Mid-Level
About Sopra Steria Sopra Steria, a major Tech player in Europe with 51,000 employees in nearly 30 countries, is recognised for its consulting, digital services and solutions. It helps its clients drive their digital transformation and obtain tangible and sustainable benefits. The Group provides end-to-end solutions to make large companies and organisations more competitive by combining in-depth knowledge of a wide range of business sectors and innovative technologies with a collaborative approach. Sopra Steria places people at the heart of everything it does and is committed to putting digital to work for its clients in order to build a positive future for all. In 2025, the Group generated revenues of €5.6 billion. The world is how we shape it.
About the Role
We're looking for a Cloud Security Engineer with a strong incident response background to join our security team. You'll be on the front lines detecting, investigating, and remediating security events across our cloud infrastructure and endpoints.
What You'll Do
Lead end-to-end incident response: triage, containment, investigation, and post-incident review
Hunt for threats and investigate alerts using CrowdStrike Falcon (EDR, threat intelligence, and OverWatch)
Build and tune detection logic in Splunk — write SPL queries, create dashboards, and maintain alert fidelity
Audit and investigate events in AWS CloudTrail, CloudWatch, and native AWS security services (GuardDuty, Security Hub, Config)
Correlate signals across endpoint, network, and cloud layers to establish attack timelines
Document findings and produce clear incident reports for both technical and non-technical audiences
Contribute to runbooks, playbooks, and continuous improvement of the IR program
What You Bring
3+ years in a security engineering, SOC, or incident response role
Hands-on experience with CrowdStrike (investigation workflows, RTR, detections tuning)
Proficiency in Splunk — SPL, data onboarding, and building actionable dashboards
Solid understanding of AWS IAM, CloudTrail log structure, and cloud-native audit trails
Familiarity with attacker TTPs (MITRE ATT&CK) and how they map to cloud environments
Ability to communicate technical findings clearly under pressure
Nice to Have
GCIH, GCFE, AWS Security Specialty, or similar certifications
Experience with IaC security tooling (Terraform, CloudFormation scanning)
Scripting ability in Python or Bash for automation and log parsing
Total Experience Expected: 04-06 years
B.E/B.TECH/MCA (Computer Science/Electronics and related branches only)
Job requires working in shifts with standby/On-call support on weekends/out of business hours.
At our organization, we are committed to fighting against all forms of discrimination. We foster a work environment that is inclusive and respectful of all differences.
All of our positions are open to people with disabilities.
Sign up to apply and find out right away if you're a fit.
Your agent will tell you — in seconds.
Sign up and I'll tell you right away how well Sopra Steria matches you — what you already have, and what's missing. Then I stay on it: I search for you and only write when I find something worth your time.