EU remote
Cloud Security Specialist – Detection Engineering
About this role
As a Cloud Security Specialist joining Ubisoft's Detection Engineering team within the SOC, you design, build, and tune the detection content that catches attacks against Ubisoft's cloud infrastructure, CI/CD pipelines, and DevOps tooling. Your value comes from deep, hands-on knowledge of how cloud environments and pipelines actually work — gained as a cloud, DevOps, or CI/CD engineer — which you will apply, with dedicated mentoring and training, to detection engineering methodology, SIEM content development, and threat hunting.
You are not securing or building cloud infrastructure in this role: you are hunting and detecting the attackers who target it, and increasingly, using LLMs and GenAI to do it faster and building the automation that responds once a threat is confirmed. Responsibilities Develop and maintain detection content (Splunk/SIEM, cloud-native logging, IDS) targeting attacks against cloud infrastructure, IAM, containers/Kubernetes, and CI/CD pipelines; Define detection engineering processes and standards specific to cloud and DevOps attack surfaces; Conduct threat hunting engagements across cloud environments and CI/CD telemetry; Research attacker TTPs targeting cloud and CI/CD (MITRE ATT&CK for Cloud, supply chain attacks, IAM abuse, container escape, pipeline poisoning) and translate them into detection logic; Leverage LLMs and GenAI to accelerate detection engineering work — generating and tuning detection logic, summarizing and enriching alerts, and speeding up hunting and triage; Design and build automated response playbooks (SOAR or custom orchestration) that contain or remediate cloud/CI-CD threats without manual intervention; Validate detection coverage through purple-teaming and adversary emulation against cloud environments; Mentor SOC analysts on investigating cloud-related alerts and the data sources available to them; Work with CTI and Incident Response to convert cloud threat intelligence into new detections and response automation; Identify logging and telemetry gaps in cloud/CI-CD systems that limit detection coverage, and drive requirements back to platform teams.
Significant hands-on experience operating, building, or securing public cloud environments (AWS, Azure, or GCP) as a cloud engineer, DevOps engineer, SRE, or cloud security specialist; Solid understanding of CI/CD pipelines and tooling (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, etc.) and how they get attacked; Familiarity with infrastructure-as-code (Terraform, CloudFormation, Pulumi) and cloud-native logging/telemetry (CloudTrail, Azure Activity Log, GCP Audit Logs, etc.); Scripting ability (Python, Go, or similar) to build detection logic and automate analysis and response; Solid grasp of cloud security fundamentals: IAM, network segmentation, container/Kubernetes security, secrets management; Experience or strong interest in applying LLMs/GenAI to security use cases (prompt engineering, RAG, agentic workflows) is a significant asset; Experience building security automation or orchestration (SOAR platforms, custom workflow engines, scripted response) is a plus; No prior SOC or detection engineering experience required — what matters is a strong analytical mindset and genuine interest in threat detection; you will be trained on Splunk content development, threat hunting methodology, and detection engineering practice; Cloud or security certification is an asset (AWS/Azure/GCP security specialty, CKS, GCDA, or equivalent).