Prinicipal (L3) SOC Analyst
On-siteParis, Île-de-France, France
Job Summary
Act as the Level 3 escalation point for advanced, complex, or high-impact security investigations, providing technical guidance and validation to Level 2 analysts. Lead advanced incident investigations involving scoping, containment, eradication, and remediation recommendations while analyzing malicious activity, adversary tactics, and techniques. Perform in-depth analysis of security events, logs, endpoint telemetry, and network traffic to support threat hunting and proactive analysis based on indicators and attack patterns. Contribute to the continuous improvement of security monitoring strategies, detection logic, and investigation playbooks to reduce false positives and improve detection quality. Support customers from a technical perspective in optimizing their security monitoring capabilities and strengthening their cyber security posture. Document investigation findings, evidence, and timelines clearly, and prepare technical reports for customers and internal stakeholders. Lead and support investigations involving Operational Technology (OT) and Industrial Control Systems environments, including IT/OT convergence scenarios.
Required Qualifications
- Act as the Level 3 escalation point for advanced, complex or high-impact security investigations.
- Support Level 2 analysts during complex investigations, providing technical guidance, validation and direction.
- Perform in-depth analysis of security events, alerts, logs, endpoint telemetry, network traffic and other relevant data sources.
- Lead advanced incident investigations, including scoping, containment, eradication and remediation recommendations.
- Analyse malicious activity, suspicious files, attacker behaviour and adversary TTPs.
- Support customers from a technical perspective in the optimisation, tuning and improvement of their security monitoring capabilities.
- Review and improve SIEM, EDR, NIDS, SOAR and other security tool configurations to reduce false positives and improve detection quality.
- Contribute to the development and refinement of detection use cases, correlation rules, alerting logic and investigation playbooks.
- Support the definition of customer security monitoring strategies based on risk profile, threat landscape and available telemetry.
- Provide technical recommendations to strengthen customer cyber security posture and improve resilience against current and emerging threats.
- Conduct threat hunting and proactive analysis based on indicators, behaviours, intelligence and attack patterns.
- Document investigation findings, evidence, timelines, containment actions and remediation recommendations in a clear and structured manner.
- Prepare and deliver technical reports to customers, partners and internal stakeholders.
- Monitor trusted sources for emerging threats, vulnerabilities and adversary activity relevant to customer environments.
- Contribute to the continuous improvement of SOC processes, procedures, documentation and knowledge base material.
- Support mentoring and technical development of Level 1 and Level 2 analysts where required.
- Lead and support investigations involving Operational Technology (OT) / Industrial Control Systems (ICS) environments, including IT/OT convergence scenarios.
- Analyse security events related to industrial assets and protocols (ex. SCADA systems, DCS, PLCs, HMIs).
- Support incident response activities, in close collaboration with the Group Incident Response Team for complex security incidents, including those impacting IT and OT environments (scoping, containment, eradication, and post-incident analysis).
- Contribute to the development and fine-tuning of OT-specific detection use cases, monitoring strategies and incident response playbooks.
- Collaborate closely with the Group's OT Security Practice, leveraging industrial expertise to enhance SOC monitoring, detection and response capabilities.
- Minimum 2–3 years of experience in a SOC, MDR, incident response, CSIRT or cyber security operations role.
- Proven experience handling complex security incidents and supporting advanced investigations.
- Working knowledge of SIEM, EDR, SOAR, NIDS, DLP and threat intelligence platforms.
- Experience working with threat hunting methodologies and security detection frameworks.
- Experience supporting customers or internal stakeholders with security optimization, detection tuning and cyber security posture improvement.
Desired Qualifications
- Strong hands-on experience in Security Operations Centre or MDR environments.
- Deep operational knowledge of SIEM, EDR, Network Intrusion Detection Systems, SOAR, DLP and related security monitoring technologies.
- Strong experience with security event triage, correlation, investigation and escalation.
- Ability to analyse endpoint, network, identity, cloud and application telemetry in support of complex investigations.
- Experience with SIEM query languages and detection logic, such as KQL, SPL, Sigma or equivalent.
- Experience tuning security controls and detection content to improve alert fidelity and reduce false positives.
- Strong understanding of attacker tactics, techniques and procedures, including MITRE ATT&CK.
- Ability to perform host-based and network-based threat analysis.
- Experience analysing packet captures, endpoint artefacts, logs, scripts, documents and potentially malicious files.
- Strong understanding of incident response lifecycle, including preparation, identification, containment, eradication, recovery and lessons learned.
- Strong understanding of enterprise network architecture, TCP/IP, firewalls, proxies, VPNs, DNS, email security and cloud environments.
- Understanding of security protocols, encryption technologies and common authentication mechanisms.
- Experience supporting customer-facing technical discussions, including investigation reviews, tuning recommendations and posture improvement activities.
- Ability to manage multiple complex incidents and make effective decisions under pressure.
- Strong written and verbal communication skills, with the ability to explain technical findings to both technical and non-technical stakeholders.
- Experience with Microsoft Sentinel, Microsoft Defender, Splunk, QRadar, CrowdStrike, SentinelOne, Palo Alto, Suricata, Zeek, Snort or similar technologies is highly beneficial.
- Experience with cloud security monitoring across Microsoft Azure, AWS or Google Cloud is beneficial.
- Experience with threat hunting, detection engineering or purple team activities is beneficial.
- Ability to produce clear technical documentation, investigation reports and customer-facing recommendations.
- Understanding of OT / ICS environments (SCADA, DCS, PLCs, HMIs, industrial networks).
- Familiarity with industrial protocols (ex. Modbus, OPC, IEC 104, DNP3, etc.) is beneficial.
- Knowledge of OT threat landscape and frameworks (ex. MITRE ATT&CK for ICS).
- Understanding of IT/OT convergence challenges and network segmentation practices (ex. IEC 62443).
- Experience with OT security platforms or NDR (ex. Armis, Nozomi, Clarity, Dragos, Darktrace, etc.) is a plus.
- Security industry certifications such as GCIH, GCFA, GCIA, GNFA, GCTI, GSEC, CISSP, CySA+, SC-200, AZ-500 or equivalent are highly beneficial.
- OT-related certifications or training (ex. GICSP, GRID, IEC 62443) are advantageous.
- Experience supporting industrial or critical infrastructure environments is a plus.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.