Prinicipal (L3) SOC Analyst

Integrity360

Paris

Sur place

EUR 65 000 - 95 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Integrity360 is seeking a Principal SOC Analyst (L3) to serve as the Level 3 escalation point within the MDR/SOC function. You will provide advanced technical support to Level 2 analysts during complex investigations and contribute to the continuous improvement of detection strategies, tuning, and incident response playbooks across IT and OT environments.

The role requires hands-on security operations experience, strong knowledge of SIEM/EDR/NIDS/SOAR/DLP, and the ability to communicate

Qualifications

  • Experience in Security Operations Centre or MDR environments.
  • Experience with SIEM, EDR, NIDS, SOAR, DLP and related security monitoring technologies.
  • Ability to analyse endpoint/network telemetry for complex investigations.
  • Experience with SIEM query languages and detection logic.
  • Strong understanding of attacker tactics and MITRE ATT&CK for ICs.
  • OT/ICS familiarity and IT/OT convergence awareness.
  • Experience developing detection use cases and incident playbooks.
  • Customer-facing technical discussion experience.

Responsabilités

  • Act as Level 3 escalation for advanced investigations.
  • Support Level 2 during complex investigations with guidance.
  • Analyze security events, logs, and telemetry.
  • Lead investigations: scoping, containment, eradication, remediation.
  • Analyse attacker behaviour and TTPs.
  • Assist customers in tuning security monitoring capabilities.
  • Review and improve SIEM/EDR/NIDS/SOAR configurations.
  • Develop detection use cases and alert logic.
  • Define customer monitoring strategies based on risk.
  • Provide technical recommendations to improve posture.
  • Conduct threat hunting and proactive analysis.
  • Document findings and remediation steps clearly.
  • Prepare technical reports for customers and partners.
  • Monitor emerging threats relevant to customer environments.
  • Contribute to SOC process improvements and playbooks.
  • Mentor Level 1/2 analysts as needed.
  • Lead investigations involving OT/ICS environments.
  • Analyze OT protocols and industrial assets.
  • Collaborate with OT Security Practice for improvements.

Connaissances

SOC operations
MDR expertise
Threat hunting
Incident response
Threat analysis
Detection tuning
MITRE ATT&CK
Log analysis
Endpoint telemetry
Network telemetry
Customer-facing
Communication skills
Threat intelligence
OT/ICS awareness
KQL / SPL / Sigma

Outils

Microsoft Sentinel
Splunk
QRadar
CrowdStrike
SentinelOne
Palo Alto
Suricata
Zeek
Snort
Nozomi
Armis

Description du poste

Principal SOC Analyst (L3)

Job type: Full-Time Permanent

Salary: Negotiable / DOE

About Us

Integrity360 is a leading independent cybersecurity and PCI specialist operating across Europe, Africa, the Caribbean, and North America. The company has office locations in Ireland, the UK, Bulgaria, Italy, Sweden, Spain, Lithuania, Ukraine, Africa, the Caribbean, and Canada, supported by six Security Operations Centres (SOCs) located in Dublin, Sofia, Madrid, Stockholm, Rome, and Cape Town.

With over 780 employees, including more than 585 dedicated cybersecurity professionals, Integrity360 delivers a full suite of professional, support, and managed security services. These span the complete cyber risk lifecycle, from identification and prevention to detection, response, and recovery. Integrity360 supports over 3000 mid-market and enterprise organisations across sectors including financial services, insurance, government, healthcare, retail, telecommunications, and utilities.

At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you're ready to take your cyber security career to the next level, we'd love to hear from you.

Job Role / Responsibilities

In this role, you will act as a Level 3 escalation point within the MDR/SOC function, providing advanced technical support to Level 2 analysts during complex or high-severity investigations. You will be expected to bring deep operational knowledge across modern security technologies, including SIEM, EDR, Network Intrusion Detection Systems, SOAR, DLP and related security monitoring platforms. The Principal SOC Analyst will support the investigation, containment and remediation of advanced threats, ensuring that incidents are analysed in the correct business and technical context. The role requires strong hands-on experience in security operations, incident response, threat analysis and detection tuning, as well as the ability to work directly with customers and internal stakeholders to improve detection capability and strengthen cyber security posture. You will contribute to the continuous improvement of the MDR service by supporting the definition of security monitoring strategies, improving detection logic, tuning security technologies, reviewing investigation processes and advising customers on technical optimisation opportunities. A strong understanding of malware behaviour, adversary tactics, techniques and procedures, and emerging threats will be critical to success.

This role contributes to the development of Operational Technology (OT) security monitoring and incident response capabilities, as part of the integration of industrial environments into our Global SOC model.

Primary Duties/Responsibilities include:
  • Act as the Level 3 escalation point for advanced, complex or high-impact security investigations.
  • Support Level 2 analysts during complex investigations, providing technical guidance, validation and direction.
  • Perform in-depth analysis of security events, alerts, logs, endpoint telemetry, network traffic and other relevant data sources.
  • Lead advanced incident investigations, including scoping, containment, eradication and remediation recommendations.
  • Analyse malicious activity, suspicious files, attacker behaviour and adversary TTPs.
  • Support customers from a technical perspective in the optimisation, tuning and improvement of their security monitoring capabilities.
  • Review and improve SIEM, EDR, NIDS, SOAR and other security tool configurations to reduce false positives and improve detection quality.
  • Contribute to the development and refinement of detection use cases, correlation rules, alerting logic and investigation playbooks.
  • Support the definition of customer security monitoring strategies based on risk profile, threat landscape and available telemetry.
  • Provide technical recommendations to strengthen customer cyber security posture and improve resilience against current and emerging threats.
  • Conduct threat hunting and proactive analysis based on indicators, behaviours, intelligence and attack patterns.
  • Document investigation findings, evidence, timelines, containment actions and remediation recommendations in a clear and structured manner.
  • Prepare and deliver technical reports to customers, partners and internal stakeholders.
  • Monitor trusted sources for emerging threats, vulnerabilities and adversary activity relevant to customer environments.
  • Contribute to the continuous improvement of SOC processes, procedures, documentation and knowledge base material.
  • Support mentoring and technical development of Level 1 and Level 2 analysts where required.
  • Lead and support investigations involving Operational Technology (OT) / Industrial Control Systems (ICS) environments, including IT/OT convergence scenarios.
  • Analyse security events related to industrial assets and protocols (ex. SCADA systems, DCS, PLCs, HMIs).
  • Support incident response activities, in close collaboration with the Group Incident Response Team for complex security incidents, including those impacting IT and OT environments (scoping, containment, eradication, and post-incident analysis).
  • Contribute to the development and fine-tuning of OT-specific detection use cases, monitoring strategies and incident response playbooks.
  • Collaborate closely with the Group’s OT Security Practice, leveraging industrial expertise to enhance SOC monitoring, detection and response capabilities.
Desired Skills
  • Strong hands-on experience in Security Operations Centre or MDR environments.
  • Deep operational knowledge of SIEM, EDR, Network Intrusion Detection Systems, SOAR, DLP and related security monitoring technologies.
  • Strong experience with security event triage, correlation, investigation and escalation.
  • Ability to analyse endpoint, network, identity, cloud and application telemetry in support of complex investigations.
  • Experience with SIEM query languages and detection logic, such as KQL, SPL, Sigma or equivalent.
  • Experience tuning security controls and detection content to improve alert fidelity and reduce false positives.
  • Strong understanding of attacker tactics, techniques and procedures, including MITRE ATT&CK.
  • Ability to perform host-based and network-based threat analysis.
  • Experience analysing packet captures, endpoint artefacts, logs, scripts, documents and potentially malicious files.
  • Strong understanding of incident response lifecycle, including preparation, identification, containment, eradication, recovery and lessons learned.
  • Strong understanding of enterprise network architecture, TCP/IP, firewalls, proxies, VPNs, DNS, email security and cloud environments.
  • Understanding of security protocols, encryption technologies and common authentication mechanisms.
  • Experience supporting customer-facing technical discussions, including investigation reviews, tuning recommendations and posture improvement activities.
  • Ability to manage multiple complex incidents and make effective decisions under pressure.
  • Strong written and verbal communication skills, with the ability to explain technical findings to both technical and non-technical stakeholders.
  • Experience with Microsoft Sentinel, Microsoft Defender, Splunk, QRadar, CrowdStrike, SentinelOne, Palo Alto, Suricata, Zeek, Snort or similar technologies is highly beneficial.
  • Experience with cloud security monitoring across Microsoft Azure, AWS or Google Cloud is beneficial.
  • Experience with threat hunting, detection engineering or purple team activities is beneficial.
  • Ability to produce clear technical documentation, investigation reports and customer-facing recommendations.
  • Understanding of OT / ICs environments (SCADA, DCS, PLCs, HMIs).
  • Familiarity with industrial protocols (ex. Modbus, OPC, IEC 104, DNP3, etc.) is beneficial.
  • Knowledge of OT threat landscape and frameworks (ex. MITRE ATT&CK for ICs).
  • Understanding of IT/OT convergence challenges and network segmentation practices (ex. IEC 62443).
  • Experience with OT security platforms or NDR (ex. Armis, Nozomi, Clarity, Dragos, Darktrace, etc.) is a plus.
Certifications/Qualifications
  • Security industry certifications such as GCIH, GCFA, GCIA, GNFA, GCTI, GSEC, CISSP, CySA+, SC-200, AZ-500 or equivalent are highly beneficial.
  • OT-related certifications or training (ex. GICSP, GRID, IEC 62443) are advantageous.
  • Minimum 2–3 years of experience in a SOC, MDR, incident response, CSIRT or cyber security operations role.
  • Proven experience handling complex security incidents and supporting advanced investigations.
  • Working knowledge of SIEM, EDR, SOAR, NIDS, DLP and threat intelligence platforms.
  • Experience working with threat hunting methodologies and security detection frameworks.
  • Experience supporting customers or internal stakeholders with security optimization, detection tuning and cyber security posture improvement.
  • Experience supporting industrial or critical infrastructure environments is a plus.

#LI-PM2

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

L2 SOC Analyst
L2 SOC Analyst

Integrity360 • Paris

Hybride
EUR 58 000 - 78 000
L2 SOC Analyst
L2 SOC Analyst

Integrity360 • Paris

Sur place
EUR 50 000 - 75 000
Senior SOC Analyst (L3) – IR & Threat Hunting
Senior SOC Analyst (L3) – IR & Threat Hunting

Integrity360 • Paris

Hybride
EUR 65 000 - 95 000
SOC Engineer
SOC Engineer

Europcar • Paris

Sur place
EUR 65 000 - 90 000
Senior Security Operations Engineer
Senior Security Operations Engineer

Capital Fund Management (CFM) • Paris

Hybride
EUR 60 000 - 80 000
SOC Analyst (Level 3)
SOC Analyst (Level 3)

Jobtailor • Paris

Sur place
EUR 70 000 - 90 000
OT Cyber Security Manager
OT Cyber Security Manager

Integrity360 • Paris

Hybride
EUR 90 000 - 130 000
Reference manager
Internal training
Annual external training
SOC Team Lead (M/F/X)
SOC Team Lead (M/F/X)

Equans France • Courbevoie

Sur place
EUR 75 000 - 110 000
Analyste SOC / MDR (H/F)
Analyste SOC / MDR (H/F)

Neurones • France

Sur place
EUR 45 000 - 70 000
Snr OT Cyber Security Consultant
Snr OT Cyber Security Consultant

Integrity360 • Paris

Sur place
EUR 50 000 - 75 000
Coaching and skills development
Annual external training
Team activities and events