Senior Security Operations Engineer

Lever, Inc.

France

À distance

EUR 70 000 - 110 000

Plein temps

Il y a 3 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature sur mesure pour ce poste — un CV personnalisé et une lettre de motivation qui correspondent directement à l’offre.

Passez les filtres ATS

Avantages offerts par ce poste

Fully remote
Health benefits
Pension plan
EAP program
Wellness days
Volunteer time off
Birthday off
Recognition program
Growth opportunities
Total Rewards
Diversity & inclusion

Résumé du poste

Lever, Inc. is seeking a Senior Security Operations Engineer based in France to translate advanced offensive security research into production-ready detection capabilities for modern applications.

You will build and maintain production‑grade detection content, develop new rules with OpenGrep, and research vulnerabilities, exploitation techniques, and emerging attack patterns. Collaborating with engineering, product, AI/ML, and infra teams, you will integrate content into cloud-native and CI/CD

Qualifications

  • 5+ years of experience in offensive security or application security research, or equivalent experience with a relevant bachelor's degree plus 2 years.
  • Broad programming knowledge with strong JavaScript skills and Python desirable.
  • Strong understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomies.
  • Experience writing detection logic for DAST scanners, fuzzers, or comparable security systems.
  • Hands-on web application penetration testing covering OWASP Top 10, REST, GraphQL, authentication and authorization.
  • Ability to research complex technical problems and work with ASTs.
  • Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems.
  • Fluent English communication and collaboration skills.

Responsabilités

  • Build and maintain production-ready security checks and detection content with a focus on accuracy and low FP rates.
  • Develop new detection rules using OpenGrep to identify novel malware and vulnerability patterns.
  • Research vulnerability classes, exploitation techniques, and emerging attack patterns for production detections.
  • Extend analysis capabilities to support additional languages and evolving application technologies.
  • Triage analysis pipeline packages, investigate findings, and validate detection results.
  • Create attack-chain templates combining findings into higher-impact security scenarios.
  • Develop evaluation harnesses, benchmarks, and testing frameworks to measure coverage and FP rates.
  • Investigate difficult or ambiguous findings and maintain detection quality across the platform.
  • Apply detection principles while contributing to internal standards and methodologies.
  • Experiment with new security tools and techniques for scalable threat detection.
  • Monitor developments in application security, AI security, LLM vulnerabilities, and MCP ecosystems.
  • Collaborate with engineering, product, AI/ML, and infrastructure teams to deploy content.
  • Integrate detection, testing, and validation into cloud-native and CI/CD environments.

Connaissances

JavaScript
Python
DAST
OpenGrep
Semgrep
Burp Suite
nmap
ffuf
HTTP
CI/CD
Cloud infrastructure
AST concepts
LLMs prompt engineering
YARA

Formation

Bachelor's degree in a relevant field

Outils

Burp Suite
sqlmap
nmap
ffuf
OpenGrep
Semgrep

Description du poste

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Operations Engineer based in France.

This role offers the opportunity to turn advanced offensive security research into production‑ready detection capabilities for modern application security.

You will build and maintain security checks designed to identify vulnerabilities, malware, and emerging attack patterns with high accuracy and low false‑positive rates.

The position combines hands‑on security research, detection engineering, testing, and continuous experimentation across evolving threat landscapes.

You will work with technologies including OpenGrep, JavaScript, Python, static analysis, cloud infrastructure, and CI/CD pipelines.

Your work will also extend into emerging areas such as AI security, LLM vulnerabilities, agentic systems, and MCP security.

Collaboration spans engineering, product, AI/ML, and infrastructure teams to ensure detection content is effectively developed, tested, and deployed.

This is a hands‑on environment for an experienced security professional who enjoys solving complex problems and improving security capabilities at scale.

Accountabilities
  • Build and maintain production‑ready security checks and detection content with a focus on accuracy, broad coverage, and low false‑positive rates.
  • Develop new detection rules, primarily using OpenGrep, to identify novel malware and vulnerability patterns.
  • Research vulnerability classes, exploitation techniques, and emerging attack patterns and translate findings into effective production detections.
  • Extend analysis capabilities to support additional programming languages and evolving application technologies.
  • Triage analysis pipeline packages, investigate findings, and validate detection results.
  • Develop attack‑chain templates that combine lower‑severity findings into higher‑impact security scenarios.
  • Create and maintain evaluation harnesses, benchmarks, and testing frameworks to measure detection coverage, accuracy, false‑positive rates, exploit reproducibility, and regression performance.
  • Investigate difficult or ambiguous findings and help maintain consistent detection quality across the platform.
  • Apply established detection and exploitation principles while contributing to internal standards and methodologies.
  • Experiment with new security tools and techniques for detecting threats and malware at scale.
  • Monitor developments in application security, offensive security, AI security, LLM vulnerabilities, agentic systems, and MCP ecosystems and incorporate relevant insights into detection engineering.
  • Collaborate with engineering, product, AI/ML, and infrastructure teams to develop, test, integrate, and operate detection content.
  • Integrate detection, testing, and validation into cloud‑native and CI/CD development environments.
Requirements
  • 5+ years of experience in offensive security or application security research, or equivalent experience, with a relevant bachelor's degree plus 2 years of experience.
  • Broad programming knowledge, with strong JavaScript skills required and Python highly desirable.
  • Strong understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomies.
  • Experience writing detection logic for DAST scanners, fuzzers, or comparable security systems, including response interpretation and false‑positive management.
  • Hands‑on web application penetration testing experience covering OWASP Top 10 vulnerabilities, authentication, authorization, business logic, REST, GraphQL, and related application security areas.
  • Ability to research complex technical problems and work with algorithms and concepts such as Abstract Syntax Trees (ASTs).
  • Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems is highly valued.
  • Familiarity with offensive security tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload‑generation techniques.
  • Understanding of HTTP and modern web protocols.
  • Familiarity with cloud infrastructure, containers, CI/CD, and modern DevOps practices is advantageous.
  • Fluent English communication skills, with the ability to explain technical concepts to both technical and non‑technical audiences.
  • Strong collaboration skills and good judgment around when to *escalate* complex or high‑impact issues.
  • Hands‑on mindset, intellectual curiosity, and willingness to investigate both established application security challenges and emerging threats.
  • OpenGrep or Semgrep experience, static analysis expertise, production system development experience, or exposure to LLMs and prompt engineering are advantageous.
  • Security research contributions such as CVEs, advisories, technical talks, open‑source tools, or technical writing experience are a plus.
  • YARA experience is also beneficial.
Benefits
  • Fully remote working options.
  • Health, pension, and statutory benefits tailored to the employee's country of residence.
  • 24/7 Employee Assistance Program offering emotional support counseling, life coaching, dependent and elder care, financial and legal support, wellness coaching, and new‑parent support.
  • Quarterly Thrive‑Wellness Days, providing one additional day off each quarter for company‑wide rest and renewal.
  • 5 days of paid volunteer time off each year.
  • Paid birthday day off.
  • Employee recognition and rewards programs.
  • Opportunities for personal and professional growth and development.
  • Flexible, globally oriented Total Rewards approach adapted to regional needs.
  • Inclusive and collaborative environment supporting diversity and individuality.
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Staff Security Researcher
Staff Security Researcher

Lever, Inc. • France

À distance
EUR 90 000 - 140 000
Fully remote Europe
Health & pension
Wellness days
+1
Security Engineer - Paris / Lyon / Cracow
Security Engineer - Paris / Lyon / Cracow

Atlas Metrics • Tassin-la-Demi-Lune

Sur place
EUR 60 000 - 90 000
Hybrid work model
RTT days
Meal vouchers (SWILE)
+2
Security Risk Management Specialist
Security Risk Management Specialist

Lever, Inc. • France

Sur place
EUR 70 000 - 110 000
Remote-first working environment
In-person team sprints (twice yearly)
Learning & development budget (USD 2,0
+5
Senior Backend Engineer | Cybersecurity AI AppSec
Senior Backend Engineer | Cybersecurity AI AppSec

United States Digital Space LLC • Paris

Sur place
EUR 90 000 - 130 000
Significant equity
Top-tier health insurance
Meal vouchers
+5
Senior Security Operations Engineer
Senior Security Operations Engineer

Capital Fund Management (CFM) • Paris

Sur place
EUR 60 000 - 80 000
Cyber Security Engineer
Cyber Security Engineer

Leap29 • France

Sur place
EUR 70 000 - 100 000
Remote work in France
On-call rotation pay
Associate Security Engineer
Associate Security Engineer

Spendesk • Paris

Sur place
EUR 40 000 - 70 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care for wellbeing
+2
Senior Security Engineer
Senior Security Engineer

DataDome • France

Sur place
EUR 70 000 - 90 000
500€ stipend for workspace setup
Generous health benefits
Annual allowance for leisure activities
+2
Senior Solution Engineer Southern Europe (Remote, France)
Senior Solution Engineer Southern Europe (Remote, France)

Jobgether • France

Sur place
EUR 50 000 - 70 000
Flexible working hours
33 vacation days per year
Wellbeing support programs
+2
Senior DevSecOps Engineer (Offensive Security Focus)
Senior DevSecOps Engineer (Offensive Security Focus)

Neotrust • France

Sur place
EUR 60 000 - 80 000