SOC Engineer

Europcar

Paris

Sur place

EUR 65 000 - 90 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Europcar Mobility Group is seeking a SOC Engineer to monitor security events across cloud, on‑premises, and applications, and to defend against cyber threats in a hybrid tech environment.

You will build detections, operate Splunk and SOAR, conduct investigations, threat hunting, and collaborate with IT and business teams to improve resilience.

The role emphasizes collaboration, continuous monitoring, and alignment with security policies and regulatory obligations.

Qualifications

  • 3-8 years in SOC, security operations, detection engineering, incident response, or cyber defense roles.
  • Hands-on experience with Splunk SIEM, SOAR tools, EDR/XDR, and cloud logging.
  • Understanding of cloud security (AWS/GCP), API security, microservices architecture.

Responsabilités

  • Develop and maintain detection rules, dashboards, alerts, correlation logic, and analytics within Splunk (SIEM), SOAR, cloud-native SIEM/SOC tools, EDR/XDR, and identity logs.
  • Build detections and emerging threat patterns.
  • Configure, monitor and troubleshoot security infrastructure devices and services such as EDR, DLP or CASB.
  • Identify opportunities for automation and new security tools to mitigate vulnerabilities.

Connaissances

Detection engineering
Splunk SIEM
SOAR tooling
Incident response
Cloud security

Outils

EDR/XDR tooling
Dynatrace
Splunk
GitLab

Description du poste

Job Description

MISSION: Ensure EMG’s digital assets, cloud platforms, applications, infrastructure, APIs, and data ecosystems are continuously monitored, protected, and defended against cyber threats.

The SOC Engineer is responsible for:

  • Building and tuning security detections
  • Operating EMG’s SIEM/SOAR platforms (Splunk, cloud-native tools)
  • Handling cyber investigations and forensics activities
  • Enhancing visibility across cloud, on-prem, and application layers
  • Supporting threat hunting, response, and vulnerability remediation
  • Ensuring alignment with EMG security policies, CISO directives, and regulatory obligations

This role is essential for maintaining EMG’s cybersecurity resilience in a hybrid and modernized technology landscape.

Main Responsibilities

1. Security Monitoring & Detection Engineering

  • Develop and maintain detection rules, dashboards, alerts, correlation logic, and analytics within Splunk (SIEM), SOAR (such as n8n), cloud-native SIEM/SOC tools, endpoint detection tools (EDR/XDR), and identity logs.
  • Build detections and emerging threat patterns.
  • Configure, monitor and troubleshoot security infrastructure devices and services such as EDR, DLP or CASB.
  • Identify opportunities for, and promote automation and new technical solutions and security tools to help mitigate security vulnerabilities and improve efficiency.

2. Incident Investigation & Threat Response

  • Perform L3 investigation of security alerts, including anomalous authentication events, suspicious network activities, endpoint compromises, cloud misconfigurations, API misuse or credential abuse.
  • Execute containment and remediation actions in collaboration with cybersecurity teams, IT Ops and Engineering teams.
  • Produce clear incident reports and contribute to RCA and continuous improvement.
  • Establish disaster recovery procedures and conduct breach of security drills.

3. Threat Hunting

  • Conduct proactive threat hunts using log patterns, anomalous behavior detection, threat intel feeds, historical investigations, cloud & API-specific threat vectors.
  • Identify gaps in security visibility and propose instrumentation improvements.

4. Security Logging & Observability Integration

  • Ensure complete and reliable logging coverage across cybersecurity tools (EDR, DLP, etc.), APIs, cloud workloads, network traffic, databases, CI/CD systems (GitLab).
  • Work with Observability teams to ensure correlated visibility (Dynatrace + Splunk).

5. Vulnerability & Attack Surface Support

  • Support vulnerability management by correlating findings with real activity logs.
  • Validate remediation and track exploitation attempts related to EMG systems.
  • Assist IT Ops and Engineering teams to prioritize and mitigate vulnerabilities.

6. Cyber Security Controls Validation

  • Validate enforcement of cybersecurity standards (Zero Trust, MFA, encryption, identity governance).
  • Test security controls effectiveness through simulations or red-team collaboration.

7. Documentation, Playbooks & Knowledge Sharing

  • Maintain SOC runbooks, response playbooks, detection documentation, and forensic procedures.
  • Identify and communicate current and emerging security threats.

8. Collaboration Across IT & Business

  • Work closely with CISO, Cybersecurity Architecture Manager, IAM teams, Cloud & Production Services, Network & Infrastructure Ops, Domain Engineering Teams.
  • Ensure consistent communication and coordination during incidents and monitoring activities.
Ideal Experience
  • 3-8 years in SOC, security operations, detection engineering, incident response, or cyber defense roles.
  • Hands‑on experience with Splunk SIEM, SOAR tools, EDR/XDR, and cloud logging.
  • Understanding of cloud security (AWS/GCP), API security, microservices architecture.
Skills & Competencies
  • Strong log analysis, correlation, and detection engineering ability.
  • Understanding of attacker techniques, threat vectors, malware behavior, identity attacks.
  • Ability to operate during high‑pressure security incidents.
  • Knowledge of IAM flows, network security, and container security.
Other Personal Characteristics
  • Analytical, methodical, and rigorous.
  • Calm under pressure; reliable during crises.
  • Highly ethical and trustworthy.
  • Curious and proactive in threat intelligence and detection improvement.
  • Risk‑oriented: ability to detect, assess risks, and propose realistic solutions.
  • Business‑focused: ability to understand business priorities.
Employment Notice

Europcar Mobility Group is a global mobility player with over 75 years of experience. The position is for the role described above.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

SOC Detection Engineer: Threat Hunting & Incident Response
SOC Detection Engineer: Threat Hunting & Incident Response

Europcar • Paris

Hybride
EUR 65 000 - 90 000
SOC Engineer: Threat Detection, Response & Forensics
SOC Engineer: Threat Detection, Response & Forensics

Europcar • Paris

Sur place
EUR 55 000 - 75 000
Prinicipal (L3) SOC Analyst
Prinicipal (L3) SOC Analyst

Integrity360 • Paris

Hybride
EUR 65 000 - 95 000
L2 SOC Analyst
L2 SOC Analyst

Integrity360 • Paris

Hybride
EUR 58 000 - 78 000
SOC Team Lead (M/F/X)
SOC Team Lead (M/F/X)

Equans France • Courbevoie

Sur place
EUR 75 000 - 110 000
Senior Security Operations Engineer
Senior Security Operations Engineer

Capital Fund Management (CFM) • Paris

Hybride
EUR 60 000 - 80 000
L2 SOC Analyst
L2 SOC Analyst

Integrity360 • Paris

Sur place
EUR 50 000 - 75 000
SOC Engineer
SOC Engineer

Europcar España • Paris

Sur place
EUR 60 000 - 80 000
Oportunidades de desarrollo profesional
Ambiente de trabajo colaborativo
SOC Engineer
SOC Engineer

Europcar Mobility Group • Paris

Sur place
EUR 45 000 - 65 000
Ambiente dinâmico e desafiador
Oportunidades de crescimento profissional
Foco em inovação e tecnologia
Senior Security Engineer
Senior Security Engineer

Adrixis • Paris

Sur place
EUR 90 000 - 130 000