Ubisoft2

Cloud Security Specialist – Detection Engineering

Saint-Mandé, IDF, FranceFull timePosted 7 days ago
Apply on Ubisoft2 →

Sign in to see who you know at Ubisoft2.

Ubisoft is a global leader in gaming with teams across the world creating original and memorable gaming experiences, from Assassin’s Creed, Rainbow Six, to Just Dance and more. We believe diverse perspectives help both players and teams thrive. If you’re passionate about innovation and pushing entertainment boundaries, join our journey and help us create the unknown!  As a Cloud Security Specialist joining Ubisoft's Detection Engineering team within the SOC, you design, build, and tune the detection content that catches attacks against Ubisoft's cloud infrastructure, CI/CD pipelines, and DevOps tooling. Your value comes from deep, hands-on knowledge of how cloud environments and pipelines actually work — gained as a cloud, DevOps, or CI/CD engineer — which you will apply, with dedicated mentoring and training, to detection engineering methodology, SIEM content development, and threat hunting. You are not securing or building cloud infrastructure in this role: you are hunting and detecting the attackers who target it, and increasingly, using LLMs and GenAI to do it faster and building the automation that responds once a threat is confirmed.ResponsibilitiesDevelop and maintain detection content (Splunk/SIEM, cloud-native logging, IDS) targeting attacks against cloud infrastructure, IAM, containers/Kubernetes, and CI/CD pipelines;Define detection engineering processes and standards specific to cloud and DevOps attack surfaces;Conduct threat hunting engagements across cloud environments and CI/CD telemetry;Research attacker TTPs targeting cloud and CI/CD (MITRE ATT&CK for Cloud, supply chain attacks, IAM abuse, container escape, pipeline poisoning) and translate them into detection logic;Leverage LLMs and GenAI to accelerate detection engineering work — generating and tuning detection logic, summarizing and enriching alerts, and speeding up hunting and triage;Design and build automated response playbooks (SOAR or custom orchestration) that contain or remediate cloud/CI-CD threats without manual intervention;Validate detection coverage through purple-teaming and adversary emulation against cloud environments;Mentor SOC analysts on investigating cloud-related alerts and the data sources available to them;Work with CTI and Incident Response to convert cloud threat intelligence into new detections and response automation;Identify logging and telemetry gaps in cloud/CI-CD systems that limit detection coverage, and drive requirements back to platform teams. Significant hands-on experience operating, building, or securing public cloud environments (AWS, Azure, or GCP) as a cloud engineer, DevOps engineer, SRE, or cloud security specialist;Solid understanding of CI/CD pipelines and tooling (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, etc.) and how they get attacked;Familiarity with infrastructure-as-code (Terraform, CloudFormation, Pulumi) and cloud-native logging/telemetry (CloudTrail, Azure Activity Log, GCP Audit Logs, etc.);Scripting ab...