{"id":1797619,"url":"https://alion.io/job/orange-analyste-soc-incident","title":"Analyste SOC / Incident","company":{"id":696752,"name":"bonnorange","domain":"bonnorange.de","url":"https://alion.io/company/bonnorange","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Personio","truth_index":{"grade":"A","score":100,"open_postings":15,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":4,"computed_at":"2026-10-08T05:49:30Z"}},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Casablanca, Morocco"],"countries":["MA"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":83000,"max_usd":231000,"period":"year","method":null,"sample_n":3655},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Autopsy","optional":false},{"name":"Cortex XDR","optional":false},{"name":"Linux","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SentinelOne","optional":false},{"name":"SIEM","optional":false},{"name":"Velociraptor","optional":false},{"name":"Volatility","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-10-03T16:32:26Z","employer_posted_date":"2026-10-04","last_verified_at":"2026-10-08T22:41:20Z","board_verified":true,"closed_at":null,"days_open":5,"trust":{"level":"ok","repost_count":1,"flags":[],"days_open":4},"description":"Publication date : Mar 27, 2026, 12:00AM\nVidéo EVP\nÀ propos de nousJoin us at Orange Business!\nWe are a network and digital integrator that understands the entire value chain of the digital world, freeing our customers to focus on the strategic initiatives that shape their business.\nEvery day, you will collaborate with a team dedicated to providing consistent, sustainable global solutions, no matter where our customers operate. With over 30,000 employees across Asia, the Americas, Africa, and Europe, we offer a dynamic environment to develop and perfect your skills in a field filled with exciting challenges and opportunities.\nÀ propos du rôleVos principales missions seront:\nParticiper à la construction du service:\nPrendre en main les solutions techniques (d’un point de vue administration et exploitation);\nEprouver et construire des processus concernant les outils et l’exploitation du service;\nDévelopper des connecteurs pour interfacer les solutions de détection avec nos outils internes.\nExploiter le service:\nPrendre en charge les alertes de sécurité provenant des solutions de détection;\nQualifier, analyser et notifier les clients des incidents de sécurité potentiels;\nMaintenir les solutions de détection fonctionnelles;\nAméliorer la qualité de détection pour les clients.\nContribuer à l’amélioration du service:\nIdentifier des enrichissements possibles (outillage, veille, processus) permettant d’améliorer la qualité du service et / ou son efficacité;\nEtudier comment intégrer des référentiels (MITRE, ETSI) dans nos couvertures de détections.\nÀ propos de vousDe formation Bac+5 en informatique, cybersécurité ou équivalent, vous justifiez d'une expérience significative d' au moins 3 ans en réponse à incidents de sécurité, idéalement acquise en SOC, CSIRT ou cellule de crise cyber. Vous avez été confronté(e) à de vraies attaques - pas uniquement à des exercices théoriques.\nCompétences techniques\nMaîtrise des phases du cycle IR : détection, confinement, éradication, remédiation et retour à la normale\nExpérience concrète en analyse forensique : artefacts Windows/Linux (prefetch, event logs, MFT, registry hives), mémoire vive, images disque\nCapacité à reconstituer une timeline d'attaque et à identifier le patient zéro, les vecteurs d'entrée et les mouvements latéraux\nConnaissance des tactiques, techniques et procédures adversariales (MITRE ATT&CK) : ransomware, APT, supply chain, BEC…\nMaîtrise d'outils d'investigation : Velociraptor, Volatility, Autopsy, EDR (SentinelOne, Cortex XDR…), SIEM\nCompétences en threat hunting proactif sur des environnements compromis\nNotions en scripting (Python, PowerShell) pour automatiser les collectes ou l'analyse d'artefacts\nSavoir-être & posture professionnelle\nSang-froid sous pression : en situation de crise, vous structurez votre approche et gardez le cap même face à l'incertitude\nRigueur documentaire : chaque action, chaque découverte est tracée - vos rapports post-incident sont exploitables et actionnables\nPédagogie : vous savez vulgariser une attaque complexe pour un RSSI, un DG ou un client non-technique\nAutonomie et leadership situationnel : capable de piloter une investigation de bout en bout, y compris en coordonnant d'autres intervenants\nDiscrétion et éthique professionnelle : vous traitez des données sensibles dans des contextes à fort enjeu\nLangues Maîtrise du français indispensable - à l'écrit comme à l'oral, y compris pour la rédaction de rapports d'incidents et la communication de crise. L'anglais technique est fortement apprécié pour exploiter les ressources de threat intelligence et interagir avec des éditeurs.\nYou bring rigor, passion for challenges, and determination. You seek the opportunity to expand your expertise, achieve your goals, and thrive.\nCe que nous proposons\nGlobal Opportunities: Work in multi-national teams with opportunity to collaborate with colleagues and customers from all over the world.\n\nFlexible Work Environment: Flexible working hours and possibility to combine work from office and home (hybrid ways of working).\n\nProfessional Development: training programs and upskilling/re-skilling opportunities.\n\nCareer Growth: Internal growth and mobility opportunities within Orange.\n\nCaring and Daring Culture: Health and well-being programs and benefits, diversity & inclusion initiatives, CSR and employee connect events.\n\nReward Programs: Employee Referral Program, Change Maker Awards.\nÉgalité des chances en matière d'emploiRegardless of your age, gender identity, race, ethnic origin, religion/belief, sexual orientation, marital status, neurotype, disability, veteran status or appearance, we encourage diversity within our teams because it is a strength for the collective and a vector of innovation. Orange Group is a disabled-friendly company and equal opportunity employer: don't hesitate to tell us about your specific needs.\nRécompenses..At Orange, only your skills matter.\nRegardless of your age, gender, background, origin, religion, sexual orientation, disability, neurodiversity, or appearance, we actively encourage diversity within our teams, as it is a collective strength and a driver of innovation.Orange is a disability-inclusive employer: please feel free to let us know about any specific needs you may have.","description_format":"text","description_chars":5261,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"French","level":"All levels","optional":false}]},"benefits":["Flexible schedule","Professional development"],"hiring_locations":[{"name":"Morocco","iso":"MA","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response","Energy & Utilities","Waste Management"],"lifecycle":[{"event":"open","at":"2026-10-03T18:16:44Z"},{"event":"close","at":"2026-10-03T19:01:25Z"},{"event":"reopen","at":"2026-10-04T22:48:24Z"}],"visa":[],"liveness":{"score":37,"band":"fade","label":"Fading","p_open":1,"p_active":0.677,"p_room":0.55,"age_days":4,"expected_fill_days":4,"reasons":["conf:0","velocity","win:tail","comp:brand"],"computed_at":"2026-10-08T05:49:30Z"},"pay":null,"html_url":"https://alion.io/job/orange-analyste-soc-incident","json_url":"https://alion.io/job/orange-analyste-soc-incident.json","meta":{"generated_at":"2026-10-09T02:36:00Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":743,"day_limit":5000,"remaining_today":4257,"minute_limit":60,"resets_at":"2026-10-10T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":696752},"rest":"https://alion.io/mcp/rest/get_company?id=696752"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Forange-analyste-soc-incident"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Forange-analyste-soc-incident"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Forange-analyste-soc-incident"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/orange-analyste-soc-incident\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Forange-analyste-soc-incident"}]}