Senior Security Operations Engineer
Job description
About the role
You will own the full lifecycle of security operations within a fast-moving, globally distributed SOC. You will investigate and respond to cyber threats across Ledger's corporate, cloud, SaaS, and data center environments with autonomy and precision. You will act as the technical owner for complex incidents, guiding investigations from detection through containment, remediation, and recovery. You will build and refine detection capabilities that keep pace with evolving infrastructure and threat techniques. You will mentor junior analysts by providing clear direction, code review, and knowledge transfer during incident handling. You will continuously challenge existing processes to uncover inefficiencies and drive measurable improvements in security posture. You will serve as a critical bridge between security engineering, cloud infrastructure, and product teams to close visibility and response gaps.
Key facts
What you'll do
Analyze, classify, and prioritize security alerts from Splunk, CrowdStrike, Wiz, AWS, and other sources, then conduct thorough investigations into incidents affecting endpoints, cloud environments, identities, SaaS platforms, workloads, and infrastructure.
Provide clear, actionable context and recommendations to inform incident response next steps, and act as the technical escalation point for less experienced analysts within the Security Operations team.
Leverage the in-house Agentic SOC to handle weak signals and enriched alert data, allowing you to concentrate on high-priority incidents that require human judgment and deep technical investigation.
Build, tune, and optimize cloud detection use cases for AWS, including IAM activity, EKS/Kubernetes, and container workloads, while using Wiz to track and prioritize cloud exposure as part of your detection responsibilities.
Integrate, maintain, and improve data quality for log sources spanning cloud, endpoints, identities, SaaS, infrastructure, and Kubernetes ecosystems to ensure completeness, accurate parsing, normalization, and usability.
Identify visibility blind spots across Ledger's environments and collaborate with IT, Cloud, Infrastructure, and Engineering teams to design and implement mitigations that reduce risk.
Design, write, and optimize Splunk queries, develop new detection use cases based on available logs, iteratively refine detection logic, and document technical approaches to reduce noise and improve signal quality.
Lead incident response activities from initial alert triage through containment, eradication, recovery, and post-incident review, ensuring thorough documentation and actionable learnings.
Expand and maintain detection coverage and visibility across SaaS, identities, workloads, and infrastructure while contributing to the reliability and scalability of the SOC's operational workflows.
Continuously contribute to the development and maturity of the internal Agentic SOC, including automation, correlation rules, investigation playbooks, and dashboards that support efficient and consistent incident handling.
Requirements
You must have a strong background in security operations, cloud security, and incident response with proven ability to work autonomously in a complex and evolving environment.
You must possess hands-on experience analyzing and investigating security incidents across endpoints, cloud infrastructure, identities, and SaaS platforms using tools such as Splunk, CrowdStrike, and cloud-native monitoring systems.
You must demonstrate expertise in cloud security, including AWS services, IAM activity monitoring, container workloads, and Kubernetes security, with the ability to translate operational findings into improved detection logic.
You must have advanced proficiency in writing and optimizing queries in Splunk, creating and tuning detection rules, and documenting technical approaches to ensure clarity and maintainability.
You must be comfortable working with log sources, data normalization, and schema management across diverse systems, including cloud, endpoints, identities, and infrastructure.
You must show a strong commitment to knowledge sharing and mentorship, actively supporting junior analysts through code review, technical guidance, and collaborative incident resolution.
You must have a proven track record of identifying visibility gaps and collaborating cross-functionally with infrastructure, cloud, and engineering teams to implement effective remediations.
You must be highly disciplined in root cause analysis, incident documentation, and post-incident improvement activities to drive measurable security outcomes over time.
Nice to have
Preferred candidates will have experience contributing to the development and maintenance of an internal Agentic SOC and automation frameworks.
Preferred candidates will have a background in designing and optimizing detection use cases for cloud environments, including AWS, IAM, EKS, and container workloads.
Preferred candidates will have hands-on experience with SOAR platforms or automation tools such as Torq, and a track record of building reliable operational workflows.
Practical notes
This role is based in Paris, France, and requires availability during standard business hours as defined by the company. Travel may be required between offices and to customer locations as needed. Candidates must be eligible to work in France and comply with local employment regulations. Visa sponsorship may be considered for exceptional candidates in accordance with current immigration laws and company policies. Applications will be reviewed on a rolling basis until the position is filled, and early submission is strongly encouraged.