Staff Security Operations Engineer

Ledger
Paris
Workplace: HybridFull timeFunction: Solutions Engineering & Sales EngineeringExperience: 9+ yearsSkills: ["Incident management","Threat hunting","Forensics","Technical leadership","Automation"]

Lead complex incident response for internal cloud, SaaS, endpoint, identity, and data center environments as the Security Operations team’s top technical authority. Own detection strategy and threat hunting using CTI/OSINT, and design the SIEM/SOAR foundations (Splunk and Torq). Build and evolve Ledger’s in-house Agentic SOC, log/data pipelines, and automation to improve noise reduction, detection quality, and faster investigations.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ledger
Ledger
2 months ago

Staff Security Operations Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Lead complex incident response for internal cloud, SaaS, endpoint, identity, and data center environments as the Security Operations team’s top technical authority. Own detection strategy and threat hunting using CTI/OSINT, and design the SIEM/SOAR foundations (Splunk and Torq). Build and evolve Ledger’s in-house Agentic SOC, log/data pipelines, and automation to improve noise reduction, detection quality, and faster investigations.
Location: Paris
Workplace: Hybrid
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Director level

Key Responsibilities

  • •Serve as primary point of contact and coordinator for the most complex CSIRT incidents across cloud, corporate systems, endpoints, identities, and the data center.
  • •Conduct end-to-end investigations including root cause analysis, forensics, timeline reconstruction, and remediation recommendations.
  • •Define detection strategy, architecture, and methodology; lead proactive threat hunting using CTI and OSINT.
  • •Design and optimize Splunk SIEM architecture and Torq SOAR workflows; standardize data quality (CIM), data models, search performance, and detection governance.
  • •Build and evolve the internal Agentic SOC, log/data pipelines, and reporting automation; establish standards, playbooks, and runbooks and mentor engineers.

Key Requirements

  • •9+ years of experience in security operations, incident response, and CSIRT.
  • •Track record as a technical expert in incident management, threat hunting, and detection engineering.
  • •In-depth expertise in SIEM (ideally Splunk) and SOAR platforms, plus CTI/OSINT methodologies.
  • •Solid knowledge of AWS security (IAM, audit logs, network configurations, workloads, containers, Kubernetes) and cloud security tools (ideally Wiz, CSPM/CNAPP) with EDR experience (ideally CrowdStrike).
  • •Ability to automate tasks and reporting using Python, Bash, APIs, GitHub Actions, and a SOAR platform (or equivalent).
Experience:9+ yearsSecurity operationsIncident responseCloud securitySaaSSOC automationWeb3
Skills:Incident managementThreat huntingForensicsTechnical leadershipAutomation
Tech Stack:SplunkCrowdStrikeWizTorqAWSEKSKubernetesSIEMSOARAgentic SOCPythonBashAPIsGitHub ActionsCIMCTIOSINTCI/CD

Company Brief

Ledger
Ledger designs and sells hardware wallets and security infrastructure for digital assets and Web3, offering consumer devices (Nano S/X, Stax), Ledger Live software, and enterprise custody solutions to secure cryptocurrencies and NFTs.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series C
Headquarters: Paris, France
Founded: 2014
Glassdoor
Glassdoor: 3.9
WebsiteLinkedInGlassdoor