SOC Analyst (Temp-to-Perm)
| Branche | Zie onder |
| Dienstverband | Zie onder |
| Uren | Zie onder |
| Locatie |
Den Haag, 's-Gravenhage |
| Opleidingsniveau | HBO / bachelor |
| Contactpersoon |
Shir Abramovich |
Informatie
- Monitor, triage, and investigate notable events and RBA-driven alerts in Splunk Enterprise Security;
- Perform log correlation and threat analysis across endpoint, network, identity (AD/Okta), and cloud telemetry;
- Execute the incident response flow: triage, containment support, escalation, and documentation, with a focus on Mean Time To Respond (MTTR) reduction;
- Map findings to MITRE ATT&CK to strengthen context and improve detection capabilities;
- Maintain auditable incident records in ticketing/case tooling, including a clear timeline and decision rationale;
- Collaborate with the SOC Engineer to tune noisy detections and reduce false positives;
- Participate in shift handovers and weekly intelligence sharing on Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs).
Omschrijving
- Monitor, triage, and investigate notable events and RBA-driven alerts in Splunk Enterprise Security;
- Perform log correlation and threat analysis across endpoint, network, identity (AD/Okta), and cloud telemetry;
- Execute the incident response flow: triage, containment support, escalation, and documentation, with a focus on Mean Time To Respond (MTTR) reduction;
- Map findings to MITRE ATT&CK to strengthen context and improve detection capabilities;
- Maintain auditable incident records in ticketing/case tooling, including a clear timeline and decision rationale;
- Collaborate with the SOC Engineer to tune noisy detections and reduce false positives;
- Participate in shift handovers and weekly intelligence sharing on Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs).
Functie eisen
- 2-4 years in SOC or blue-team operations;
- Splunk Proficiency: Hands-on experience with Splunk, including practical SPL usage for searching, dashboard analysis, and incident review;
- Solid understanding of TCP/IP, DNS, HTTP(S), authentication protocols, and common attacker patterns;
- Working knowledge of Windows Event Logs, Sysmon, firewall/proxy logs, and EDR telemetry;
- Familiarity with MITRE ATT&CK and NIST incident response lifecycle;
- Experience with at least one EDR stack (e.g., CrowdStrike, SentinelOne);
- Strong written communication skills for both technical and management audiences.
Nice-to-Have Requirements:
- Splunk Certifications/Admin: Splunk Core Certified Power User and/or Splunk ES administration exposure;
- Basic Python or PowerShell scripting for investigation acceleration;
- Cloud security monitoring exposure in AWS (e.g., CloudTrail, GuardDuty, Security Hub, VPC Flow Logs);
- Security Certifications: CySA+, GCIA, GCIH, or comparable blue-team certification.