You’ll join the Security Operations team, responsible for protecting Ledger’s corporate, cloud, SaaS, and data center environments. Its mission: to anticipate, detect, investigate, and respond to cyber threats—including monitoring, alert triage, incident response, detection, visibility, automation, exposure tracking, and continuous process improvement. The scope is distinct from that of the Donjon (product security): SecOps covers the operational security of internal environments, the cloud, endpoints, workloads, identities, and infrastructure.
As a close-knit and experienced team—technically demanding and committed to knowledge sharing—we’re also continuously building the SOC itself: integrating new log sources, ensuring data quality, expanding detection coverage, and developing reliable dashboards and operational workflows.
Our technical stack includes:
•
Splunk for SIEM, investigations, and dashboards;
•
CrowdStrike for EDR and endpoint/workload security;
•
Wiz for cloud security and exposure management;
•
Torq for SOAR and automation;
•
AWS, including modern environments such as EKS/Kubernetes;
•
An in-house developed Agentic SOC for alert enrichment, correlation, investigation support, reporting, and automation.
AI is at the heart of how we work: investing in AI applied to security is a strategic priority for Ledger this year. We’ve built our own in-house Agentic SOC, which autonomously investigates weak signals—the large volume of unreliable alerts that a human team couldn’t sort through manually—and enriches them, so our engineers can focus on what matters most and resolve incidents faster: high-quality detection, noise reduction, and accelerated investigations.
As a Staff Security Operations Engineer, you are the SecOps team’s top technical expert and our go-to authority on incident management. You lead the response to the most critical and complex incidents (CSIRT), spearhead proactive threat hunting, and define the detection and response strategy that the entire team relies on. Beyond day-to-day operations, you shape the architecture of our detection pipeline, SIEM, and automation—including the management of our internal Agentic SOC—and you establish the standards, playbooks, and methodologies that raise the technical bar for the entire team. Above all, you’re a builder: beyond design, you’ll build and actively evolve our systems—the Agentic SOC, the log pipeline, and automation—with a solid understanding of the underlying infrastructure. This is an expert role (individual contributor): your impact stems from your expertise, your judgment under pressure, and your influence.