Staff Security Operations Engineer
Job description
About the role
This role is for a Staff Security Operations Engineer who owns the full lifecycle of incident response for Ledger's most critical events, driving resolution from initial alert to post-incense improvement. You will lead the detection and response strategy for corporate, cloud, SaaS, and data center environments, ensuring threats are anticipated, identified, and neutralized at speed. As a key architect of our security operations, you will define the methodologies, playbooks, and standards that shape how the SecOps team operates and improves. You will build and evolve the underlying systems that power our defense, including the log pipeline, detection logic, and automation workflows. In this position, you act as the primary technical authority for complex incidents, coordinating with stakeholders to protect our infrastructure and users. You will leverage cutting edge AI capabilities to enhance investigation quality, reduce noise, and accelerate response times. Ultimately, your work ensures that Ledger can maintain a resilient and trustworthy environment for our global digital asset platform.
Key facts
What you'll do
- Serve as the primary point of contact and coordinator for the most complex incidents across the cloud, corporate systems, endpoints, identities, and the data center.
- Conduct end-to-end investigations: root cause analysis, forensics, timeline reconstruction, and remediation recommendations to prevent recurrence.
- Serve as the team's go-to expert in incident management, ensuring a rigorous and consistent approach to handling, escalating, and documenting incidents.
- Define the team's detection strategy, architecture, and methodology.
- Lead proactive threat hunting by leveraging CTI and OSINT to identify and neutralize risks before they impact Ledger.
- Address the most challenging and emerging detection issues, and translate threat intelligence into concrete improvements in security posture.
- Design and optimize the SIEM (Splunk) architecture and SOAR workflows to improve detection fidelity and investigation efficiency.
- Build and manage the in-house Agentic SOC, including its alert enrichment, correlation, investigation support, reporting, and automation capabilities.
- Establish standards, playbooks, and methodologies that raise the technical bar for the entire SecOps team.
- Continuously improve the log pipeline, data quality, and exposure management across cloud, endpoints, and workloads.
- Expand detection coverage and ensure high-quality telemetry that supports both automated response and human analysis.
- Develop and maintain reliable dashboards and operational workflows that provide clear visibility into security posture and incident trends.
- Collaborate closely with product security, engineering, and infrastructure teams to align on risk management and security controls.
- Mentor and elevate the technical capabilities of team members through knowledge sharing and hands-on guidance.
Requirements
- You hold a degree in Computer Science, Cybersecurity, or a related technical field, or you possess equivalent practical experience.
- You have proven experience as a security operations engineer or incident responder in a complex cloud environment.
- You are deeply experienced with SIEM platforms, specifically Splunk, including search development, correlation, and dashboard creation.
- You have hands-on expertise with endpoint detection and response solutions, such as CrowdStrike, across workloads and servers.
- You understand cloud security and exposure management, with direct experience using a platform such as Wiz in production environments.
- You are proficient in SOAR tooling and automation, including practical use of Torq or similar platforms.
- You have a strong operational background in AWS, including container orchestration with EKS and Kubernetes workloads.
- You are comfortable working with in-house tools and are capable of quickly learning and extending custom-built systems.
- You have experience developing and maintaining detection playbooks, log parsing, and data normalization practices.
- You are fluent in written and spoken English, with additional European languages being a distinct advantage in a global environment.
Nice to have
- Experience contributing to the design and operation of a Security Operations Center.
- Familiarity with emerging AI applications in security, particularly agentic workflows and autonomous investigation systems.
- Background in threat intelligence and working with Cyber Threat Intelligence sources.
- Knowledge of identity and access management security in cloud and enterprise environments.
Practical notes
This role is based in Paris, France, and requires availability to work from the office as needed for operational coverage and incident response. The position is full-time and aligned with standard working hours, with expectations for on-call rotation for critical incidents. Travel is generally limited within the defined office locations, and visa sponsorship is available for eligible candidates under Ledger's corporate policy.