Enter a job title or keyword

SOC Team Lead (MFX)

Equans


Job Location:

Courbevoie - France

Monthly Salary: Not provided by the employer
Posted: 23 July 2026 (30+ days ago)
Application Deadline: 3 November 2026
Vacancies: 1 Vacancy

Job Summary

Description de lemploi
EQUANS

Equans is a world leader in the energy and services sector with annual revenues of nearly 192 billion* and almost 800000 projects.

Equans has leading positions in Europe which is the result of the history of energy construction in these countries and strong presences in North and South America and in Oceania.

With nearly 90000 highly skilled employees Equans has a strong geographic footprint anchored by historic local brands. Equans provides its customers with excellent technical expertise in the design installation maintenance and operation of multi-technical facilities. This know-how is based on key skills. First of all in electrical and thermal engineering - two strong points that help accelerate the reduction of our clients carbon footprint - but also inventilationrefrigerationmechanics and roboticsfire protection energy renovationdigital solutionsIT cyber security and telecommunications.

The combination of this expertise allows us to offer efficient and optimized solutions at all stages of the energy chain from production storage and transport to usage.

(*) Turnover 2024 consolidated

SOC Team Lead (F/M/X)

Summary of the role

As the SOC Team Lead you will head the operational response of the Equans CSIRT. You will be responsible for guiding and mentoring a distributed team of incident handlers while supervising the initial detection preliminary assessment and response to IT security incidents.

While you maintain a strong technical oversight analyzing attackers modus operandi assessing compromises and reviewing investigation reports you will serve as the primary focal point to coordinate threat mitigation interface with management and ensure the continuous improvement of our defensive capabilities.

KEY OBJECTIVES & KPIs

Workload allocation on main activities:

  • 40% for alerts response and incidents handling (includes team oversight and escalation support)
  • 25% for Team Leadership & Operational Management (includes leading the Incident Handlers with project and build follow-up and reporting to management)
  • 10% for Detection Strategy & Hunting Oversight (review validate and prioritize the implementation of new detection rules & supervise and guide threat hunting campaigns executed)
  • 10% for Continuous Improvements & Quality Assurance (perform quality reviews on analysts investigation reports and incident handling and drive the optimization of CSIRT playbooks documentation and operational processes)
  • 10% for meetings and operational management
  • 5% for training

KEY RESPONSIBILITIES

Leading the team

  • Follow up the build and project activities within your team
  • Report on a weekly basis the main progress/roadblocks to your manager
  • Manage operationally the service providers
  • Guarantee service quality and optimization
  • Work in collaboration with all the SLS Cyberdefense members
  • Participate in vendor conferences and meetings to discover new products functionality

Threat detection

  • Identify analyze and qualify security events in real time
  • Assess the seriousness of security incidents
  • Notify security incidents escalate if necessary

Reacting to threats

  • Transmit action plans to the entities in charge of processing and provide support regarding the corrective or palliative measures to be implemented
  • Make recommendations on immediate measures
  • Supporting the investigation teams in dealing with incidents

Implementing uses and tools

  • Help set up the detection service (SIEM etc.)
  • Helping to define the strategy for collecting event logs
  • Participating in the development and maintenance of event correlation rules
  • Conduct market analysis and evaluate new solutions through Proof of Concept/Proof of Value

Monitoring and improvement

  • Contributing to the continuous improvement of procedures; developing procedures for new types of incidents
  • Contribute to ongoing monitoring of threats vulnerabilities and attack methods in order to enhance event correlation rules.

Reporting and documentation

  • Compiling dashboards reporting on operational activity
  • Keeping documentation up to date
  • Threat hunting activities

In conjunction with Equans internal and partner teams:

  • Inform management of suspected cyber incidents and explain the history status and potential impact of the event;
  • Advise on disaster recovery contingency and business continuity plans at tactical operational and strategic levels;
  • Recommend measures for circumventing and remediating the incident.

PROFILE

Academic background & Experience

Candidates should hold a Bachelors or Masters degree in Computer Science Information Technology Cybersecurity or a related field with equivalent certifications like GIAC Certified Incident Handler (GCIH) Certified Incident Handler (ECIH) or CompTIA Security considered as alternatives. A strong foundation in cybersecurity principles including threat intelligence network security and incident management is essential.

Professionally applicants need at least 3-5 years of hands-on experience in cybersecurity operations ideally in a Security Operations Center (SOC) or incident response team.

Behavioral Capabilities

  • Strong leadership skills with the ability to guide and mentor a team of Incident Response professionals.
  • Excellent problem-solving and analytical skills with the ability to troubleshoot complex access governance issues and implement effective solutions.
  • Ability to communicate effectively with both technical and non-technical stakeholders ensuring clarity in explaining complex technical concepts.
  • Strong collaboration skills working seamlessly with cross-functional teams such as IT security and compliance.
  • Results-driven with a focus on delivering high-quality solutions and achieving business objectives.
  • Highly organized with the ability to manage multiple projects and prioritize tasks effectively.
  • Comfortable working in a multicultural distributed team.

Skills

  • You have a technical background demonstrating your ability to carry out the tasks assigned.
  • You are a technical leader who knows how to motivate a decentralized team track project progress and maintain a high standard of incident response methodology
  • You are autonomous technically versatile and able to tackle new and challenging technical subjects;
  • You are familiar with monitoring and intrusion detection tools as well as incident management systems;
  • You have an excellent methodological approach to incident response management;
  • You are proficient in malware analysis;
  • You have an interest in and skills for developing task automation;
  • You are curious rigorous and enjoy a challenge;
  • You are comfortable working in a decentralized multicultural organization with varying levels of maturity in terms of cyber security;
  • Youre a good communicator with good interpersonal skills and youre comfortable adapting to a variety of people;
  • You have a sense of ethics and are able to exercise discretion;
  • Fluent English essential and willing to work in an international context;
  • One or more certifications related to incident response (SANS OSCP etc.) and possibly intelligence on cyber threats are desirable.

Why Join Us

Motivational Environment
Join a dynamic team of passionate professionals actively involved in prestigious cybersecurity collaboration networks. Be part of a culture that values excellence innovation and mutual support.

Challenging Topics
Contribute to multiple high-impact projects that tackle real-world cybersecurity challenges. Your expertise will make a difference.

Empowered Voices
Your ideas matter. As a valued team member your input will be heard respected and considered in decision-making processes.

Technical Growth
Advance your skills through tailored training programs and hands-on experience. We invest in your development to help you reach your full potential.


Required Experience:

Manager


About Company

Company Logo

Acting to build an efficient, safe and connected world to empower transitions.

View Profile View Profile