Agrovacante
Back to the list

BASF

Principal Analyst Cyber Security Defense Center (m/f/d)

Job location

Madrid, ES

Job description

ABOUT US

At BASF Digital Hub Madrid we develop innovative digital solutions for BASF, create new exciting customer experiences and business growth, and drive efficiencies in processes, helping to strengthen BASF´s position as the digital leader in the chemical industry.

We believe the right path is through creativity, trial and error and great people working and learning together. Become part of our team and develop the future with us - in a global team that embraces diversity and equal opportunities. We are committed to fostering an inclusive workplace and strongly encourage applications from individuals with disabilities. We value diversity and believe that varied perspectives enhance our team's effectiveness. Our hiring practices are designed to ensure equal opportunity for all candidates. 

As Principal Analyst, you are the most senior technical authority within the CSDC - a recognized subject matter expert who leads from expertise, not hierarchy. You shape the strategic direction of our detection and response capabilities, act as the technical bridge to adjacent security functions, and represent the CSDC in internal governance bodies and external communities.

RESPOSIBILITIES

  • Lead the technical response to our most complex and high-risk security incidents as Case Lead - from triage and analysis through containment, eradication, resolution, and closure
  • Lead investigations and compromise assessments
  • Analyze complex malicious artifacts (binaries, scripts, documents) through static and dynamic analysis and reverse engineering to determine their underlying, often obfuscated, functionality
  • Drive our hypothesis-driven threat hunting program: design hunting campaigns, validate hypotheses against threat intelligence, and convert findings into durable detection coverage
  • Design, review, and continuously improve detection logic, correlation rules, and SOAR playbooks on our Elastic Security platform, applying Detection-as-Code practices
  • Shape the CSDC automation and AI roadmap: co-design AI-assisted triage and investigation workflows and supervise their operation with clear human-in-the-loop safeguards
  • Define the strategic roadmap for detection and response capabilities together with CSDC leadership; evaluate and recommend new technologies, tools, and methodologies
  • Act as technical advisor to CSDC leadership on capability development, and as senior escalation point and on-call resource for critical incidents
  • Mentor and train Tier 2 and Tier 3 analysts; develop advanced training content and drive knowledge transfer across the team
  • Lead cross-functional initiatives with adjacent teams (Cyber Threat Intelligence, Offensive Security, Vulnerability Management, Platform Engineering) and steer external service providers to meet BASF security requirements
  • Represent the CSDC in internal security governance bodies and in external communities and trusted networks (e.g., BSI, Deutscher CERT-Verbund, CSSA, FIRST)

 

 

QUALIFICATIONS

Education and Experience

  • Degree in computer science, IT security, or a comparable technical qualification
  • 8+ years of professional experience in cyber defense, incident response, with a track record as a recognized subject matter expert
  • Demonstrated experience leading technical teams and investigations under pressure in high-stakes situations

Technical Expertise

  • Expert-level knowledge of the internals of mainstream operating systems (Microsoft Windows, Linux) and of network protocols and traffic analysis
  • Deep understanding of current attacker tradecraft: advanced persistent threats, actors, infrastructures, and TTPs, structured along MITRE ATT&CK
  • Strong hands-on expertise with Elastic Security as SIEM and EDR: detection rule development and tuning, investigation and hunting; experience with Elastic automation capabilities (workflows, AI Assistant) and ES|QL is a strong plus
  • Proficiency with modern DFIR tooling (e.g., OSQuery, Velociraptor, Volatility, Suricata, Wireshark) and with malware analysis and reverse engineering tools (e.g., Ghidra, IDA Pro, x64dbg, WinDbg)
  • Solid experience in cloud and identity threat detection and response (Microsoft Entra ID / Active Directory, Azure, AWS)
  • Ability to program in Python and ideally Go; confident scripting in common shells (Bash, PowerShell); ability to read C and x86/x64 assembly in the context of reverse engineering
  • Working understanding of AI/ML applications in security operations (model-assisted triage, LLM-assisted investigation, explainability) is a plus

Leadership and Communication

  • Proven ability to lead technical experts through stressful situations and to remain a calm, structured decision-maker during critical incidents
  • Strong mentoring and coaching mindset; genuine motivation to grow the analysts around you
  • Confident communication in English, both spoken and written, up to executive level; German language skills are a plus
  • Excellent organizational and time management skills; willingness to participate in an on-call rotation

Certifications

Relevant certifications are valued as supporting evidence of your expertise - none of them is a strict requirement. We particularly welcome:

  • GIAC / SANS: GCIH, GCFA, GNFA, GREM, GCTI, GDAT, or GCDA; the GIAC Security Expert (GSE) designation is a distinguishing qualification at this level
  • Elastic: Elastic Certified Analyst or Elastic Certified Engineer
  • Cloud security: Microsoft SC-200 or AZ-500, AWS Certified Security - Specialty, or GIAC GCLD
  • Offensive and intrusion analysis: OffSec OSCP or OSDA, or CREST Registered Intrusion Analyst (CRIA)

BENEFITS

  • A secure work environment because your health, safety and wellbeing is always our top priority.
  • Flexible work schedule and Home-office options, so that you can balance your working life and private life.
  • Learning and development opportunities
  • 25 holiday days per year
  • 5 additional days (readjustment)
  • A collaborative, trustful and innovative work environment
  • Being part of an international team and work in global projects
  • Relocation assistance to Madrid provided

At BASF, the chemistry is right

Because we are counting on innovative solutions, on sustainable actions, and on connected thinking and on you. Become a part of our formula for success and develop the future with us - in a global team that embraces diversity and equal opportunities irrespective of gender, age, origin, sexual orientation, disability or belief.

At BASF, we are committed to upholding and ensuring compliance with company standards related to quality, environment, health, safety, and energy, in line with our global guidelines.

We actively promote a culture of prevention and continuous improvement, encouraging collaboration in initiatives related to quality, environmental protection, health, safety, and energy performance.

We foster responsible energy use, promoting efficiency in daily operations and supporting the identification of improvement projects and energy-saving opportunities.

 

HOW TO REACH US

If you're interested in the position or know someone who might be and need support on how to take next steps, please send an email to felipe.bianco@partners.basf.com