Live opening · Posted 17 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
act digital is an international consulting and engineering group that supports its clients in their digital transformation projects.
Present in 12 countries and with more than 7,000 employees, we leverage our expertise to address their challenges in software development, cybersecurity, data, cloud, and AI.
Our ambition: to become the trusted technology partner of the most innovative companies, by designing and securing systems that enhance their performance and resilience.
Joining act digital means becoming part of an agile and committed organization that works closely with its clients to turn ideas into concrete results, with pragmatism and high standards.
POSTE / MISSIONS
You will join our team of experts in cybersecurity.
Your responsibilities will include:
Monitor, triage, and investigate alerts across Microsoft security tools, AWS, SIEM platforms, and EDR solutions
Analyze network and host-based logs (firewalls, NIDS/HIDS, syslog, etc.) to determine appropriate remediation and escalation
Identify root causes, direct remediation and recovery actions, and support incident response efforts
Follow structured analytical processes and collaborate with other analysts and teams to ensure effective threat management
Prepare and present security reports, summaries, and findings to clients
Contribute to the improvement of CSOC processes and procedures, including quality control procedures, documentation and knowledge base updates
Gather the necessary information from the client to identify opportunities for whitelist tuning and optimization to reduce false positives and enhance detection quality
Reviewing feedback and implementing corrective actions to maintain service excellence
Provide other ad hoc support as required
PROFIL RECHERCHÉ
What profile are we looking for this position:
Must-have skills :
A minimum of five years of relevant experience in information technology field, including triage of alerts and supporting security incidents
Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs), able to autonomously perform technical analysis of security threats and collaborate with Incident Response team
Trouble ticket generation and processing experience
Expert knowledge of Windows, Linux, Database, Application, Web server, etc. log analysis
Knowledge of Transmission Control Protocol / Internet Protocol (TCP/IP) protocols
Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR
Deep knowledge of Cloud technologies (e.g. Azure, AWS and GCP)
Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack
Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)
Knowledge of email security, network monitoring, and incident response
Knowledge of Linux/Mac/Windows
Expert knowledge of English, both written and spoken, is required
Nice to have :
Experience on an Incident Response team performing Tier I/II initial incident triage.
Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)
Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.)
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.