124.601 vacatures

30 jul 2026

SOC Analyst (Temp-to-Perm)

Branche Zie onder
Dienstverband Zie onder
Uren Zie onder
Locatie Den Haag,
's-Gravenhage
Opleidingsniveau HBO / bachelor
Contactpersoon Shir Abramovich

Informatie

  • Monitor, triage, and investigate notable events and RBA-driven alerts in Splunk Enterprise Security;
  • Perform log correlation and threat analysis across endpoint, network, identity (AD/Okta), and cloud telemetry;
  • Execute the incident response flow: triage, containment support, escalation, and documentation, with a focus on Mean Time To Respond (MTTR) reduction;
  • Map findings to MITRE ATT&CK to strengthen context and improve detection capabilities;
  • Maintain auditable incident records in ticketing/case tooling, including a clear timeline and decision rationale;
  • Collaborate with the SOC Engineer to tune noisy detections and reduce false positives;
  • Participate in shift handovers and weekly intelligence sharing on Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs).

Omschrijving

  • Monitor, triage, and investigate notable events and RBA-driven alerts in Splunk Enterprise Security;
  • Perform log correlation and threat analysis across endpoint, network, identity (AD/Okta), and cloud telemetry;
  • Execute the incident response flow: triage, containment support, escalation, and documentation, with a focus on Mean Time To Respond (MTTR) reduction;
  • Map findings to MITRE ATT&CK to strengthen context and improve detection capabilities;
  • Maintain auditable incident records in ticketing/case tooling, including a clear timeline and decision rationale;
  • Collaborate with the SOC Engineer to tune noisy detections and reduce false positives;
  • Participate in shift handovers and weekly intelligence sharing on Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs).

Functie eisen

  • 2-4 years in SOC or blue-team operations;
  • Splunk Proficiency: Hands-on experience with Splunk, including practical SPL usage for searching, dashboard analysis, and incident review;
  • Solid understanding of TCP/IP, DNS, HTTP(S), authentication protocols, and common attacker patterns;
  • Working knowledge of Windows Event Logs, Sysmon, firewall/proxy logs, and EDR telemetry;
  • Familiarity with MITRE ATT&CK and NIST incident response lifecycle;
  • Experience with at least one EDR stack (e.g., CrowdStrike, SentinelOne);
  • Strong written communication skills for both technical and management audiences.

Nice-to-Have Requirements:

  • Splunk Certifications/Admin: Splunk Core Certified Power User and/or Splunk ES administration exposure;
  • Basic Python or PowerShell scripting for investigation acceleration;
  • Cloud security monitoring exposure in AWS (e.g., CloudTrail, GuardDuty, Security Hub, VPC Flow Logs);
  • Security Certifications: CySA+, GCIA, GCIH, or comparable blue-team certification.
Solliciteer direct