
Operations Security Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in France, +2 more countries.
• Serve as the primary point of contact for alert triage, incident identification, and security event investigation across EPI environments.
• Implement incident response activities utilizing structured frameworks such as SANS PICERL.
• Conduct proactive, hypothesis-driven threat hunts based on attacker behavior, emerging threats, threat intelligence, and MITRE ATT&CK techniques.
• Analyze and correlate logs from authentication, application, system, endpoint, and cloud telemetry sources, including AWS and Azure.
• Design, refine, and maintain detection rules, use cases, dashboards, custom alerts, and automation workflows.
• Contribute to the creation and ongoing enhancement of SOC playbooks, runbooks, SIEM, and EDR integrations.
• Document and convey threat findings, incident outcomes, and remediation recommendations.
• Work collaboratively with Security, Engineering, DevOps, IT, and Operations teams to enhance detection coverage, response readiness, and operational resilience.
• Assist in incident response and operational continuity by participating in a 24/7 on-call rotation.
• Over 5 years of experience in cybersecurity, with extensive hands-on experience as a SOC analyst, incident responder, detection engineer, or a similar role.
• Proficient in English (CEFR C1 or C2); knowledge of French, German, Dutch, or other European languages is an advantage.
• Ability to excel in a remote-first, multicultural, and fast-paced environment.
• Strong familiarity with the complete SOC lifecycle, from Tier 1 to Tier 3, encompassing alert triage, incident response, threat hunting, and threat intelligence.
• Proven experience in threat hunting, detection engineering, or threat intelligence.
• Solid understanding of SIEM and EDR technologies, log parsing, detection engineering, and alert tuning.
• Practical experience with Python, PowerShell, or KQL.
• Capability to analyze and correlate logs from authentication, application, system, and cloud telemetry across AWS and Azure.
• Knowledge of attacker TTPs, MITRE ATT&CK, threat exposure, and attack path analysis.
• Experience in creating or enhancing incident response playbooks, runbooks, and automation workflows.
• Strong communication skills to articulate technical findings and security risks to both technical and non-technical stakeholders.
• Willingness to participate in a 24/7 on-call rotation, approximately one week per month.
• Nice-to-have: Experience with Rapid7 and TaHiTI.
• Nice-to-have: Familiarity with Microsoft Entra ID and its integration into detection and response workflows.
• Nice-to-have certifications: GSEC, GCIH, BTL1/2, SC-200, or AZ-500.
• Nice-to-have: Experience in payments, banking, fintech, or another highly regulated environment.
• Remote-first culture with quarterly and annual all-staff in-person meetups to foster connection and collaboration among teams.
• Opportunity to work from another EU country for up to 3 months each year.
• Competitive compensation package including performance-based bonuses and a thoughtfully crafted, high-quality benefits program.
• Learning & development budget: €5,000 training budget per year.
• Inclusive work environment with equal employment opportunities.
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.