Provide cyber defense telemetry requirements into security architecture reviews for new platforms, applications, and cloud services
Engineer and operationalize detectionsleveragingnative AWS telemetry sources such as Cloud Trail, Guard Duty, Security Lake, VPC Flow Logs, Cloud Watch, EKS Logs, and others
Develop detection use cases for IAM privilege escalation, federated identity abuse, cross-account compromise, API misuse, and serverless exploitation
Monitor containerized and Kubernetes workloads for runtime threats, suspicious process execution, and anomalous network communication patterns
Partner with Cloud Security peersto define cloud logging standards, retention requirements, and forensic readiness controls
Detection EngineeringandThreat Analytics
Architect, engineer, and operationalize advanced threat detections within Splunk Enterprise Security, including correlation searches, risk-based alerting frameworks, behavioral detections, and anomalysignals aligned to cloud computing threat scenarios
Design detection logic mapped to the MITRE ATT&CK techniques, cloud threatkillchains, and identity compromise attack paths to ensurecomprehensive adversary coverage
Build security telemetry correlation across cloud control planes, SaaS platforms, and identity providers such as MicrosoftEntraIDto detect multi-stage intrusion attempts
Collaborate with our outsourcedSOCto continuously tunelog sources/ detection contentto reduce false positives,eliminatealert fatigue, and improve “signal-to-noise” ratios within theSOCescalation pipelines
Utilize threat intelligence feeds to translate emerging adversary Tactics, Techniques, and Procedures (TTPs) into actionable detection use cases and SIEM content updates
Establish detection lifecycle governance including use case design documentation, testing validation, and performance monitoring
Develop “detection-as-code” pipelinesleveragingversion control and CI/CD processes to ensure repeatable and auditable deployment of correlation logic
Threat Detection, Analysis, and Response
Serve as the Tier 2 / Tier 3 escalationpathfor allrelevant securityalerts and suspicious activity escalated by our SOC
Conduct deep technical investigations spanning SIEM telemetry,adjacent platforms, cloud logs, identity activity, audit trails, and other forensic artifacts
Performthreat actor behavior analysis todetermineinitial access vectors, persistence mechanisms, privilege escalation paths, and lateral movement patterns
Lead threat hunting initiativesleveraginghypothesis-driven and intelligence-driven methodologiesto proactivelyidentifyhidden threats
Function as a Technical Lead / Incident Responder for confirmed cybersecurity incidentsand directing containment actions that are proportionate withtheincidentseverity
Coordinate cross-functional response activities across Product Engineering / Platform Operationsand Cybersecurity stakeholders
Maintain the Cybersecurity Incident Response Playbooks and developing new playbooks for emerging incident types / technologies
Produce formal investigation reports documenting incident timelines,impactedassets, regulatory exposure risk, and remediation recommendations
Provide incident briefings summarizing incident severity, business impact, and containment postureto the Head of Cybersecurity, Head of Cybersecurity Engineering, and other relevant leadership stakeholders (including theEvinovaChief Technology Officer)
Collaborate with Cybersecurity Assurance to document incident root causes, specifically focusing oncontrol failures, detection gaps, andpostureimprovement actions
Lead cyber crisis simulations and tabletop exercises with adjacent teams in Product Engineering and Platform Operations to ensure operational readiness
HIGHLIGHT THE SKILLS AND CAPABILITIES NEEDED
Minimum Qualifications:
Universitydegree in Cybersecurity,Information Security, Computer Science,Information Systems,ora relatedtechnical discipline.
6-8+ years of progressive experience in Cybersecurity Operations, Detection Engineering, Cybersecurity Incident Response, or Threat Intelligence functions within global enterprises
Demonstrated hands-on engineering and operational experience administering and developing detection use cases in Splunk Enterprise Security, including correlation searchers, notable event frameworks, risk-based alerting, and data modelutilization
Hands on security monitoring and threat detection experience across Amazon Web Services (AWS) environments
Operational familiarity with cloud native attack vectorsincluding IAM privilege escalation, credential misuse, token compromise, API abuse, and cross-account persistence mechanisms
Familiarity with SOAR platforms and automation engineering supporting incident response orchestration and alert enrichment
Demonstrated experience leading or coordinating incident response activities, including containment execution, stakeholder coordination, forensic triage, and post-incident lessons learned
Proficiencyin SIEM query languages (e.g., SPL, KQL) and log analysis methodologies across various log sources
Working knowledge of the MITRE ATT&CK frameworkand its application to detection engineering and threat actor simulation
Desired Qualifications:
Professional certifications in Cybersecurity, Digital Forensics, InformationAssuranceor related technical field (e.g.,CISSP, CCSP, Splunk Certified,GIAC)
Proven experienceoperatingas an escalation path within a Security Operations or Incident Response function, including leading technical investigations over advanced threats, account compromise, malware intrusions, and cloud security incidents
Experienceoperatingwithin hybrid SOC delivery models that include managed service providers or outsourced Tier 1 monitoring functions
Deep engineeringexpertisewithin Splunk Enterprise Security, including detection-as-code pipelines, SIEM optimization, data onboarding, and search performance tuning
Experience conducting proactive threat hunting operations
Experience presenting incident findings and detection maturity metrics to security leadership, auditors, and other interested stakeholders
Experience working within regulated environments such as Financial Services, Life Sciences / Pharmaceutical,and Healthcare
While notrequired, having priorexperiencewith the Microsoftsecurity ecosystem isan added plus(e.g., Purview, Sentinel, Defender)
Date Posted
16-feb-2026Closing Date
09-mar-2026AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We comply with all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.
Reasons to Join
Thomas Mathisen
There are many things I enjoy when working at AstraZeneca, mainly the Speak up culture, the great colleagues that are in my teams, the great products that AstraZeneca provides to our patients and the challenging conversations I have around our medicines.
Christine Recchio
Working at AstraZeneca has impacted my life in such a positive way. I now have an improved work-life balance through creating my own schedule and time management, I feel a balance that I didn’t have before.
Stephanie Ling
There are a lot of reasons why I enjoy working in AstraZeneca, my colleagues being one of them. My team members and the managers have provided a great deal of guidance in helping me to be more confident in my daily work.
What we offer
We're driven by our shared values of serving people, society and the planet. Our people make this possible, which is why we prioritise diversity, inclusivity, balance and sustainability. Discover what a career at AstraZeneca could mean for you.
An award-winning company
We're passionate about being a great place to work, and 84% of our employees would recommend us as an employer. We've been recognised as a Top Employer in Spain, an EFR Family Responsible Business, and we achieved third place in Forbes Spain's Top 50 Best Places to Work list.
Inclusive environment
Diversity and inclusion are embedded in everything we do, and our different views, experiences and strengths enrich our culture. There's no salary gap at AstraZeneca, and the number of female employees has increased by four per cent over the last three years. We've also made all positions fully accessible.
Work-life balance
Your wellbeing means a lot to us, and we're here to support you through all of life's ups and downs. That's why we offer an unpaid leave policy, annual leave, reduced-hours timetables and a host of benefits, including a retirement plan, long service award, and health and travel insurance.
Sustainability initiatives
We're committed to harnessing the power of science to become a more sustainable business. We've reduced our carbon footprint by over 9,000 kg of CO2 over the last two years, and we lead the European GoGreen Project, which aims to introduce environmentally friendly options in our fleet of corporate vehicles.
Join our Talent Network
Be the first to receive job updates and news from AstraZeneca
Sign up