Staff SOC/CSIRT Engineer (f/m)
Ledger
The mission
- SOC Level 3 Expertise : Act as the primary responder for SOC Level 3 activities, managing advanced threat detection, incident response, and post-incident analysis. Conduct proactive threat-hunting exercises leveraging CTI (Cyber Threat Intelligence) and OSINT (Open Source Intelligence) to identify and mitigate risks before they impact the organization.
- SIEM & SOAR Optimization : Design, optimize, and maintain Sekoia (SIEM) and associated SOAR workflows to ensure efficient threat detection, triage, and response processes. Develop advanced detection rules and automation workflows tailored to Ledger's threat landscape.
- Threat Intelligence Integration : Leverage CTI feeds and OSINT tools to enrich security operations, improving situational awareness and incident response effectiveness. Provide insights from threat intelligence to shape detection strategies and inform security posture improvements.
- Cloud Security Operations : Apply deep knowledge of AWS security best practices to monitor and secure cloud environments. Utilize tools like Wiz for CSPM (Cloud Security Posture Management) and CNAPP to ensure proactive identification and mitigation of cloud vulnerabilities.
- Incident Response & Forensics : Lead technical investigations for high-priority incidents, performing root cause analysis and recommending mitigations to prevent recurrence. Use advanced forensic tools and techniques to analyze and respond to complex attacks.
- Collaboration & Documentation : Work closely with Engineering, Infrastructure, and Security Operations teams to align operational practices with organizational goals. Create detailed playbooks, detection rules, and technical runbooks to enhance team knowledge and response efficiency.
What we're looking for
- 9+ years of experience in security operations, including SOC Level 3 activities and incident response.
- Expertise with Sekoia (or similar SIEM tools), SOAR platforms, and CTI/OSINT methodologies.
- Strong knowledge of AWS security, including IAM, VPC configurations, and cloud-native threat monitoring.
- Hands-on experience with tools such as Wiz, SentinelOne (EDR), and GitHub Actions for automation.
- Exceptional analytical and problem-solving skills, with the ability to handle complex security challenges.
- Excellent communication skills for conveying technical concepts to cross-functional teams.
What's in it for you?
- Equity: Employees are the foundation of our success, and we award stock options so you can share in that success as we grow. Flexibility: A hybrid work policy.
- Social: Annual company outing for Ledgerdary Days, plus frequent social events, snacks and drinks
- Medical: Comprehensive health insurance policy offering extensive medical, dental and vision care coverage. Well-being: Personal development, coaching & fitness with our dedicated partners.
- Vacation: Five weeks of paid leave per year, in addition to national holidays and rest & relaxation (RTT) days.
- High tech: Access to high performance office equipment and gadgets, including Apple products.
- Transport: Ledger reimburses part of your preferred means of transportation.
- Discounts: Employee discount on all our products.