Security Engineer SOC
The Security Operations Center (SOC) is the primary point of contact for cybersecurity. This role is crucial for a government organization that can be a sought-after target due to its societal influence. The SOC must maintain an overview, assess consequences, and take appropriate actions during security incidents.
What You Will Do. You will detect and mitigate malicious activities, such as phishing, intrusion attempts via websites, and exploitation of infrastructure weaknesses. You will be responsible for the technical design and implementation of security tooling and advise the management organization on technical measures. Knowledge of security aspects in cloud environments (Azure, AWS) is important. As a SOC Engineer, you will play a critical role in strengthening cybersecurity.
You will design, build, and optimize the security monitoring infrastructure, while supporting SOC analysts in detecting, analyzing, and mitigating threats.
SOC Engineering (80%).
- Building and maintaining the security monitoring environment:
- Microsoft Sentinel: Setting up, configuring, and optimizing the environment, including knowledge of Biceps CI/Cd pipelines/GIT.
- Defender XDR: Setting up the environment.
- Splunk: Setting up indexes, dashboards, alerts, and correlation rules for effective threat detection.
- Log stream management: Connecting, filtering, and normalizing logs from Windows, Linux, OpenShift, network devices, and cloud environments (Azure) via Cribl to analysis systems such as Sentinel and Splunk.
- Automation & DevSecOps:
- Developing and managing Azure DevOps pipelines for automatic deployment of configurations and detection rules.
- Maintaining Git repositories (GitHub/Azure Repos) with consistent code, peer reviews, and CI/CD pipelines.
- Scripting & automation in Python, PowerShell, Bash, YAML (and optionally Java/Go) for log processing, detection optimization, and incident response.
- Detection Engineering:
- Building, testing, and optimizing detection rules in Sentinel (KQL) and Splunk (SPL) based on internal research and Threat Intel.
SOC Analyst Support (20%).
- Collaborating with analysts to prioritize log sources and enable cost-effective analysis.
- Advising on the most relevant log events for threat detection.
- Developing playbooks and runbooks for standardized processes.
What they ask You will work in a dynamic environment with a young team, focused on proactive security and rapid incident response. You combine technical expertise with a strong analytical view and are proficient in Dutch for reporting.
What they ask
- Minimum three years of experience with SIEM/SOAR platforms: Microsoft Sentinel, KQL, Log Analytics, Azure Monitor, Splunk, SPL, dashboards, alerts, index management.
- Demonstrable experience with Cloud & DevSecOps: Infrastructure-as-Code, Azure Bicep, CI/CD: Azure DevOps, GitHub Actions, GitLab CI/CD.
- Knowledge of Scripting & Automation with, for example, Python, PowerShell, Bash, YAML, JSON, Ansible.
- Education and certifications: Microsoft Certified: SC-200, AZ-500; Splunk Core Certified User/Administrator/Power User; CISSP, CEH.
Preferences.
- Knowledge of Windows, Mac, Linux, OpenShift/Kubernetes, Network devices.
- Knowledge of Threat Intelligence Platforms (TIP): MISP, OpenCTI.
Practical
- Availability for standby duties.
- Availability for work on Fridays.
- A security screening is necessary.
How to apply
View the full assignment text and application details once your tailored application is ready.
Order a tailored application to view the full assignment and application details.
More context, less searching.
You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.