SOC Analyst - M/F
Devoteam is a consulting company specializing in technology, cloud, cyber, AI, and sustainable development. With more than 11,000 employees in more than 25 countries, we have been guiding our clients for nearly 30 years through the technological transformation of their businesses. In France, we are 4,500 Digital Architects distributed across more than 50 expertise tribes and coached by more than 400 expert managers. Joining us means: working on innovative and sustainable projects to put Technology at the service of humanity, continuously certifying in new market technologies, and sharing unique moments with colleagues! To discover more about Devoteam, visit here.
Integrated into the Cyber Defense team, you will play a key role in the detection, investigation, and response to security incidents in sensitive environments. Your main missions will be: Supervise and refine the monitoring of security environments (SIEM, EDR, logs, network detections) and ensure advanced qualification of alerts.
Lead complex technical investigations (log analysis, memory, endpoints, network traffic) and produce clear, actionable, and decision-oriented incident reports.
Design, improve, and maintain detection rules, SIEM correlations, hunting queries, dashboards, and automations to strengthen the SOC posture.
Conduct proactive threat hunting campaigns, TTP analysis, and enrichment of IOC/IOA.
Contribute to the evolution of investigation and incident response playbooks (MCDR), and the formalization of SOC processes.
Regularly evaluate detection and response capabilities via simulation exercises, red teaming, and rule tuning.
Collaborate closely with infrastructure, security, and business teams to coordinate containment, eradication, and remediation actions.
Support and upskill junior analysts on technical and methodological aspects.
Graduate of higher education (Master's degree in cybersecurity, computer science, or equivalent), you have significant experience (minimum 3 to 5 years) within a SOC, a CSIRT, or an incident response team.
Solid mastery of SIEM, EDR, IDS/IPS environments and Windows/Linux systems.
Very good understanding of network architectures, protocols, and attack/defense mechanisms.
Comfort in development and scripting (Python, PowerShell, Bash...) to automate detections, enrichments, and responses.
Ability to conduct forensic analyses and to document in a structured and traceable manner.
Fluent English (reading and writing technical reports).
Analytical mindset, rigor, sense of service, and strong autonomy.
Taste for knowledge sharing, technical monitoring, and continuous improvement.
The Devoteam Group works for equal opportunities, for the promotion of its female and male employees based on merit, and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism, and excellence of our organization. All our positions are open to people with disabilities. If you find yourself in this description, do not hesitate to apply!