Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Operations Engineer

Full-time

Ledger

We’re a team of experts pushing the limits of what’s possible, united by our common goal to unlock true freedom through digital ownership, making technology accessible for all. We believe in a world where users, creators and enterprises manage their value with ownership and freedom. Our curiosity drives us to innovate, empowering individuals on a global scale. We believe change is constant and our team moves forward as one, with a culture of problem-solving where every employee is empowered and supported to challenge tradition and create solutions. Our mission is simple: to make self-custody accessible and give people the keys to their own financial futures. If you want to make a true impact, we want you to join us at Ledger.

At Ledger, we’re proud to be the global platform for digital assets and Web3, with over 20% of the world’s crypto assets secured through our Ledger devices. With our headquarters in Paris, and offices in Vierzon, Grenoble, Montpellier, London, Portland, Geneva, Zurich and Central Singapore, we have a team of around 600 professionals developing a variety of products and services to enable individuals and companies to securely buy, store, swap, grow and manage crypto assets – including the Ledger hardware wallets line with more than 7.5 millions units already sold in 200 countries.

The team:

You’ll join the Security Operations team, responsible for protecting Ledger’s corporate, cloud, SaaS, and data center environments. Its mission: to anticipate, detect, investigate, and respond to cyber threats—including monitoring, alert triage, incident response, detection, visibility, automation, exposure tracking, and continuous process improvement. The scope is distinct from that of the Donjon (product security): SecOps covers the operational security of internal environments, the cloud, endpoints, workloads, identities, and infrastructure.

As a close-knit and experienced team—technically demanding and committed to knowledge sharing—we’re also continuously building the SOC itself: integrating new log sources, ensuring data quality, expanding detection coverage, and developing reliable dashboards and operational workflows.

Our technical stack includes:

  • Splunk for SIEM, investigations, and dashboards;

  • CrowdStrike for EDR and endpoint/workload security;

  • Wiz for cloud security and exposure management;

  • Torq for SOAR and automation;

  • AWS, including modern environments such as EKS/Kubernetes;

  • An in-house developed Agentic SOC for alert enrichment, correlation, investigation support, reporting, and automation.

AI is at the heart of how we work: investing in AI applied to security is a strategic priority for Ledger this year. We’ve built our own in-house Agentic SOC, which autonomously investigates weak signals—the large volume of unreliable alerts that a human team couldn’t sort through manually—and enriches them, so our engineers can focus on what matters most and resolve incidents faster: high-quality detection, noise reduction, and accelerated investigations.

What you’ll be doing:

As a Staff Security Operations Engineer , you are the SecOps team’s top technical expert and our go-to authority on incident management. You lead the response to the most critical and complex incidents (CSIRT), spearhead proactive threat hunting, and define the detection and response strategy that the entire team relies on. Beyond day-to-day operations, you shape the architecture of our detection pipeline, SIEM, and automation—including the management of our internal Agentic SOC—and you establish the standards, playbooks, and methodologies that raise the technical bar for the entire team. Above all, you’re a builder: beyond design, you’ll build and actively evolve our systems—the Agentic SOC, the log pipeline, and automation—with a solid understanding of the underlying infrastructure. This is an expert role (individual contributor): your impact stems from your expertise, your judgment under pressure, and your influence.

Critical Incident Response (CSIRT)
  • Serve as the primary point of contact and coordinator for the most complex incidents across the cloud, corporate systems, endpoints, identities, and the data center.
  • Conduct end-to-end investigations: root cause analysis, forensics, timeline reconstruction, and remediation recommendations to prevent recurrence.
  • Serve as the team’s go-to expert in incident management, ensuring a rigorous and consistent approach to handling, escalating, and documenting incidents.
Detection Strategy & Threat Hunting
  • Define the team’s detection strategy, architecture, and methodology.
  • Lead proactive threat hunting by leveraging CTI and OSINT to identify and neutralize risks before they impact Ledger.
  • Address the most challenging and emerging detection issues, and translate threat intelligence into concrete improvements in security posture.
Architecture & Agentic SOC
  • Design and optimize the SIEM (Splunk) architecture and SOAR (Torq) workflows that underpin effective detection, triage, and response.
  • Bring our Splunk environment up to standard and state-of-the-art: data quality and standardization (CIM), data models, search performance, and detection governance.
  • Build, evolve, and own the architecture of our internal Agentic SOC and our log/data pipeline, and lead the automation of reporting for the SecOps team.
  • Apply deep expertise in cloud security (AWS, EKS/Kubernetes) and Wiz (CSPM/CNAPP) to harden the cloud and prioritize large-scale exposure.
Technical Leadership & Mentoring
  • Establish the standards, playbooks, and runbooks that the team relies on.
  • Mentor and foster the technical growth of senior and junior engineers, and act as a force multiplier within SecOps.
  • Work with the Engineering, Infrastructure, IT, and Cloud teams to align operational security with the organization’s objectives.
What we’re looking for:
  • 9+ years of experience in security operations, incident response, and CSIRT.
  • A strong track record as a technical expert in incident management, threat hunting, and detection engineering.
  • Comfortable working both as an individual contributor and as a team player in a fast-paced cloud and SaaS environment.
  • In-depth expertise in SIEM (ideally Splunk) and SOAR platforms, as well as CTI/OSINT methodologies.
  • Solid knowledge of AWS security (IAM, audit logs, network configurations, workloads, containers, Kubernetes) and cloud security tools (ideally Wiz, CSPM/CNAPP); experience with an EDR (ideally CrowdStrike).
  • Strong incident response and forensics skills, with the ability to conduct complex end-to-end investigations.
  • The ability to automate tasks and reporting using Python, Bash, APIs, GitHub Actions, a SOAR platform, or equivalent.
  • A solid understanding of infrastructure (cloud, networking, containers, CI/CD) and the ability to build and scale: log/data pipelines, integrations, and internal services.
  • A strong interest—or experience—in AI applied to security operations, agent-based workflows, and SOC automation.
  • Rigor and discipline: You follow and improve established processes and ensure consistency in incident handling and reporting; excellent analytical skills, even under pressure.
  • Clear communication of complex technical concepts to cross-functional teams; ability to document thoroughly and escalate issues with the appropriate level of context; awareness of confidentiality and the proper handling of sensitive information.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Staff Security Operations Engineer in Paris, TX vacancy
  •  ...with over 20% of the world’s crypto assets secured through our Ledger devices. With our...  ...The team You will join the Security Operations team, which is responsible for protecting...  ...through manually—and enriches them, so our engineers can focus on what matters most and resolve... 
    Suggested
    Remote job
    Full time

    Ledger

    Paris, TX
    a month ago
  •  ...facilitating over $1 trillion in crypto transactions. You will operate the Product Security programe for Blockchain.com’s internally-developed...  ...architecture review, own the security debt lifecycle for product engineering teams, and architect the automated pipelines that protect... 
    Suggested
    Full time
    Contract work
    Apprenticeship
    Work at office
    Remote work
    Worldwide

    Blockchain

    Paris, TX
    4 days ago
  •  ...verified users, facilitating over $1 trillion in crypto transactions. You’ll be the hands-on security engineer embedded with the Institutional Trading and Financial Operations (FinOps) team. Your focus is the secure operation of off-chain trading processes and... 
    Suggested
    Full time
    Contract work
    Apprenticeship
    Work at office
    Remote work
    Worldwide

    Blockchain

    Paris, TX
    a month ago
  •  ...Server Job PostingThis job posting is for employment at an independently owned and operated franchisee of Denny's.At Denny's, we love feeding people. If you have a passion for food and serving others, see what your future can hold at Denny's!As a Server, you're the guest... 
    Suggested
    Local area

    Denny

    Paris, TX
    4 days ago
  •  ...food and beverage orders from customers Answer questions about the menu and preparation Provide accurate orders to the kitchen staff Check with customers periodically during their meals to ensure they are satisfied Take orders from customers for food and... 
    Suggested
    Flexible hours

    J&B Heinz LLC

    Paris, TX
    3 days ago
  • Scooter's CoffeeEstablished in 1998, Scooter's Coffee has distinguished itself as one of the premiere specialty coffee companies in the industry. Scooter's Coffee may be one of the fastest-growing specialty coffee brands, but simplicity is at our core: sustainably-sourced...

    Scooter's Coffee

    Reno, TX
    1 day ago
  • €75k - €95k per year

     ...app or API. We are building the full infrastructure: issuing, operating, and distributing the products ourselves. Two years after...  ...talk. We are looking for a Founding Infrastructure & Security Engineer to join Spiko's 8-people engineering team. You will be the first... 
    Full time
    Work at office
    Remote work
    2 days per week

    Spiko

    Paris, TX
    a month ago
  •  ...transactions. We are looking for a Senior Infrastructure Security Engineer with a proven track record in keeping systems safe. You will...  ...product, platform, and infrastructure environments. Identify operational and technical security gaps, propose solutions, and drive... 
    Full time
    Apprenticeship
    Work at office
    Remote work
    Worldwide

    Blockchain

    Paris, TX
    a month ago
  •  ...Guest Service Agent The Guest Service Agent is responsible for processing check-ins/outs, securing payment, verifying and adjusting billing, and assisting guests with reservations and requests in a friendly, professional and timely manner, while following high standards... 

    Peachtree Group

    Paris, TX
    2 days ago
  • Just do it right,make it look easy be open and honest ,don't get in a hurry and most of all don't be afraid to tell me what you like and you will get paid bonuses Please visit to view full details and to apply. Lots of jobs to choose from!

    Housekeeper.com

    Blossom, TX
    3 days ago
  •  ...store customers in donating, selecting and purchasing store items; operates and maintains a cash register; responds to customer questions....  ...cash drawer and runs routine register print-outs; ensures the security and accountability of all cash register funds and sales records... 
    Work at office

    Salvation Army

    Paris, TX
    5 days ago
  •  ...Maintain a positive and friendly attitude, even during busy or challenging situations. Work collaboratively with servers and other staff members to ensure a seamless dining experience. Additional Duties: Assist with other tasks as needed, such as light cleaning,... 

    Shogun Hibachi & Sushi

    Paris, TX
    7 days ago
  • Join the Waffle House Family – Now Hiring Servers! At Waffle House, we're not just in the food business—we're in the people business! We're looking for full-time and part-time servers to join our team immediately across all shifts. Why Work With Us? Since 1955,...
    Weekly pay
    Full time
    Part time
    Immediate start
    All shifts
    Flexible hours
    Shift work
    Night shift
    Weekend work

    Waffle House, Inc.

    Paris, TX
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Operations Engineer. Be the first to apply!