SOC (Security Operations Center), Team Lead

Sumár práce
Plný úväzok
Paris
Niekoľko dní doma
Plat: Neuvedené
Zručnosti & odborná znalosť
Znalosť kybernetickej bezpečnosti
Skenovanie zraniteľností
Spolupráca a tímová práca
Zručnosti pri riešení problémov
Linux
+6

Mistral Ai
Mistral Ai

Máte záujem o túto ponuku?

Otázky a odpovede ohľadne ponuky

Pozícia

Popis pracovnej ponuky

About Mistral 

At Mistral AI, we believe in the power of AI to simplify tasks, save time, and enhance learning and creativity. Our technology is designed to integrate seamlessly into daily working life.

We democratize AI through high-performance, optimized, open-source and cutting-edge models, products and solutions. Our comprehensive AI platform is designed to meet enterprise needs, whether on-premises or in cloud environments. Our offerings include le Chat, the AI assistant for life and work.

We are a dynamic, collaborative team passionate about AI and its potential to transform society.

Our diverse workforce thrives in competitive environments and is committed to driving innovation. Our teams are distributed between France, USA, UK, Germany and Singapore. We are creative, low-ego and team-spirited.

Join us to be part of a pioneering company shaping the future of AI. Together, we can make a meaningful impact. See more about our culture on https://mistral.ai/careers.

Role summary

We are looking for a SOC (Security Operations Center) Team Lead to build and lead our SOC function end-to-end. You will own vulnerability management, alerting and detection engineering, incident response, and the security tooling/infrastructure that enable these missions. You’ll define processes, collaborate closely with Product, Infra and IT, and continuously improve detection quality and response time.

Key missions & objectives: Establish a best-in-class SOC; reduce MTTA/MTTR; drive vulnerability remediation; raise detection coverage and precision; ensure robust incident handling and communication.

Reporting line: Reports to the Head of Security.

Location: Paris (on-site hybrid).

What you will do

Lead & grow the team: Manage the SOC team, shape the roadmap, delegate effectively, and mentor engineers.

Drive operations:

– Define vulnerability management processes and coordinate stakeholders for timely remediation.

– Design, implement, and operate SIEM/SOAR infrastructure (ingestion, normalization, correlation, alerting, playbooks).

– Specify logging requirements across our main stacks and centralize telemetry in the SIEM.

– Develop and tune correlation rules and detections; manage CTI intake and operationalize intel.

– Run continuous improvement to reduce false positives and raise signal quality.

– Establish crisp procedures for alert triage, escalation, and incident handling & investigation.

– Lead incident communications with stakeholders and ensure thorough documentation.

Engineering & enablement:

– Contribute to security tooling, automation, and integrations that speed up detection/response.

– Produce guidance and documentation for product/infra teams; contribute to compliance in the SOC perimeter.

Exercises & assurance: Coordinate red/blue exercises, post-mortems, and targeted audits to validate coverage and resilience.

Who you are

• 5+ years of experience leading SOC/CSIRT functions, with proven incident leadership.

• Hands-on with SIEM (e.g., Elastic Security, Sekoia, Splunk) and SOAR platforms.

• Strong experience in vulnerability management (e.g., DefectDojo, Dependency-Track) and remediation workflows.

• Solid grasp of the cyber kill chain / attack lifecycle, detection engineering, and log source coverage.

• Excellent problem-solving and communication skills; able to operate in a fast-paced startup environment.

• Builder mindset: pragmatic, automation-oriented, comfortable with ambiguity and ownership.

Now, it would be ideal if you… (Nice to have)

• Bring scripting/automation skills (e.g., Python, Bash) for data pipelines/playbooks.

• Know modern infra/app stacks (Linux, containers, Kubernetes, cloud), EDR/IDS/IPS.

• Have exposure to compliance frameworks (ISO 27001, SOC 2) and security audits/pen-tests.

• Have run purple team exercises and measurable detection-coverage programs.

• Are comfortable partnering with Product/Platform teams and influencing roadmaps.

Recruitment process

• Introduction call (30 min)

• Technical Rounds:

- Technical Screen (30 min)

- Technical Round (45 min)

• Hiring Manager (30 min)

• Value talk / Culture fit (30 min)

• References

Location & Remote

The position is based in our Paris HQ offices and we encourage going to the office as much as we can (at least 3 days per week) to create bonds and smooth communication. Our remote policy aims to provide flexibility, improve work-life balance and increase productivity. Each manager can decide the amount of days worked remotely based on autonomy and a specific context (e.g. more flexibility can occur during summer). In any case, employees are expected to maintain regular communication with their teams and be available during core working hours.

What we offer

💰 Competitive salary and equity package

🧑‍⚕️ Health insurance

🚴 Transportation allowance

🥎 Sport allowance

🥕 Meal vouchers

💰 Private pension plan

🍼 Generous parental leave policy

Chcete sa dozvedieť viac?

Tieto pracovné ponuky by vás mohli zaujímať!

Tieto spoločnosti tiež prijímajú pracovníkov na pozíciu "{profesia}".

  • Dataiku

    IT Security Engineer

    Dataiku
    Dataiku
    Plný úväzok
    Paris
    Žiadna práca na diaľku
    Softvér, Umelá inteligencia / Machine Learning
    1 000 zamestnanci