Security Operations Engineer

Posted 1 day ago

This is a fully remote position, open to applicants in France, +2 more countries.

πŸ“‹ Description

β€’ Serve as the primary contact for alert triage, incident identification, and security event investigation within EPI environments.

β€’ Carry out incident response activities utilizing structured frameworks such as SANS PICERL.

β€’ Perform proactive, hypothesis-driven threat hunting based on attacker behavior, emerging threats, threat intelligence, and MITRE ATT&CK techniques.

β€’ Analyze and correlate logs from authentication, application, system, endpoint, and cloud telemetry sources, including AWS and Azure.

β€’ Develop, fine-tune, and maintain detection rules, use cases, dashboards, custom alerts, and automation workflows.

β€’ Contribute to SOC playbooks, runbooks, and integrations with SIEM and EDR systems.

β€’ Document and convey threat findings, incident outcomes, and remediation suggestions.

β€’ Work collaboratively with engineering, SOC, IR, and IT teams to enhance detection coverage, response preparedness, and operational resilience.


⛳️ Requirements

β€’ Over 5 years of experience in cybersecurity, with substantial hands-on experience as a SOC analyst, incident responder, detection engineer, or in a similar position.

β€’ Proficient in English (CEFR C1 or C2); knowledge of French, German, Dutch, or other European languages is advantageous.

β€’ Strong understanding of the complete SOC lifecycle, from Tier 1 to Tier 3, including alert triage, incident response, threat hunting, and threat intelligence.

β€’ Proven expertise in threat hunting, detection engineering, or threat intelligence.

β€’ Solid grasp of SIEM and EDR technologies, log parsing, detection engineering, and alert tuning.

β€’ Practical experience with Python, PowerShell, or KQL.

β€’ Ability to analyze and correlate logs from authentication, application, system, and cloud telemetry across AWS and Azure.

β€’ Knowledge of attacker TTPs, MITRE ATT&CK, threat exposure, and attack path analysis.

β€’ Experience in creating or enhancing incident response playbooks, runbooks, and automation workflows.

β€’ Strong communication skills when interacting with both technical and non-technical stakeholders.

β€’ Willingness to participate in a 24/7 on-call rotation, approximately one week per month.

β€’ Experience with Rapid7 and TaHiTI is a bonus.

β€’ Familiarity with Microsoft Entra ID is a bonus.

β€’ GSEC, GCIH, BTL1/2, SC-200, or AZ-500 certifications are advantageous.

β€’ Experience in payments, banking, fintech, or another highly regulated industry is a bonus.


🏝️ Benefits

β€’ Remote-first culture with quarterly and annual in-person meetups for all staff.

β€’ Opportunity to work from another EU country for up to 3 months each year.

β€’ Competitive compensation package, including salary and performance-based bonuses.

β€’ Comprehensive benefits program.

β€’ Learning & development budget: €5,000 training budget annually.

People also viewed

Palo Alto Networks18 hours ago

Senior MSIAM SOC Engineer – Unit 42

US flagNorth Carolina OnlyFull-timeSecurity Operations$134.6k – $217.8k/year
ApplyView job
Pantheon Platform19 hours ago

Staff Security Engineer – Security Operations

IE flagIreland OnlyFull-timeSecurity Operations
ApplyView job
Convergint21 hours ago

Security Operations Center Architect

US flagUnited States OnlyFull-timeSecurity Operations$98k – $140k/year
ApplyView job
Conduent22 hours ago

Cyber Security Operations Engineer

US flagUnited States OnlyFull-timeSecurity Operations$76.1k – $98.8k/year
ApplyView job
Tokio Marine HCC22 hours ago

Security Operations Engineer

US flagUnited States OnlyFull-timeSecurity Operations$104.3k – $157.9k/year
ApplyView job
SANS Institute1 day ago

Senior SOC Engineer

US flagMaryland OnlyFull-timeSecurity Operations$155k – $205k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers