Solidgate

FinTech

SOCL2/L3Engineer

Europe FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“SOC L2/L3 Engineer at Solidgate. Skills: SIEM, Detection Engineering, Incident Response, Cloud Security, Scripting. Build and operationalize the SIEM, design and tune detection rules, triage and investigate alerts, lead incident response and forensics, onboard log sources, run threat hunts, build runbooks, and define SOC metrics.”

What You'll Achieve.

Empower entrepreneurs to build exceptional internet companies by providing robust financial infrastructure. Become the #1 payments orchestration platform globally.

Industry & Context.

FinTech
Problems you'll solve

detection engineering; incident response; threat hunting; automation; system design

Eligibility Requirements

Ability to work in a regulated environment with real cardholder data and SWIFT connectivity. Opportunity to build the SOC from scratch and choose the technology stack.

What They're Looking For.

Must Have

3+ years in SOC / Detection & Response at L2/L3 level, hands-on investigation experience, practical experience building or operating a SIEM, detection engineering with MITRE ATT&CK, experience investigating cloud log sources (AWS CloudTrail, GuardDuty, Google Workspace, EDR/XDR), scripting and automation skills (Python or similar), solid understanding of attacker techniques.

Nice to Have

SOAR experience, detection-as-code approach, UEBA, threat intelligence enrichment, alert contextualization at scale, familiarity with payment-specific environments, purple teaming experience.

What You'll Do.

Build and operationalize the SIEM

design and tune detection rules

triage and investigate alerts

lead incident response and forensics

and define SOC metrics.

How You'll Work.

Team & Collaboration

Work with a senior InfoSec team that treats detection gaps as engineering problems. Smart, experienced teammates who raise the bar and have each other's backs.

Communication Scope

clear escalation paths; clear documentation; monthly reporting

Full Job Description

OUR MISSION AND VISION At Solidgate, our mission is clear: to empower outstanding entrepreneurs to build exceptional internet companies. We exist to fuel the builders — the ones shaping the digital economy — with the financial infrastructure they deserve. To achieve that, we’re on a bold path: to become the #1 payments orchestration platform in the world. We believe the future of payments is shaped by people who think big, take ownership, and bring curiosity and drive to everything they do. That’s exactly the kind of teammates we want on board. We’re building the #1 payment orchestrator in the world — and the names behind us prove it. Clients include Bolt, Ajax, Nova Post, MEGOGO. Trusted by giants like J.P. Morgan. Ranked #2 in the “Employer of the Year 2026” award by Forbes Ukraine. WHY THIS ROLE IS CRITICAL Solidgate processes millions of payments across 120+ services, including its own acquiring module, and operates in a regulated environment with real cardholder data and SWIFT connectivity. You'll define what detection looks like at Solidgate: what gets monitored, what gets detected, and how the team responds when something goes wrong. WHAT YOU WILL OWN - Build and operationalize the SIEM from PoC to production - including case management and UEBA, with full ownership of the technology selection - Design, write, and tune detection rules mapped to MITRE ATT&CK, covering identity compromise, privilege escalation, lateral movement, and endpoint threats - Triage and investigate L2/L3 alerts, reduce false positives, and establish clear escalation paths for each use case - Lead incident response and basic forensics - containment, eradication, and structured lessons learned - Onboard log sources across AWS, JumpCloud, Google Workspace, CDE, and SWIFT; - Run threat hunts based on realistic attack hypotheses specific to a payment platform's risk profile - Build and maintain runbooks and playbooks; automate repetitive actions via SOAR or scripting - Define SOC metrics an

Free ATS check

Applying for this SOC L2/L3 Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Solidgate?

Real rants from real employees. Read before you apply.

Read Company Rants →