This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The role supports the Cyber Security Operations Centre for the EU critical infrastructure, aiming to strengthen IT security through advanced monitoring, detection, and incident response services.
Job Responsibility:
Define incident handling procedures, automation requirements, and playbook logic aligned with the needs
Prepare incident response workflows, automated enrichment steps, and technical documentation for standardized alert handling
Handle cybersecurity incidents from detection through escalation, containment, and resolution
Develop and maintain XSOAR playbooks, integrations, and automations across platforms such as Splunk, AWS, Azure Sentinel, Carbon Black Cloud, and Sysdig
Coordinate and review playbook updates, incident reports, and cross-team collaboration
Report key performance metrics, including FPTP rate, MTTH, escalation rate, automation coverage, time saved, and error reductions
Assist training analysts on playbook usage and incident response methods
Collaborate with CSIRC, CATCH analysts, infrastructure teams, and external stakeholders to validate playbook coverage and share threat intelligence.
Requirements:
Strong incident response methodology and hands-on experience in end-to-end incident handling in multinational settings
Advanced knowledge of XSOAR playbook creation and automation
Proficiency in designing and adapting automated workflows and enrichment
Python programming skills
Ability to present technical and business information effectively to diverse EC stakeholders
High standards for incident documentation, KPI reporting, and compliance with security frameworks
Familiarity with cloud-native services (AWS, Azure), EDR, SIEM-SOAR platforms, and container security
Excellent communication skills for working in multicultural teams and liaising with technical and non-technical audiences
Certifications or experience in relevant security technologies (e.g., Palo Alto Cortex XSOAR, Splunk, Microsoft SC-200, AWS Security Specialty)
Level 6 European Qualification Framework (Bachelor's degree or higher) for senior profiles
Ability to work in international, multicultural environments
Rapid self-starting, teamwork, and multitasking on large projects
Language proficiency: English (B2), French or German a plus
High discretion and integrity.
Nice to have:
French language proficiency
German language proficiency.
What we offer:
Mobility options (including a company car)
Insurance coverage
Meal vouchers
Eco-cheques
Continuous learning opportunities through the Sopra Steria Academy
Welcome to CrawlJobs.com – Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.
We use cookies to enhance your experience, analyze traffic, and serve personalized content. By clicking “Accept”, you agree to the use of cookies.