Ledger - Senior Security Operations Engineer
Requirements
• Solid & proven experience in SecOps, SOC, cloud security, incident response, or infrastructure security, with a track record of building and improving SOC capabilities (logs, detections, dashboards, automations, runbooks, workflows) and conducting independent investigations. • Comfortable working in cloud and SaaS environments and with rapidly evolving technologies. • Proficiency in SecOps fundamentals: triage, investigation, incident response, log analysis, and documentation. • Strong, hands-on cloud security skills (ideally AWS): investigating IAM and identity activity, analyzing cloud audit logs (e.g. CloudTrail, GuardDuty), securing workloads, containers, and Kubernetes (EKS), and scoping cloud incidents end-to-end. Comfortable with exposure/CSPM tooling (ideally Wiz). • SIEM (ideally Splunk) with the ability to write queries for investigation and detection; EDR (ideally CrowdStrike). • Automation using Python, Bash, APIs, GitHub Actions, SOAR, or equivalent. • Interest in—or experience with—AI applied to security, agent-based workflows, and SOC automation. • Diligence, independence, technical curiosity, and attention to detail. • Ability to conduct in-depth investigations, document findings clearly, and escalate issues with the appropriate level of context; awareness of confidentiality and the proper handling of sensitive information. • Professional-level English; Ledger operates in an international environment.
Responsibilities
• As a Senior Security Operations Engineer, you are at the heart of the SOC: you lead investigations from start to finish, manage the lifecycle of detections, dashboards, and automations, and continuously expand our visibility (cloud, endpoints, identities, SaaS, infrastructure). You work independently on complex issues, decide on the next steps - investigation, containment, remediation, or escalation - serve as a technical resource and point of escalation for more junior analysts (whose work you review and with whom you share your knowledge), and make a tangible contribution to improving our internal Agentic SOC. • Senior Security Operations Engineer • Operate the SOC • Operate the SOC • Analyze, classify, and prioritize alerts (from Splunk, CrowdStrike, Wiz, AWS, and other sources), and conduct in-depth investigations into incidents affecting endpoints, the cloud, identities, SaaS, workloads, and infrastructure. • Provide clear, actionable context to inform next steps, and serve as an escalation point for less experienced analysts. • Leverage the Agentic SOC, which investigates weak signals and enriches alerts, so you can focus your time on the incidents that matter. • Visibility & Detection • Build and tune cloud detection use cases (AWS, IAM activity, EKS/Kubernetes, container workloads), and use Wiz to track and prioritize cloud exposure as part of your detection work. • Integrate and maintain the necessary log sources (cloud, endpoints, identities, SaaS, infrastructure, Kubernetes) and improve data quality: completeness, parsing, normalization, relevance, and usability. • Identify visibility blind spots and work with the IT, Cloud, Infrastructure, and Engineering teams to reduce them. • Design, write, and optimize Splunk queries; develop new detection use cases based on available logs, refine them, and document their logic; reduce noise and improve signal quality. • Incident Response • Incident Response • Play a leading role in investigations: gathering evidence, reconstructing timelines, and documenting actions taken. • Monitor containment, remediation, and post-incident measures. • Turn lessons learned into sustainable improvements and formalize processes: detection mechanisms, runbooks, dashboards, and automations. • Contribute to automation and our Agentic SOC • Build and maintain automations (Torq/SOAR, scripts, APIs) that accelerate triage, enrichment, and response. • Contribute to the design and continuous improvement of the internal Agentic SOC—the AI system that investigates weak signals, enriches alerts, and assists with investigations—and expand its capabilities: new investigation workflows, better correlation, and tighter integration with detection and response.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT