SOC Engineer L2/L3

🕒 June 2

đŸ‡ȘđŸ‡ș Europe – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ›Ąïž Security Operations

đŸ‘» Ghost score 20%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Solidgate

Solidgate

201 - 500 employees

💳 Fintech

☁ SaaS

🔌 API

Fintech ‱ SaaS ‱ API

Solidgate is a fintech SaaS platform that provides payment orchestration and global payment infrastructure for merchants and businesses. It offers hosted payment pages and APIs, intelligent routing, connectors to dozens of payment providers and alternative payment methods, acquiring, billing and subscription engines, antifraud and chargeback representment tools, and treasury/business accounts to move and receive funds. Solidgate focuses on helping businesses launch and scale global commerce with enterprise-grade security, multi-region availability, and developer-friendly integrations.

📋 Description

‱ Build and operationalize the SIEM from PoC to production - including case management and UEBA, with full ownership of the technology selection ‱ Design, write, and tune detection rules mapped to MITRE ATT&CK, covering identity compromise, privilege escalation, lateral movement, and endpoint threats ‱ Triage and investigate L2/L3 alerts, reduce false positives, and establish clear escalation paths for each use case ‱ Lead incident response and basic forensics - containment, eradication, and structured lessons learned ‱ Onboard log sources across AWS, JumpCloud, Google Workspace, CDE, and SWIFT; ‱ Run threat hunts based on realistic attack hypotheses specific to a payment platform's risk profile ‱ Build and maintain runbooks and playbooks; automate repetitive actions via SOAR or scripting ‱ Define SOC metrics and own monthly reporting to management on detection coverage and response performance

🎯 Requirements

‱ 3+ years in SOC / Detection & Response at L2/L3 level, with hands-on investigation experience ‱ Practical experience building or operating a SIEM, including writing and tuning detection rules ‱ Detection engineering with MITRE ATT&CK mapping; confident with KQL, SPL, or equivalent query languages ‱ Experience investigating cloud log sources: AWS CloudTrail, GuardDuty, Google Workspace, EDR/XDR ‱ Scripting and automation skills (Python or similar) for telemetry processing and routine tasks ‱ Solid understanding of attacker techniques and how they manifest in logs - not just tool knowledge, but threat understanding ‱ Structured under pressure: disciplined investigation process, clear documentation, clean post-mortems ‱ SOAR experience and a detection-as-code approach (version control for rules, CI pipelines for detection) ‱ UEBA, threat intelligence enrichment, or alert contextualization at scale ‱ Familiarity with payment-specific environments - CDE monitoring, SWIFT, PCI DSS context ‱ Purple teaming experience working alongside an offensive security team

đŸ–ïž Benefits

‱ 30+ days off ‱ Unlimited sick leave ‱ Free office meals ‱ Health coverage ‱ Apple gear to keep you productive ‱ Courses, conferences, sports and wellness benefits

Apply Now