Operations Security Engineer

đŸ”„ 23 hours ago

🌐 France, Germany, +1 more countries – Remote

infoinfo

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ›Ąïž Security Operations

đŸ‘» Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of EPI Company

EPI Company

201 - 500 employees

Founded 2020

đŸ’Œ Consulting

📩 Logistics

📣 Marketing

Consulting ‱ Logistics ‱ Marketing

EPI Company is reshaping the future of payments with Wero, a European-made digital payments solution that enables instant, cross-border transactions for consumers and businesses. The company operates as a remote-first, Europe-based team building payment platform and wallet products, focusing on digital sovereignty, compliance, and seamless payment experiences across markets.

📋 Description

‱ Act as a central point of contact for alert triage, incident identification and security event investigation across EPI environments ‱ Execute incident response activities using structured frameworks such as SANS PICERL ‱ Conduct proactive, hypothesis-driven threat hunts based on attacker behaviour, emerging threats, threat intelligence and MITRE ATT&CK techniques ‱ Parse, analyse and correlate logs from authentication, application, system, endpoint and cloud telemetry sources, including AWS and Azure ‱ Design, tune and maintain detection rules, use cases, dashboards, custom alerts and automation workflows ‱ Contribute to the development and continuous improvement of SOC playbooks, runbooks, SIEM and EDR integrations ‱ Document and communicate threat findings, incident outcomes and remediation recommendations ‱ Collaborate with Security, Engineering, DevOps, IT and Operations teams to improve detection coverage, response readiness and operational resilience ‱ Support incident response and operational continuity through participation in a 24/7 on-call rotation

🎯 Requirements

‱ 5+ years of experience in cybersecurity, with strong hands-on experience as a SOC analyst, incident responder, detection engineer or similar role ‱ Fluent in English (CEFR C1 or C2); French, German, Dutch or other European languages are a plus ‱ Ability to thrive in a remote-first, multicultural and fast-paced environment ‱ Strong familiarity with the full SOC lifecycle, from Tier 1 to Tier 3, including alert triage, incident response, threat hunting and threat intelligence ‱ Proven experience in threat hunting, detection engineering or threat intelligence ‱ Solid understanding of SIEM and EDR technologies, log parsing, detection engineering and alert tuning ‱ Hands-on experience with Python, PowerShell or KQL ‱ Ability to analyse and correlate logs from authentication, application, system and cloud telemetry across AWS and Azure ‱ Knowledge of attacker TTPs, MITRE ATT&CK, threat exposure and attack path analysis ‱ Experience creating or improving incident response playbooks, runbooks and automation workflows ‱ Strong communication skills for explaining technical findings and security risks to technical and non-technical stakeholders ‱ Willingness to participate in a 24/7 on-call rotation, approximately one week per month ‱ Nice-to-have: Experience with Rapid7 and TaHiTI ‱ Nice-to-have: Familiarity with Microsoft Entra ID and its integration into detection and response workflows ‱ Nice-to-have certifications: GSEC, GCIH, BTL1/2, SC-200 or AZ-500 ‱ Nice-to-have: Experience in payments, banking, fintech or another highly regulated environment

đŸ–ïž Benefits

‱ Remote-first culture with quarterly and annual all-staff in-person meetups to keep teams connected and collaborative ‱ Possibility to work from another EU country for up to 3 months per year ‱ Competitive compensation package featuring performance-based bonus and a thoughtfully designed, high-quality benefits programme ‱ Learning & development budget: €5,000 training budget per year ‱ Inclusive work environment and equal employment opportunities

Apply Now