Ubique Systems

TRCI-26-04901

Cybersecurity Analytics / SIEM Detection Engineer (SOC L2/L3)

Contract role in Paris (occasional remote) for a senior cybersecurity analyst focused on SIEM monitoring, alert qualification, incident investigation/response, vulnerability follow-up, and continuous improvement of detection content. The mission requires strong operational knowledge of Windows and ADDS, systems/networks/storage, and hands-on expertise building, testing, documenting, and optimizing detection rules using SIEM query languages (XQL/SPL/KQL). The consultant will contribute to knowledge capitalization (incident DB, documentation, feedback), automation/SOAR opportunities, threat/vulnerability monitoring, and participate in on-call duties.

Position summary

Location
France
Workplace
On-site
Employment
Contract
Experience
Minimum 7 years and Maximum 15 years
Apply now

Role overview

Why This Role Matters.

Contract role in Paris (occasional remote) for a senior cybersecurity analyst focused on SIEM monitoring, alert qualification, incident investigation/response, vulnerability follow-up, and continuous improvement of detection content. The mission requires strong operational knowledge of Windows and ADDS, systems/networks/storage, and hands-on expertise building, testing, documenting, and optimizing detection rules using SIEM query languages (XQL/SPL/KQL). The consultant will contribute to knowledge capitalization (incident DB, documentation, feedback), automation/SOAR opportunities, threat/vulnerability monitoring, and participate in on-call duties.

Your Impact

Deliver Enterprise Value

Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.

Collaboration

Work Across Teams

Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.

Growth

Learn Continuously

Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.

Career Path

Grow With Ubique

Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.

Responsibilities

What You'll Be Doing.

Every role at Ubique contributes directly to solving meaningful business challenges for our clients.

01

Documented qualification of security events and alerts from monitoring tools and SIEM solutions.

02

Investigation, analysis and handling of incidents, with follow-up of resolution actions and coordination of stakeholders.

03

Monitoring and management of identified vulnerabilities, with assessment of their impact and prioritization of actions.

04

Design and implement new detection rules adapted to newly identified threats and vulnerabilities.

05

Continuous improvement of existing rules to reduce false positives and increase the relevance of detections.

06

Perform validation tests before deploying the rules, including verification of their effectiveness and coverage.

07

Drafting of detailed documentation specifying the purpose, operation, triggering conditions and maintenance procedures of each rule.

08

Production of feedback, enrichment of the incident database and identification of opportunities for automation or SOAR orchestration.

09

Contribution to technology watch, threat analysis and vulnerability monitoring.

10

Participation in the team's on-call duties according to the terms and conditions defined by the organization.

Technology stack

Tools & Technologies.

The platforms and technologies you'll use to build modern, enterprise-grade solutions.

01

SIEM

02

SOAR

03

XQL

04

SPL

05

KQL

06

Windows

07

Active Directory

08

ADDS

09

incident response

10

SOC

11

detection engineering

12

use case development

13

alert triage

14

forensics

15

pentest

16

vulnerability management

17

security monitoring

18

shell scripting

Requirements

Skills & Experience.

We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.

Essential

Required Qualifications

SIEM operations (monitoring, alert triage/qualification, event investigation)

Security incident handling / incident response (investigation, coordination, follow-up to resolution)

Detection rule engineering (design, development, optimization, false-positive reduction)

SIEM query languages (XQL and/or SPL and/or KQL)

Windows security administration and security monitoring

Active Directory Domain Services (ADDS) security knowledge

Systems, networks, and storage operational knowledge

Vulnerability monitoring/management (impact assessment, prioritization)

Validation/testing of detection rules before deployment

Technical documentation for detection rules (purpose, triggers, maintenance)

Preferred

Nice to Have

SOAR / security automation tooling

Forensics

Penetration testing

Threat intelligence / technology watch

Audiovisual environment experience

Scripting/programming (shell/scripts)

On-call / pager duty participation

What you'll gain

More Than Just A Job.

We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.

Global Exposure

Collaborate with international clients and multicultural teams on enterprise programmes.

Continuous Learning

Expand your expertise through mentoring, certifications and hands-on project experience.

Career Growth

Take ownership, develop leadership skills and grow your consulting career over time.

Flexible Working

Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.

People First

Join a supportive culture where collaboration, respect and long-term relationships come first.

Enterprise Projects

Work on meaningful technology initiatives for leading organisations across industries.

Apply

Apply for Cybersecurity Analytics / SIEM Detection Engineer (SOC L2/L3)

One page, about two minutes. We only ask for what we actually need to have a first conversation.

Your CV

Optional. A line or two is plenty.