Security Operations Engineer Senior+ - Staff - Soc Run & Build H/F

Anderson Rh
Paris, France
1 day ago
Apply on www.hellowork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Bash Shell Software as a Service Cloud Computing Security Cyber Security Continuous Integration Noise Reduction Github Identity and Access Management Python (Programming Language) Open Source Intelligence
+4 more
Security Information and Event Management Git Kubernetes Splunk

Job description

L’équipe Security Operations protège les environnements corporate, cloud, SaaS et datacenter : anticipation, détection, investigation et réponse aux menaces sur les endpoints, workloads, identités et l’infrastructure. Équipe réduite, senior et exigeante, qui construit en continu son propre SOC : intégration de sources de logs, qualité de la donnée, couverture de détection, dashboards, workflows et un SOC agentique développé en interne.

Stack : Splunk (SIEM) · CrowdStrike (EDR) · Wiz (CSPM/CNAPP) · Torq (SOAR) · AWS (dont EKS/Kubernetes) · SOC agentique interne, Renforcer immédiatement la capacité opérationnelle en absorbant le RUN du SOC, tout en contribuant au BUILD dès que la charge le permet. Cible indicative : ~60 % RUN / ~40 % BUILD.

  • Opérer le SOC (priorité) :
  • Triage, classification et priorisation des alertes (Splunk, CrowdStrike, Wiz, AWS)
  • Investigations de bout en bout : endpoints, cloud, identités, SaaS, workloads, infra - collecte de preuves, timeline, root cause
  • Pilotage de la réponse à incident : containment, remediation, post-mortems
  • Point d’escalade pour les analystes juniors (revue d’analyses, partage de connaissance)
  • Exploitation du SOC agentique pour absorber le volume de signaux faibles
  • Documentation rigoureuse de chaque investigation
  • Faire progresser le SOC :
  • Detection engineering : conception et optimisation de recherches Splunk (SPL), nouveaux use cases (AWS/IAM, EKS/K8s, workloads), réduction du bruit
  • Qualité de la donnée & pipeline : intégration de sources de logs, parsing, normalisation (CIM), data models, performance
  • Automatisation : workflows Torq/SOAR, scripts et intégrations API (Python, Bash, GitHub Actions)
  • SOC agentique : contribution à son évolution (workflows d’investigation, corrélation, enrichissement)
  • Reporting & dashboards, cloud security (Wiz, AWS/EKS), threat hunting (CTI/OSINT), capitalisation (runbooks, playbooks, standards)

Requirements

Profil recherché8 à 10 ans d’expérience minimum en SecOps / SOC / incident response / CSIRTHistorique de construction et d’amélioration de capacités SOC (détections, dashboards, runbooks) et d’investigations menées en autonomieAutonomie totale sur des investigations complexes, y compris sous pressionSIEM : Splunk (SPL avancé, data models, CIM) - investigation et détectionEDR : CrowdStrikeCloud : AWS security (IAM, CloudTrail, GuardDuty, réseau, workloads, containers, EKS/Kubernetes) ; CSPM/CNAPP, Wiz idéalementAutomatisation : Python, Bash, API, GitHub Actions, SOAR (Torq idéalement)Infra : cloud / réseau / containers / CI/CD, pipelines de logs et intégrationsIA appliquée à la sécurité : intérêt fort ou expérience des workflows agentiquesSoft skills : rigueur, discipline de process, documentation claire, escalade au bon niveau de contexte, confidentialité, pédagogieAnglais professionnel (environnement international)10 à 12 ans minimum d’expérience en exécution autonome du RUN et du BUILD, référent techniquePour le niveau Staff : influence sur l’architecture (pipeline de détection, SIEM, SOC agentique), définition de standards/playbooks et mentoring, 1. 8 à 10 ans d’expérience minimum en SecOps / SOC / incident response / CSIRT

  1. Historique de construction et d’amélioration de capacités SOC (détections, dashboards, runbooks) et d’investigations menées en autonomie
  2. Autonomie totale sur des investigations complexes, y compris sous pression
  3. SIEM : Splunk (SPL avancé, data models, CIM) - investigation et détection
  4. EDR : CrowdStrike
  5. Cloud : AWS security (IAM, CloudTrail, GuardDuty, réseau, workloads, containers, EKS/Kubernetes) ; CSPM/CNAPP, Wiz idéalement
  6. Automatisation : Python, Bash, API, GitHub Actions, SOAR (Torq idéalement)
  7. Infra : cloud / réseau / containers / CI/CD, pipelines de logs et intégrations
  8. IA appliquée à la sécurité : intérêt fort ou expérience des workflows agentiques
  9. Soft skills : rigueur, discipline de process, documentation claire, escalade au bon niveau de contexte, confidentialité, pédagogie
  10. Anglais professionnel (environnement international)
  11. 10 à 12 ans minimum d’expérience en exécution autonome du RUN et du BUILD, référent technique
  12. Pour le niveau Staff : influence sur l’architecture (pipeline de détection, SIEM, SOC agentique), définition de standards/playbooks et mentoring

EUR

Bash Anglais API AWS Git Normalisation Kubernetes Python Autonomie

Benefits & conditions

Lieu de la mission : Paris

  • Démarrage ASAP
  • 2 jours de télétravail
  • Anglais professionnel obligatoire
  • Séniorité requise : 8 à 10 ans d’expérience minimum

About the company

Pour un acteur international de la tech évoluant dans un environnement à forte exigence de sécurité, nous recherchons un Security Operations Engineer expérimenté.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.hellowork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all