Skip to main content
Solidgate

SOC L2/L3 Engineer

RemoteEUEurope
Published
Role
Security
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to Anywhere in EU & Europe. Set where you work from to check your eligibility.

No BS summary

L2/L3 SOC Engineer with 3+ years of experience in detection and response, SIEM building/operation, and detection engineering. Must be proficient in KQL/SPL, cloud logging (AWS, Google Workspace, EDR/XDR), and scripting (Python). Understanding of attacker techniques and structured investigation processes is required.

Core skills

SIEMDetection EngineeringIncident Response

Required skills

KQLSPLPython

Optional skills

SOARdetection-as-codeUEBAthreat intelligence enrichmentalert contextualizationCDE monitoringSwiftPCI DSS

Required languages

English

What you'll do

  • Build and operationalize the SIEM from PoC to production - including case management and UEBA, with full ownership of the technology selection
  • Design, write, and tune detection rules mapped to MITRE ATT&CK, covering identity compromise, privilege escalation, lateral movement, and endpoint threats
  • Triage and investigate L2/L3 alerts, reduce false positives, and establish clear escalation paths for each use case
  • Lead incident response and basic forensics - containment, eradication, and structured lessons learned
  • Onboard log sources across AWS, JumpCloud, Google Workspace, CDE, and SWIFT
  • Run threat hunts based on realistic attack hypotheses specific to a payment platform's risk profile
  • Build and maintain runbooks and playbooks; automate repetitive actions via SOAR or scripting
  • Define SOC metrics and own monthly reporting to management on detection coverage and response performance

What they require

  • 3+ years in SOC / Detection & Response at L2/L3 level, with hands-on investigation experience
  • Practical experience building or operating a SIEM, including writing and tuning detection rules
  • Detection engineering with MITRE ATT&CK mapping; confident with KQL, SPL, or equivalent query languages
  • Experience investigating cloud log sources: AWS CloudTrail, GuardDuty, Google Workspace, EDR/XDR
  • Scripting and automation skills (Python or similar) for telemetry processing and routine tasks
  • Solid understanding of attacker techniques and how they manifest in logs - not just tool knowledge, but threat understanding
  • Structured under pressure: disciplined investigation process, clear documentation, clean post-mortems

Benefits

  • You'll own the Security Operations direction at Solidgate - this isn't a slot in someone else's SOC, it's yours to build
  • Real data, real threats - a fintech processing millions of transactions is a genuinely complex detection environment, not a sandbox
  • You'll choose the stack: SIEM, SOAR, detection framework - your decisions will shape how Solidgate detects threats for years
  • Direct path to leading the SOC function and growing the team as the company scales
  • Hands-on experience at the intersection of cloud-native infrastructure, IR, and detection engineering in a regulated environment - a combination rare outside large enterprises
  • Impactful work: you're monitoring and defending financial infrastructure that processes millions of real payments. What you detect and respond to directly affects the company's risk profile and the businesses relying on the platform.
  • Creative freedom: the SOC is greenfield. No inherited SIEM, no legacy detection rules, no alert fatigue from someone else's misconfigured use cases. You build the detection stack from scratch and own every decision in it.
  • Career growth: a realistic path to leading the Security Operations function within 6-12 months, with direct collaboration with a CISO who came up through the technical side. Want to go deeper into cloud detection, threat intelligence, or automation? That door is open.
  • Ownership culture: you own the detection lifecycle end to end - log onboarding, use case design, triage, response, and reporting. No hand-offs, no findings that disappear into a backlog.
  • People worth working with: a senior InfoSec team that takes security seriously and treats detection gaps as engineering problems worth solving. Smart, experienced teammates who raise the bar and actually have each other's backs.
  • 30+ days off, unlimited sick leave, free office meals, health coverage, and Apple gear to keep you productive.
  • Courses, conferences, sports and wellness benefits — all designed for ideas, focus, and fun.

Solidgate is a payments orchestration platform and financial infrastructure provider for modern internet businesses.

FintechStartup
Salary not disclosed