Back to all jobs
Visible on IKONS todayNewPopular

Security analyst

UtrechtHybrid34 hours/week<3months

Investigate serious security incidents and coordinate their approach. Perform threat hunts yourself and determine how to improve detections. This role combines technical depth with content leadership within an IT service provider for a government organization. You will have an important voice in the development of the Security Operations Center (SOC) and help less experienced analysts grow in their profession. A versatile role where your expertise directly contributes to the digital security of the organization.

What you will do.

  • Lead serious security incidents with major impact or affecting multiple organizational units.
  • Bring together the right specialists, coordinate the investigation, and monitor progress, from initial analysis to recovery and evaluation.
  • Liaise with technical teams, security champions, managers, and the CISO.
  • Translate findings into clear advice and ensure stakeholders are informed about risks and necessary measures.
  • Build and maintain a network within the organization and collaborate structurally with security champions and the Information Security department.
  • Actively gather signals, concerns, and improvement needs from other departments and communicate threats, risks, and lessons learned from incidents back to the organization.
  • Create support for measures and help technical and non-technical teams fulfill their role in prevention, detection, response, and recovery.
  • Dive into technical depth with SIEM platforms, advanced XDR tooling, and other analysis platforms.
  • Investigate attack patterns, perform threat hunts, and test whether detections work as intended.
  • Evaluate and improve use cases of L2 analysts and assist L1 and L2 colleagues with difficult investigations.
  • Deal with threats and incidents affecting multiple government organizations through contacts with national cybersecurity centers and SOCs of government agencies.
  • Be substantively responsible for one or more SOC services and co-determine which improvements receive priority.
  • Take on improvement projects to detect attacks earlier, adapt processes and playbooks, and promote automation.
  • Use knowledge of new threats and experience with incidents to continuously improve detections, working methods, and tooling.

What they ask

  • HBO (higher professional education) thinking and working level.
  • More than 6 years of experience as a security analyst or within incident response, including leading or coordinating complex incident investigations.
  • In-depth knowledge of security and network concepts, security architecture, and incident response.
  • Experience with security tools such as Splunk, Microsoft Defender XDR, and Azure.
  • Experience with threat hunting, scenario analysis, detection validation, and improving use cases.
  • Experience with improving SOC processes and tooling, independently carrying out improvement projects.
  • Knowledge of relevant security standards such as BIO CISSP or a demonstrable equivalent senior knowledge and experience level.
  • A technical specialization, for example, a SANS certification.
  • A Certificate of Conduct (VOG) is required.

Profile

  • You like to be at the forefront of your profession.
  • You know how to engage people.
  • You keep a cool head and maintain an overview under pressure.

Practical

  • Pleasant, informal working atmosphere with short lines of communication.
  • Possibility to work partly from home.
  • Contribution to setting up a comfortable home office.
  • Good pension scheme.
  • Various activities such as team days and social gatherings.

How to apply

View the full assignment text and application details once your tailored application is ready.

Order a tailored application to view the full assignment and application details.

More context, less searching.

You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.