123.773 vacatures

30 jul 2026

SOC Engineer (Temp-to-Perm)

Branche Zie onder
Dienstverband Zie onder
Uren Zie onder
Locatie Den Haag,
's-Gravenhage
Opleidingsniveau HBO / bachelor
Contactpersoon Shir Abramovich

Informatie

  • Administer Splunk stack components relevant to SOC operations, including the search tier, data ingestion path, forwarders, licensing, and availability model;
  • Own the data onboarding and normalization pipeline, encompassing inputs, CIM-aligned mapping, and the quality of index-time and search-time extractions;
  • Build and maintain correlation searches, Risk-Based Alerting (RBA) logic, and detection content aligned with the MITRE ATT&CK framework;
  • Maintain the quality of the Asset & Identity framework within Splunk Enterprise Security (ES) to ensure accurate enrichment and risk scoring;
  • Create analyst-facing dashboards, investigation views, and workflow automation using SPL and adaptive response actions;
  • Integrate Security Orchestration, Automation, and Response (SOAR) playbooks for repeatable tier-1 automation;
  • Conduct platform health reviews, tuning sessions, and capacity planning;
  • Define and enforce Role-Based Access Control (RBAC) in Splunk ES in alignment with least-privilege principles.

Omschrijving

  • Administer Splunk stack components relevant to SOC operations, including the search tier, data ingestion path, forwarders, licensing, and availability model;
  • Own the data onboarding and normalization pipeline, encompassing inputs, CIM-aligned mapping, and the quality of index-time and search-time extractions;
  • Build and maintain correlation searches, Risk-Based Alerting (RBA) logic, and detection content aligned with the MITRE ATT&CK framework;
  • Maintain the quality of the Asset & Identity framework within Splunk Enterprise Security (ES) to ensure accurate enrichment and risk scoring;
  • Create analyst-facing dashboards, investigation views, and workflow automation using SPL and adaptive response actions;
  • Integrate Security Orchestration, Automation, and Response (SOAR) playbooks for repeatable tier-1 automation;
  • Conduct platform health reviews, tuning sessions, and capacity planning;
  • Define and enforce Role-Based Access Control (RBAC) in Splunk ES in alignment with least-privilege principles.

Functie eisen

  • Completed HBO or university degree in IT (preferably Software Engineering or Cybersecurity);
  • Minimum 3 years of experience as a Security Engineer;
  • 3-5 years of Splunk administration and security-content engineering (including ES/Security Premium Apps);
  • Strong SPL proficiency (macros, lookups, accelerated data models, tstats-based search patterns);
  • Hands-on integration of log sources (firewall, EDR, AD/identity, cloud telemetry) with CIM normalization;
  • Practical detection engineering mindset (signal-to-noise tuning, risk scoring, false-positive control);
  • Knowledge of operating system security, network security, and secure development methods;
  • Hands-on knowledge of AWS cloud security and operations;
  • Good spoken and written Dutch;
  • Clear communication of technical decisions to both analyst and non-technical stakeholders;
  • Linux/Unix operational capability for Splunk infrastructure support;
  • Splunk Certified Architect and/or Splunk ES Certified Admin;
  • At least one valid technical security certification (e.g., OSCP, GCIH, GMON, GCIA, AWS Certified Security) or willingness to obtain one;
  • Experience with other SIEM/SOAR platforms (e.g., Elastic).
Solliciteer direct