> Markdown version of [/jobs/ext/3007712-security-operations-engineer-senior-staff-soc-run-build-h-f](https://www.wearedevelopers.com/jobs/ext/3007712-security-operations-engineer-senior-staff-soc-run-build-h-f). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Engineer Senior+ - Staff - Soc Run & Build H/F - **Company:** Anderson Rh - **Location:** Paris, France (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Bash Shell, Software as a Service, Cloud Computing Security, Cyber Security, Continuous Integration, Noise Reduction, Github, Identity and Access Management, Python (Programming Language), Open Source Intelligence, Security Information and Event Management, Git, Kubernetes, Splunk - **Published:** September 20, 2026 - **Apply:** https://www.hellowork.com/fr-fr/emplois/83566419.html ## About the Role Profil recherché8 à 10 ans d'expérience minimum en SecOps / SOC / incident response / CSIRTHistorique de construction et d'amélioration de capacités SOC (détections, dashboards, runbooks) et d'investigations menées en autonomieAutonomie totale sur des investigations complexes, y compris sous pressionSIEM : Splunk (SPL avancé, data models, CIM) - investigation et détectionEDR : CrowdStrikeCloud : AWS security (IAM, CloudTrail, GuardDuty, réseau, workloads, containers, EKS/Kubernetes) ; CSPM/CNAPP, Wiz idéalementAutomatisation : Python, Bash, API, GitHub Actions, SOAR (Torq idéalement)Infra : cloud / réseau / containers / CI/CD, pipelines de logs et intégrationsIA appliquée à la sécurité : intérêt fort ou expérience des workflows agentiquesSoft skills : rigueur, discipline de process, documentation claire, escalade au bon niveau de contexte, confidentialité, pédagogieAnglais professionnel (environnement international)10 à 12 ans minimum d'expérience en exécution autonome du RUN et du BUILD, référent techniquePour le niveau Staff : influence sur l'architecture (pipeline de détection, SIEM, SOC agentique), définition de standards/playbooks et mentoring, 1. 8 à 10 ans d'expérience minimum en SecOps / SOC / incident response / CSIRT 2. Historique de construction et d'amélioration de capacités SOC (détections, dashboards, runbooks) et d'investigations menées en autonomie 3. Autonomie totale sur des investigations complexes, y compris sous pression 4. SIEM : Splunk (SPL avancé, data models, CIM) - investigation et détection 5. EDR : CrowdStrike 6. Cloud : AWS security (IAM, CloudTrail, GuardDuty, réseau, workloads, containers, EKS/Kubernetes) ; CSPM/CNAPP, Wiz idéalement 7. Automatisation : Python, Bash, API, GitHub Actions, SOAR (Torq idéalement) 8. Infra : cloud / réseau / containers / CI/CD, pipelines de logs et intégrations 9. IA appliquée à la sécurité : intérêt fort ou expérience des workflows agentiques 10. Soft skills : rigueur, discipline de process, documentation claire, escalade au bon niveau de contexte, confidentialité, pédagogie 11. Anglais professionnel (environnement international) 12. 10 à 12 ans minimum d'expérience en exécution autonome du RUN et du BUILD, référent technique 13. Pour le niveau Staff : influence sur l'architecture (pipeline de détection, SIEM, SOC agentique), définition de standards/playbooks et mentoring EUR Bash Anglais API AWS Git Normalisation Kubernetes Python Autonomie ## Description L'équipe Security Operations protège les environnements corporate, cloud, SaaS et datacenter : anticipation, détection, investigation et réponse aux menaces sur les endpoints, workloads, identités et l'infrastructure. Équipe réduite, senior et exigeante, qui construit en continu son propre SOC : intégration de sources de logs, qualité de la donnée, couverture de détection, dashboards, workflows et un SOC agentique développé en interne. Stack : Splunk (SIEM) · CrowdStrike (EDR) · Wiz (CSPM/CNAPP) · Torq (SOAR) · AWS (dont EKS/Kubernetes) · SOC agentique interne, Renforcer immédiatement la capacité opérationnelle en absorbant le RUN du SOC, tout en contribuant au BUILD dès que la charge le permet. Cible indicative : ~60 % RUN / ~40 % BUILD. - Opérer le SOC (priorité) : - Triage, classification et priorisation des alertes (Splunk, CrowdStrike, Wiz, AWS) - Investigations de bout en bout : endpoints, cloud, identités, SaaS, workloads, infra - collecte de preuves, timeline, root cause - Pilotage de la réponse à incident : containment, remediation, post-mortems - Point d'escalade pour les analystes juniors (revue d'analyses, partage de connaissance) - Exploitation du SOC agentique pour absorber le volume de signaux faibles - Documentation rigoureuse de chaque investigation - Faire progresser le SOC : - Detection engineering : conception et optimisation de recherches Splunk (SPL), nouveaux use cases (AWS/IAM, EKS/K8s, workloads), réduction du bruit - Qualité de la donnée & pipeline : intégration de sources de logs, parsing, normalisation (CIM), data models, performance - Automatisation : workflows Torq/SOAR, scripts et intégrations API (Python, Bash, GitHub Actions) - SOC agentique : contribution à son évolution (workflows d'investigation, corrélation, enrichissement) - Reporting & dashboards, cloud security (Wiz, AWS/EKS), threat hunting (CTI/OSINT), capitalisation (runbooks, playbooks, standards) ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Best Companies to Work For in Paris: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/190-best-companies-to-work-for-in-paris-top-25-companies-in-2023) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)