Skip to content

Open nowPosted 59 days ago

Security Operations Engineer – Remote-First

epicompany12 open roles

Where
Paris, France; Berlin, Germany; Madrid, Spain
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Operations Engineer – Remote-Firstepicompany · Paris, France; Berlin, Germany; Madrid, Spain
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on epicompany's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. epicompany postings stay open a median of 1 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 59 days ago

epicompany median: 1 days open

The posting

🚀 Be part of a movement to change the way Europe pays

In today’s digital Europe, payments still feel too complicated. Random delays, confusing rules, extra apps and accounts make it harder than it should be to pay and get paid.

The European Payments Initiative is changing that with Wero, a proudly European digital wallet to make payments easier, clearer and more secure. Online, in store, at home and across borders, with your money and data protected under European laws and regulations.

Wero is live in Belgium, France, Germany and the Netherlands and launching very soon in Luxembourg and Austria. Backed by 17 major banks and the two largest European acquirers, we’re building a brand new, proudly European payment system. Why not join us?

🔎 What's in it for you

Play a key role in protecting Europe’s next-generation payment infrastructure. As an Operations Security Engineer, you will be at the heart of EPI’s Security Operations capability: triaging alerts, responding to incidents, improving detection coverage and proactively hunting for threats across cloud, identity, endpoint and application environments.

This is a high-impact opportunity to combine hands-on SOC expertise, threat hunting and detection engineering in a remote-first, pan-European company where security directly supports the resilience and trust of Wero.

🐝 About the team

You’ll join the Security Operations team within Operations Services Delivery. The team brings together highly skilled security profiles, including SOC, IAM, general security, threat hunting and penetration testing expertise.

You’ll collaborate closely with Security, Engineering, DevOps, IT and Operations teams to strengthen detection and response capabilities, improve tooling and ensure strong visibility across our environments. This role is ideal for someone who enjoys hands-on investigation, structured incident response and clear communication with both technical and non-technical stakeholders.

💥 Your impact

  • Act as a central point of contact for alert triage, incident identification and security event investigation across EPI environments.
  • Execute incident response activities using structured frameworks such as SANS PICERL, from preparation and identification through containment, eradication, recovery and lessons learned.
  • Conduct proactive, hypothesis-driven threat hunts based on attacker behaviour, emerging threats, threat intelligence and MITRE ATT&CK techniques.
  • Parse, analyse and correlate logs from authentication, application, system, endpoint and cloud telemetry sources, including AWS and Azure.
  • Design, tune and maintain detection rules, use cases, dashboards, custom alerts and automation workflows to identify anomalies, lateral movement and persistent threats.
  • Contribute to the development and continuous improvement of SOC playbooks, runbooks, SIEM and EDR integrations.
  • Document and communicate threat findings, incident outcomes and remediation recommendations clearly to technical and non-technical stakeholders.
  • Collaborate with engineering, SOC, IR and IT teams to improve detection coverage, response readiness and operational resilience.

💻 Technology stack & way of working

  • Primary security tools: Rapid7, Microsoft Defender, SIEM and EDR technologies
  • Cloud, identity & operations: AWS, Azure, Microsoft Entra ID, Okta, PagerDuty
  • Scripting, querying & automation: Python, PowerShell, KQL, custom alerting and auto-remediation workflows
  • Collaboration & delivery: Jira, Confluence, GitHub

🕵🏻‍♀️ To succeed, you should meet at least 70% of these requirements

  • +8 years of experience in cybersecurity, with strong hands-on experience as a SOC analyst, incident responder, detection engineer or similar role.
  • Fluent in English (CEFR C1 or C2); French, German, Dutch or other European languages are a plus.
  • Thrive in a remote-first, multicultural and fast-paced environment.
  • Strong familiarity with the full SOC lifecycle, from Tier 1 to Tier 3, including alert triage, incident response, threat hunting and threat intelligence.
  • Proven experience in threat hunting, detection engineering or threat intelligence, with the ability to turn attacker behaviours into actionable detections.
  • Solid understanding of SIEM and EDR technologies, log parsing, detection engineering and alert tuning.
  • Hands-on experience with scripting and querying tools such as Python, PowerShell or KQL to support automation, investigations and custom alerting.
  • Ability to analyse and correlate logs from diverse sources, including authentication, application, system and cloud telemetry across AWS and Azure.
  • Knowledge of attacker TTPs, MITRE ATT&CK, threat exposure and attack path analysis.
  • Experience creating or improving incident response playbooks, runbooks and automation workflows.
  • Strong communication skills, with the ability to explain technical findings and security risks clearly to both technical and non-technical stakeholders.
  • Willingness to participate in a 24/7 on-call rotation, approximately one week per month, to support incident response and operational continuity.

Nice to haves

  • Experience with Rapid7 and with TaHiTI.
  • Familiarity with Microsoft Entra ID and its integration into detection and response workflows.
  • Nice-to-have certifications such as GSEC, GCIH, BTL1/2, SC-200 or AZ-500.
  • Experience in payments, banking, fintech or another highly regulated environment.

🪜 If this looks like you, the recruitment steps are:

  1. A first call with one of our recruiters
  2. A technical interview with our CISO and a security expert
  3. A final interview with our COO
  4. Hopefully, an offer you can’t refuse

⛔ Turn back if …

  • You prefer a purely reactive SOC role where you only handle out-of-the-box alerts and escalations.
  • You don’t enjoy digging into logs, building queries, tuning detections or investigating ambiguous signals across distributed systems.
  • You are looking for a role with no on-call responsibilities or no operational incident response exposure.
  • You prefer working in isolation rather than collaborating with engineering, DevOps, IT and business stakeholders.

🎁 What we can offer

  • Remote-first culture with quarterly and annual all-staff in-person meetups to keep teams connected and collaborative
  • Possibility to work from another EU country for up to 3 months per year
  • Competitive compensation package, featuring salary, performance-based bonus and a thoughtfully designed, high-quality benefits programme
  • The opportunity to be part of a true pan-European company
  • Learning & development budget: €5,000 training budget per year

Otherwise apply!

🫶 Our commitment to equal employment opportunities

EPI offers the same job opportunities to all, without distinction of gender, ethnicity, religion, sexual orientation, social status, disability or age. EPI promotes the development of an inclusive work environment that mirrors the diversity of the clients our product is serving.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against epicompany's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on epicompany's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    epicompany's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.