SOC Analyst (Tier 1) for NATO with security clearance

WLG
Bergen, Belgium
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Analysis of Variance (ANOVA) Proxy Servers Cyber Security Computer Networks Data Files Linux Domain Name System (DNS) Networking Hardware Intrusion Detection and Prevention Intrusion Detection Systems Network Security
+10 more
Log Analysis Network Intrusion Detection Systems Packet Analyzer ArcSight SIEM Tool Security Information and Event Management Wireshark Network Routers Firewalls (Computer Science) Information Technology Splunk

Job description

  • Conduct research and assessments of security events within NATO Cyber Security Centre (NCSC)team
  • Provide analysis of firewall, IDS, anti-virus and other network sensor produced events and present findings
  • Appropriately leverage the comprehensive extended toolset (e.g. Log Collection, Intrusion Detection, Packet Capture, VA, Network Devices etc.) for enhancing investigations
  • Support the end-to-end Incident Handling process
  • Propose optimisations and enhancements which help to both maintain and improve NATO’s Cyber Security posture

Requirements

  • A university degree in a technical subject with a focus on Information Technology (IT), obtained from a nationally recognised/certified institution in addition to a minimum of 1 year experience in the field of cyber security analysis. The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis. Similarly, candidate’s lacking experience can compensate by demonstrating a high level of knowledge in the field of cybersecurity.
  • Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP networking, Windows and Linux operating systems
  • Broad understanding of common network security threats and mitigation techniques
  • Experience in the following:
  • Security Information and Event Management products (SIEM) - e.g. ArcSight, Splunk
  • Analysis of Network Based Intrusion Detection Systems (NIDS) events- e.g. SourceFire, Palo Alto Network Threat Prevention
  • Log analysis from a variety of sources (e.g. Firewalls, Proxies, Routers, DNS and other security appliances)
  • Network traffic capture analysis using Wireshark

  • Logical approach to analysis and ability to perform structured security investigations using large, complex data sets
  • Good written and spoken communication skills
  • Ability to work independently and as part of a team

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.be

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

3:19 min

Setting up a vulnerable test application and monitoring environment

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all