SOC (Security Operations Center), Team Lead
il y a 2 semaines
About Mistral
At Mistral AI, we believe in the power of AI to simplify tasks, save time, and enhance learning and creativity. Our technology is designed to integrate seamlessly into daily working life.
We democratize AI through high-performance, optimized, open-source and cutting-edge models, products and solutions. Our comprehensive AI platform is designed to meet enterprise needs, whether on-premises or in cloud environments. Our offerings include le Chat, the AI assistant for life and work.
We are a dynamic, collaborative team passionate about AI and its potential to transform society.
Our diverse workforce thrives in competitive environments and is committed to driving innovation. Our teams are distributed between France, USA, UK, Germany and Singapore. We are creative, low-ego and team-spirited.
Join us to be part of a pioneering company shaping the future of AI. Together, we can make a meaningful impact. See more about our culture on
Role summary
We are looking for a SOC (Security Operations Center) Team Lead to build and lead our SOC function end-to-end. You will own vulnerability management, alerting and detection engineering, incident response, and the security tooling/infrastructure that enable these missions. You'll define processes, collaborate closely with Product, Infra and IT, and continuously improve detection quality and response time.
Key missions & objectives: Establish a best-in-class SOC; reduce MTTA/MTTR; drive vulnerability remediation; raise detection coverage and precision; ensure robust incident handling and communication.
Reporting line: Reports to the Head of Security.
Location: Paris (on-site hybrid).
What You Will Do
- Lead & grow the team: Manage the SOC team, shape the roadmap, delegate effectively, and mentor engineers
- Drive operations:
– Define vulnerability management processes and coordinate stakeholders for timely remediation.
– Design, implement, and operate SIEM/SOAR infrastructure (ingestion, normalization, correlation, alerting, playbooks).
– Specify logging requirements across our main stacks and centralize telemetry in the SIEM.
– Develop and tune correlation rules and detections; manage CTI intake and operationalize intel.
– Run continuous improvement to reduce false positives and raise signal quality.
– Establish crisp procedures for alert triage, escalation, and incident handling & investigation.
– Lead incident communications with stakeholders and ensure thorough documentation.
- Engineering & enablement:
– Contribute to security tooling, automation, and integrations that speed up detection/response.
– Produce guidance and documentation for product/infra teams; contribute to compliance in the SOC perimeter.
- Exercises & assurance: Coordinate red/blue exercises, post-mortems, and targeted audits to validate coverage and resilience
Who You Are
- 5+ years of experience leading SOC/CSIRT functions, with proven incident leadership
- Hands-on with SIEM (e.g., Elastic Security, Sekoia, Splunk) and SOAR platforms
- Strong experience in vulnerability management (e.g., DefectDojo, Dependency-Track) and remediation workflows
- Solid grasp of the cyber kill chain / attack lifecycle, detection engineering, and log source coverage
- Excellent problem-solving and communication skills; able to operate in a fast-paced startup environment
- Builder mindset: pragmatic, automation-oriented, comfortable with ambiguity and ownership
Now, it would be ideal if you…
(Nice to have)
- Bring scripting/automation skills (e.g., Python, Bash) for data pipelines/playbooks
- Know modern infra/app stacks (Linux, containers, Kubernetes, cloud), EDR/IDS/IPS
- Have exposure to compliance frameworks (ISO 27001, SOC 2) and security audits/pen-tests
- Have run purple team exercises and measurable detection-coverage programs
- Are comfortable partnering with Product/Platform teams and influencing roadmaps
Recruitment process
- Introduction call (30 min)
- Technical Rounds:
- Technical Screen (30 min)
- Technical Round (45 min)
- Hiring Manager (30 min)
- Value talk / Culture fit (30 min)
- References
Location & Remote
This role is primarily based at one of our European offices (Paris and London). We will prioritize candidates who either reside there or are open to relocating. We strongly believe in the value of in-person collaboration to foster strong relationships and seamless communication within our team. Our remote work policy is designed to offer flexibility, enhance work-life balance, and boost productivity.
In certain specific situations, we will also consider remote candidates based in one of the countries listed in this job posting (currently France & UK). In that case, we ask all new hires to visit our local office:
- for the first week of their onboarding (accommodation and travelling covered)
- then at least 3 days per month
What we offer
Competitive salary and equity
Health insurance
Transportation allowance
Sport allowance
Meal vouchers
Private pension plan
Parental : Generous parental leave policy
Visa sponsorship
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
-
SOC (Security Operations Center), Team Lead
il y a 2 semaines
Paris, Île-de-France Mistral AI Temps pleinAbout Mistral At Mistral AI, we believe in the power of AI to simplify tasks, save time, and enhance learning and creativity. Our technology is designed to integrate seamlessly into daily working life. We democratize AI through high-performance, optimized, open-source and cutting-edge models, products and solutions. Our comprehensive AI platform is designed...
-
Team Lead, SOC
il y a 4 jours
Paris, Île-de-France Mistral AI Temps pleinAbout Mistral At Mistral AI, we believe in the power of AI to simplify tasks, save time, and enhance learning and creativity. Our technology is designed to integrate seamlessly into daily working life. We democratize AI through high-performance, optimized, open-source and cutting-edge models, products and solutions. Our comprehensive AI platform is...
-
Team Lead, SOC
il y a 2 jours
Paris, Île-de-France Mistral Ai Temps pleinAbout Mistral At Mistral AI, we believe in the power of AI to simplify tasks, save time, and enhance learning and creativity. Our technology is designed to integrate seamlessly into daily working life. We democratize AI through high-performance, optimized, open-source and cutting-edge models, products and solutions. Our comprehensive AI platform is designed...
-
Security Solutions Operations Lead
il y a 4 jours
Paris, Île-de-France Capital Fund Management (CFM) Temps pleinABOUT THE POSITIONCFM is gearing up for a transformative year as we head into 2025, marking a significant acceleration for our company.To meet the evolving demands of the research department, we are dedicated to making substantial investments in cutting-edge technological initiatives. The meaningful integration of advanced technologies, such as generative AI...
-
Email security Expert
il y a 4 jours
Paris, Île-de-France AXA Group Operations Temps pleinAbout AXAAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of respect, for each other, for our...
-
SOC Detection Expert
il y a 2 semaines
Paris, Île-de-France AXA France Temps pleinJob Description:About the jobJob purposeSecurity Operations Center (SOC) delivers the following capabilities to the AXA entities around the globe: Security Incident Detection, Threat Hunting, Security Incident Response and Threat Intelligence.Highly skilled SOC Detection Expert with a deep understanding of detection engineering is responsible for designing,...
-
Senior SOC Analyst
il y a 2 jours
Paris, Île-de-France SERMA Safety and Security Temps pleinCompany DescriptionSERMA Safety and Security, established in 2015, is a leading authority in ensuring the security and safety of products and systems. With expertise spanning cybersecurity, security evaluation, functional safety, and formal methods, the company delivers comprehensive consulting and evaluation services across the entire lifecycle of...
-
Agile Security Risk Consultant
il y a 3 jours
Paris, Île-de-France AXA Group Operations Temps pleinAbout AXAAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of respect, for each other, for our...
-
Cyber Security Operations Officer
il y a 2 jours
Paris, Île-de-France EUROAPI Temps pleinJoin the team IT Services to contribute to Euroapi's performance by implementing the digital transformation of our production sites and support functions. You will support our growth by providing best-of-breed systems, IT support, effective analysis and reporting platforms.The Cyber Security Operations Officer plays a key role in ensuring the operational...
-
Mainframe Security Lead W/M
il y a 2 semaines
Paris, Île-de-France AXA Temps pleinAbout AXAAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of respect, for each other, for our...