TRCI-26-04901
Cybersecurity Analytics / SIEM Detection Engineer (SOC L2/L3)
Contract role in Paris (occasional remote) for a senior cybersecurity analyst focused on SIEM monitoring, alert qualification, incident investigation/response, vulnerability follow-up, and continuous improvement of detection content. The mission requires strong operational knowledge of Windows and ADDS, systems/networks/storage, and hands-on expertise building, testing, documenting, and optimizing detection rules using SIEM query languages (XQL/SPL/KQL). The consultant will contribute to knowledge capitalization (incident DB, documentation, feedback), automation/SOAR opportunities, threat/vulnerability monitoring, and participate in on-call duties.
Position summary
- Location
- France
- Workplace
- On-site
- Employment
- Contract
- Experience
- Minimum 7 years and Maximum 15 years
Role overview
Why This Role Matters.
Contract role in Paris (occasional remote) for a senior cybersecurity analyst focused on SIEM monitoring, alert qualification, incident investigation/response, vulnerability follow-up, and continuous improvement of detection content. The mission requires strong operational knowledge of Windows and ADDS, systems/networks/storage, and hands-on expertise building, testing, documenting, and optimizing detection rules using SIEM query languages (XQL/SPL/KQL). The consultant will contribute to knowledge capitalization (incident DB, documentation, feedback), automation/SOAR opportunities, threat/vulnerability monitoring, and participate in on-call duties.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Investigation, analysis and handling of incidents, with follow-up of resolution actions and coordination of stakeholders.
Monitoring and management of identified vulnerabilities, with assessment of their impact and prioritization of actions.
Design and implement new detection rules adapted to newly identified threats and vulnerabilities.
Continuous improvement of existing rules to reduce false positives and increase the relevance of detections.
Perform validation tests before deploying the rules, including verification of their effectiveness and coverage.
Drafting of detailed documentation specifying the purpose, operation, triggering conditions and maintenance procedures of each rule.
Production of feedback, enrichment of the incident database and identification of opportunities for automation or SOAR orchestration.
Contribution to technology watch, threat analysis and vulnerability monitoring.
Participation in the team's on-call duties according to the terms and conditions defined by the organization.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
SIEM
SOAR
XQL
SPL
KQL
Windows
Active Directory
ADDS
incident response
SOC
detection engineering
use case development
alert triage
forensics
pentest
vulnerability management
security monitoring
shell scripting
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
SIEM operations (monitoring, alert triage/qualification, event investigation)
Security incident handling / incident response (investigation, coordination, follow-up to resolution)
Detection rule engineering (design, development, optimization, false-positive reduction)
SIEM query languages (XQL and/or SPL and/or KQL)
Windows security administration and security monitoring
Active Directory Domain Services (ADDS) security knowledge
Systems, networks, and storage operational knowledge
Vulnerability monitoring/management (impact assessment, prioritization)
Validation/testing of detection rules before deployment
Technical documentation for detection rules (purpose, triggers, maintenance)
Preferred
Nice to Have
SOAR / security automation tooling
Forensics
Penetration testing
Threat intelligence / technology watch
Audiovisual environment experience
Scripting/programming (shell/scripts)
On-call / pager duty participation
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Cybersecurity Analytics / SIEM Detection Engineer (SOC L2/L3)
One page, about two minutes. We only ask for what we actually need to have a first conversation.