Managed cybersecurity and OT defense for critical infrastructure across 35+ countries
S2GRUPO operates a security-first organization with 20+ years defending critical infrastructure and OT environments across Europe and beyond. The stack reveals a mature SOC platform built on open-source foundations (Elasticsearch, Graylog, OpenCTI, MISP) integrated with enterprise detection tools (CrowdStrike, SentinelOne) and custom offensive tooling — a signal they're moving from pure managed services toward proprietary analytics and AI-driven threat response. Hiring is heavily skewed toward security specialists (28 of 52 roles), with active projects in SOC automation, generative AI for threat hunting, and purple-team validation, indicating an engineering-driven shift in their service delivery model.
S2GRUPO is a European cybersecurity firm headquartered in Valencia, Spain, with 501–1,000 employees operating across 35+ countries. They deliver managed security services, OT/IT integrated defense, and incident response to public and private organizations in critical sectors. The product surface spans early detection, incident response, recovery, and continuous improvement across both traditional IT infrastructure and operational technology environments. Current hiring activity centers on security roles (mostly mid- to senior-level practitioners), with emerging investments in data science, product, and go-to-market functions. They maintain offices in Spain and Colombia.
Core SIEM and detection: Elasticsearch, Graylog, CrowdStrike, SentinelOne, OpenCTI, MISP. Infrastructure: Azure, Kubernetes, Docker, VMware, vCenter. Languages: Python, C, C++, Java. Defense frameworks: YARA, MITRE ATT&CK, Syslog, NXLog.
Active projects include SOC automation, offensive tooling frameworks, purple-team exercises, generative AI for threat hunting, OT/IT resilience, regulatory compliance, risk management, and sales enablement for product launches.
Other companies in the same industry, closest in size