Operations Security Engineer

Posted 4 days ago

This is a fully remote position, open to applicants in France, +2 more countries.

📋 Description

• Serve as the primary point of contact for alert triage, incident identification, and security event investigation across EPI environments.

• Implement incident response activities utilizing structured frameworks such as SANS PICERL.

• Conduct proactive, hypothesis-driven threat hunts based on attacker behavior, emerging threats, threat intelligence, and MITRE ATT&CK techniques.

• Analyze and correlate logs from authentication, application, system, endpoint, and cloud telemetry sources, including AWS and Azure.

• Design, refine, and maintain detection rules, use cases, dashboards, custom alerts, and automation workflows.

• Contribute to the creation and ongoing enhancement of SOC playbooks, runbooks, SIEM, and EDR integrations.

• Document and convey threat findings, incident outcomes, and remediation recommendations.

• Work collaboratively with Security, Engineering, DevOps, IT, and Operations teams to enhance detection coverage, response readiness, and operational resilience.

• Assist in incident response and operational continuity by participating in a 24/7 on-call rotation.


⛳️ Requirements

• Over 5 years of experience in cybersecurity, with extensive hands-on experience as a SOC analyst, incident responder, detection engineer, or a similar role.

• Proficient in English (CEFR C1 or C2); knowledge of French, German, Dutch, or other European languages is an advantage.

• Ability to excel in a remote-first, multicultural, and fast-paced environment.

• Strong familiarity with the complete SOC lifecycle, from Tier 1 to Tier 3, encompassing alert triage, incident response, threat hunting, and threat intelligence.

• Proven experience in threat hunting, detection engineering, or threat intelligence.

• Solid understanding of SIEM and EDR technologies, log parsing, detection engineering, and alert tuning.

• Practical experience with Python, PowerShell, or KQL.

• Capability to analyze and correlate logs from authentication, application, system, and cloud telemetry across AWS and Azure.

• Knowledge of attacker TTPs, MITRE ATT&CK, threat exposure, and attack path analysis.

• Experience in creating or enhancing incident response playbooks, runbooks, and automation workflows.

• Strong communication skills to articulate technical findings and security risks to both technical and non-technical stakeholders.

• Willingness to participate in a 24/7 on-call rotation, approximately one week per month.

• Nice-to-have: Experience with Rapid7 and TaHiTI.

• Nice-to-have: Familiarity with Microsoft Entra ID and its integration into detection and response workflows.

• Nice-to-have certifications: GSEC, GCIH, BTL1/2, SC-200, or AZ-500.

• Nice-to-have: Experience in payments, banking, fintech, or another highly regulated environment.


🏝️ Benefits

• Remote-first culture with quarterly and annual all-staff in-person meetups to foster connection and collaboration among teams.

• Opportunity to work from another EU country for up to 3 months each year.

• Competitive compensation package including performance-based bonuses and a thoughtfully crafted, high-quality benefits program.

• Learning & development budget: €5,000 training budget per year.

• Inclusive work environment with equal employment opportunities.

People also viewed

Talan1 day ago

Security Operations Analyst – SIEM Operations, Threat Detection

CZ flagCzechia OnlyFull-timeSecurity Operations
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – SIEM, Threat Detection

ES flagSpain OnlyFreelanceSecurity Operations
ApplyView job
Supply Chimp1 day ago

SOC Analyst Level 2

PH flagPhilippines OnlyFull-timeSecurity OperationsPHP 65k – PHP 80k/month
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense Operations

ES flagSpain, +5 more countriesFull-timeSecurity Operations
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense

IN flagIndia, +4 more countriesFull-timeSecurity Operations
ApplyView job
Talan1 day ago

Security Operations Analyst – SIEM Operations, Threat Detection

PL flagPoland OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers