This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re looking for a Senior Security Engineer to lead and scale our security monitoring, threat detection, and incident response capabilities in a cloud-native environment. You’ll design and operate detection and response workflows across AWS and Kubernetes, improve signal quality, drive automation through SOAR, and partner closely with Engineering and SRE teams to reduce risk while enabling fast delivery.
Job Responsibility:
Own detection engineering end-to-end: build, tune, and maintain threat detections across cloud, Kubernetes, workloads, and identity, focusing on high-fidelity signals and actionable alerts
Operate and evolve SIEM & SOAR: develop ingestion pipelines, parsing/normalization, enrichment, correlation, dashboards, and automated playbooks (triage, containment, evidence collection)
Incident response leadership: act as an incident responder and escalation point. Coordinate investigations, containment, eradication, recovery, and build incident reports
maintain version control, peer review, and CI/CD for detections/playbooks
Threat hunting & proactive analysis: conduct hypothesis-driven hunts, identify gaps, and translate findings into new detections and automated response
Cross-functional collaboration: partner with GRC, SRE, and Engineering teams to harden services, improve observability, and roll out secure-by-default controls
Documentation and enablement: create runbooks, playbooks, and training so on-call responders and stakeholders can act quickly and consistently
Requirements:
6+ years in security engineering, detection & response, or SOC/IR roles, with strong hands-on technical depth
Proven experience building and operating SIEM (Splunk, Elastic, or other equivalent SIEM platforms) detections, alerting, and dashboards in production environments
Strong incident response skills: investigation, evidence collection and custody-chain enforcement, containment strategies, and communications
Solid knowledge of AWS security (CloudTrail, GuardDuty concepts, IAM, VPC flow logs, CloudWatch, etc.) and common cloud attack techniques