SOC Engineer (Temp-to-Perm)
| Branche | Zie onder |
| Dienstverband | Zie onder |
| Uren | Zie onder |
| Locatie |
Den Haag, 's-Gravenhage |
| Opleidingsniveau | HBO / bachelor |
| Contactpersoon |
Shir Abramovich |
Informatie
- Administer Splunk stack components relevant to SOC operations, including the search tier, data ingestion path, forwarders, licensing, and availability model;
- Own the data onboarding and normalization pipeline, encompassing inputs, CIM-aligned mapping, and the quality of index-time and search-time extractions;
- Build and maintain correlation searches, Risk-Based Alerting (RBA) logic, and detection content aligned with the MITRE ATT&CK framework;
- Maintain the quality of the Asset & Identity framework within Splunk Enterprise Security (ES) to ensure accurate enrichment and risk scoring;
- Create analyst-facing dashboards, investigation views, and workflow automation using SPL and adaptive response actions;
- Integrate Security Orchestration, Automation, and Response (SOAR) playbooks for repeatable tier-1 automation;
- Conduct platform health reviews, tuning sessions, and capacity planning;
- Define and enforce Role-Based Access Control (RBAC) in Splunk ES in alignment with least-privilege principles.
Omschrijving
- Administer Splunk stack components relevant to SOC operations, including the search tier, data ingestion path, forwarders, licensing, and availability model;
- Own the data onboarding and normalization pipeline, encompassing inputs, CIM-aligned mapping, and the quality of index-time and search-time extractions;
- Build and maintain correlation searches, Risk-Based Alerting (RBA) logic, and detection content aligned with the MITRE ATT&CK framework;
- Maintain the quality of the Asset & Identity framework within Splunk Enterprise Security (ES) to ensure accurate enrichment and risk scoring;
- Create analyst-facing dashboards, investigation views, and workflow automation using SPL and adaptive response actions;
- Integrate Security Orchestration, Automation, and Response (SOAR) playbooks for repeatable tier-1 automation;
- Conduct platform health reviews, tuning sessions, and capacity planning;
- Define and enforce Role-Based Access Control (RBAC) in Splunk ES in alignment with least-privilege principles.
Functie eisen
- Completed HBO or university degree in IT (preferably Software Engineering or Cybersecurity);
- Minimum 3 years of experience as a Security Engineer;
- 3-5 years of Splunk administration and security-content engineering (including ES/Security Premium Apps);
- Strong SPL proficiency (macros, lookups, accelerated data models, tstats-based search patterns);
- Hands-on integration of log sources (firewall, EDR, AD/identity, cloud telemetry) with CIM normalization;
- Practical detection engineering mindset (signal-to-noise tuning, risk scoring, false-positive control);
- Knowledge of operating system security, network security, and secure development methods;
- Hands-on knowledge of AWS cloud security and operations;
- Good spoken and written Dutch;
- Clear communication of technical decisions to both analyst and non-technical stakeholders;
- Linux/Unix operational capability for Splunk infrastructure support;
- Splunk Certified Architect and/or Splunk ES Certified Admin;
- At least one valid technical security certification (e.g., OSCP, GCIH, GMON, GCIA, AWS Certified Security) or willingness to obtain one;
- Experience with other SIEM/SOAR platforms (e.g., Elastic).