Ubisoft
Cloud Security Specialist – Detection Engineering
- Location
- Saint-Mandé, IDF, France
- Work model
- OnSite
- Employment
- FullTime
- Posted
- Added to Codestelle
Language requirements
- German
- Not specified
- English alone
- Not specified
Based on explicit wording in the listing. “Not specified” does not mean a language is optional.
About this role
As a Cloud Security Specialist joining Ubisoft's Detection Engineering team within the SOC, you design, build, and tune the detection content that catches attacks against Ubisoft's cloud infrastructure, CI/CD pipelines, and DevOps tooling. Your value comes from deep, hands-on knowledge of how cloud environments and pipelines actually work — gained as a cloud, DevOps, or CI/CD engineer — which you will apply, with dedicated mentoring and training, to detection engineering methodology, SIEM content development, and threat hunting. You are not securing or building cloud infrastructure in this role: you are hunting and detecting the attackers who target it, and increasingly, using LLMs and GenAI to do it faster and building the automation that responds once a threat is confirmed.
Responsibilities
- Develop and maintain detection content (Splunk/SIEM, cloud-native logging, IDS) targeting attacks against cloud infrastructure, IAM, containers/Kubernetes, and CI/CD pipelines;
- Define detection engineering processes and standards specific to cloud and DevOps attack surfaces;
- Conduct threat hunting engagements across cloud environments and CI/CD telemetry;
- Research attacker TTPs targeting cloud and CI/CD (MITRE ATT&CK for Cloud, supply chain attacks, IAM abuse, container escape, pipeline poisoning) and translate them into detection logic;
- Leverage LLMs and GenAI to accelerate detection engineering work — generating and tuning detection logic, summarizing and enriching alerts, and speeding up hunting and triage;
- Design and build automated response playbooks (SOAR or custom orchestration) that contain or remediate cloud/CI-CD threats without manual intervention;
- Validate detection coverage through purple-teaming and adversary emulation against cloud environments;
- Mentor SOC analysts on investigating cloud-related alerts and the data sources available to them;
- Work with CTI and Incident Response to convert cloud threat intelligence into new detections and response automation;
- Identify logging and telemetry gaps in cloud/CI-CD systems that limit detection coverage, and drive requirements back to platform teams.
- Significant hands-on experience operating, building, or securing public cloud environments (AWS, Azure, or GCP) as a cloud engineer, DevOps engineer, SRE, or cloud security specialist;
- Solid understanding of CI/CD pipelines and tooling (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, etc.) and how they get attacked;
- Familiarity with infrastructure-as-code (Terraform, CloudFormation, Pulumi) and cloud-native logging/telemetry (CloudTrail, Azure Activity Log, GCP Audit Logs, etc.);
- Scripting ability (Python, Go, or similar) to build detection logic and automate analysis and response;
- Solid grasp of cloud security fundamentals: IAM, network segmentation, container/Kubernetes security, secrets management;
- Experience or strong interest in applying LLMs/GenAI to security use cases (prompt engineering, RAG, agentic workflows) is a significant asset;
- Experience building security automation or orchestration (SOAR platforms, custom workflow engines, scripted response) is a plus;
- No prior SOC or detection engineering experience required — what matters is a strong analytical mindset and genuine interest in threat detection; you will be trained on Splunk content development, threat hunting methodology, and detection engineering practice;
- Cloud or security certification is an asset (AWS/Azure/GCP security specialty, CKS, GCDA, or equivalent).