CareerPlanSign in

SOC L2/L3 Engineer

Europe💼 Full-time🗓 2026-06-02 → 2026-09-26

Core

Build and operationalize a SIEM from PoC to production, design detection rules mapped to MITRE ATT&CK, triage L2/L3 alerts, and lead incident response for a payments orchestration platform.

Role type

SOC L2/L3 Engineer (Detection & Response)

Builds

SIEM, detection rules, incident response playbooks, and automated telemetry processing pipelines

Domain

Fintech / Payments Orchestration / Cybersecurity

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

SIEM operation and tuning, MITRE ATT&CK mapping, KQL/SPL query languages, cloud log investigation (AWS, Google Workspace, EDR/XDR), Python scripting, threat hunting, incident response, runbook creation

Preferred skills

SOAR implementation, detection-as-code, UEBA, threat intelligence enrichment, purple teaming, payment-specific environment knowledge (CDE, SWIFT, PCI DSS)

Technologies

SIEM, SOAR, AWS CloudTrail, GuardDuty, Google Workspace, JumpCloud, CDE, SWIFT

Responsibilities

Build and operationalize the SIEM from PoC to production; Design, write, and tune detection rules mapped to MITRE ATT&CK; Triage and investigate L2/L3 alerts; Lead incident response and basic forensics; Onboard log sources across AWS, JumpCloud, Google Workspace, CDE, and SWIFT; Run threat hunts based on realistic attack hypotheses

Seniority

Mid-level, hands-on IC

Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.