
Security Operations Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in France, +2 more countries.
β’ Serve as the primary contact for alert triage, incident identification, and security event investigation within EPI environments.
β’ Carry out incident response activities utilizing structured frameworks such as SANS PICERL.
β’ Perform proactive, hypothesis-driven threat hunting based on attacker behavior, emerging threats, threat intelligence, and MITRE ATT&CK techniques.
β’ Analyze and correlate logs from authentication, application, system, endpoint, and cloud telemetry sources, including AWS and Azure.
β’ Develop, fine-tune, and maintain detection rules, use cases, dashboards, custom alerts, and automation workflows.
β’ Contribute to SOC playbooks, runbooks, and integrations with SIEM and EDR systems.
β’ Document and convey threat findings, incident outcomes, and remediation suggestions.
β’ Work collaboratively with engineering, SOC, IR, and IT teams to enhance detection coverage, response preparedness, and operational resilience.
β’ Over 5 years of experience in cybersecurity, with substantial hands-on experience as a SOC analyst, incident responder, detection engineer, or in a similar position.
β’ Proficient in English (CEFR C1 or C2); knowledge of French, German, Dutch, or other European languages is advantageous.
β’ Strong understanding of the complete SOC lifecycle, from Tier 1 to Tier 3, including alert triage, incident response, threat hunting, and threat intelligence.
β’ Proven expertise in threat hunting, detection engineering, or threat intelligence.
β’ Solid grasp of SIEM and EDR technologies, log parsing, detection engineering, and alert tuning.
β’ Practical experience with Python, PowerShell, or KQL.
β’ Ability to analyze and correlate logs from authentication, application, system, and cloud telemetry across AWS and Azure.
β’ Knowledge of attacker TTPs, MITRE ATT&CK, threat exposure, and attack path analysis.
β’ Experience in creating or enhancing incident response playbooks, runbooks, and automation workflows.
β’ Strong communication skills when interacting with both technical and non-technical stakeholders.
β’ Willingness to participate in a 24/7 on-call rotation, approximately one week per month.
β’ Experience with Rapid7 and TaHiTI is a bonus.
β’ Familiarity with Microsoft Entra ID is a bonus.
β’ GSEC, GCIH, BTL1/2, SC-200, or AZ-500 certifications are advantageous.
β’ Experience in payments, banking, fintech, or another highly regulated industry is a bonus.
β’ Remote-first culture with quarterly and annual in-person meetups for all staff.
β’ Opportunity to work from another EU country for up to 3 months each year.
β’ Competitive compensation package, including salary and performance-based bonuses.
β’ Comprehensive benefits program.
β’ Learning & development budget: β¬5,000 training budget annually.
Palo Alto Networks
Pantheon Platform
Convergint
Conduent
Get handpicked remote jobs straight to your inbox weekly.