Back to all jobs
Visible on IKONS todayNewPopular
SOC Analyst
UtrechtHybrid40 hours/week6-12months
Within a government organization, there is a product called Cyber Security Operations. The team is responsible for the overall management of security across the areas of protection, defense, resilience, and governance.
- Developments in security are accelerating and are an important theme. The product team aims to further implement the existing roadmap and renewed strategy.
- The product team works in multidisciplinary scrum teams on development and management.
- Two Cybersecurity SOC analysts are sought to strengthen the team.
What you will do.
- Monitor the cybersecurity status of the organization.
- Handle incidents resulting from cybersecurity attacks.
- Ensure the availability and continuity of services.
- Proactively and reactively monitor and maintain cybersecurity resilience.
- Develop and implement a roadmap to elevate the SOC to the next maturity level.
- Initiate and implement improvements based on the Kanban methodology.
- Optimize processes, increase operational efficiency, and strengthen collaboration with other departments.
- Ensure knowledge transfer, coaching, and process improvements within the team.
- Organize exercises at various levels: tabletop validations of playbooks, technically oriented SOC exercises, and exercises in a broader forum.
- Proactively identify improvement opportunities in processes, detection capabilities, automation, reporting, and collaboration.
- Translate improvement opportunities into concrete measures and ensure successful implementation and embedding.
- Formulate strategic objectives and translate them into tactical and operational improvements.
- Effectively engage stakeholders in necessary changes.
Activities.
- Regular monitoring and analysis of security incidents.
- Coordinate with various resolution groups and take lead in timely resolution of security incidents.
- Document incident results and actions performed.
- Develop, maintain, and validate the Incident Response Plan.
- Contribute to improving and validating the incident handling process.
- Periodically conduct vulnerability research and determine the content and depth of penetration tests.
- Improve the penetration testing process, reporting, and follow-up process.
- Perform periodic reports on operational security results and ensure improvement activities.
- Measure the effectiveness of incident detection and response.
- Analyze and assess cybersecurity controls and mitigation actions after an incident.
- Develop and introduce test methods for incident handling.
- Analyze and investigate IT security issues.
- Perform periodic assessment analysis on delivered products and services.
- Establish risk classifications within various IT security areas.
- Provide solicited and unsolicited advice on IT security matters.
- Create, maintain, and validate use cases and playbooks.
- Incorporate improvements into the use case and playbook lifecycle.
- Collaborate with the Computer Security Incident Response Team (CSIRT).
Profile
- Accustomed to working within the frameworks and guidelines of an existing security architecture and information security standards, norms, and frameworks (e.g., ISO, NIST, Mitre).
- Team player and able to work independently.
- Good verbal and written communication/reporting skills.
- Critical thinking regarding the improvement of detection, monitoring, and response.
- Maintains high quality standards, monitors and improves them where possible.
- Sense of duty and responsibility for delivered work.
- Accountable for results of agreed actions.
- Investigates, recognizes, and understands the key elements of issues and their interrelationships.
- Articulates thoughts clearly and fluently, conveys a message understandably to others, and maintains their attention.
- Acts in the group's interest and contributes with others to the common result.
What they ask
- Demonstrable HBO (higher professional education) work and thinking level.
- Completed education in Informatics, Business Administration/ICT (or similar).
- In possession of Security certifications such as CSA, SC200.
- Proficient in English and Dutch, both spoken and written.
- Current (within the last 7 years) and at least 5 years of demonstrable experience as a SOC analyst.
- Current (within the last 5 years) and demonstrable experience with the daily technical, functional, and operational aspects of the cybersecurity incident and response process.
- Current (within the last 5 years) and demonstrable experience with collecting, analyzing, and correlating cyber threat information from various sources.
- Current (within the last 5 years) and demonstrable experience with operating systems, servers, cloud, and relevant infrastructure.
- Current (within the last 5 years) and demonstrable experience with Security Operation Center operations.
- Current (within the last 5 years) and demonstrable experience with SIEM platforms and setting up use cases, playbooks, and tuning.
- Current (within the last 5 years) and demonstrable experience with improving the incident process and best practices.
- Current (within the last 5 years) and demonstrable experience with incident tools such as Topdesk and Microsoft.
- Current (within the last 5 years) and demonstrable experience with incident communication procedures.
- Current (within the last 5 years) and demonstrable experience with offensive and defensive concepts.
- Current (within the last 5 years) and demonstrable experience with operating system & hypervisor security and network security.
- Current (within the last 5 years) and demonstrable experience with cybersecurity threats and attack procedures.
- Current (within the last 5 years) and demonstrable experience with scanning system vulnerabilities.
- Current (within the last 5 years) and demonstrable experience with Log Management Systems and log formats (Syslog-BSD, Syslog-IETF, CEF).
- Current (within the last 5 years) and demonstrable experience with Microsoft Cloud solutions.
- Current (within the last 5 years) and demonstrable experience with cybersecurity-related legislation such as GDPR/AVG, WDO, WBNI, eIDAS.
- Current (within the last 5 years) and demonstrable experience with automation and optimization.
- Current (within the last 5 years) and demonstrable experience with Computer Security Incident Response Team operations.
Preferences.
- Demonstrable experience working at similar government organizations.
How to apply
View the full assignment text and application details once your tailored application is ready.
Order a tailored application to view the full assignment and application details.
More context, less searching.
You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.