Security Operations Analyst

Royal BAM Group nv
Bunnik, Netherlands
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
€5,100.0 - €7,000.0
Working hours
Regular working hours
Languages
Dutch, English

Tech stack

Cloud Computing CompTIA Security+ Cyber Security Data Validation Python (Programming Language) Windows PowerShell Phishing Kusto Query Language Security Information and Event Management Software Vulnerability Management Scripting Cloud Platform System
+6 more
Mitre Att&ck Cyber Threat Analysis Azure Security Center Information Technology Cybercrime Microsoft Sentinel

Job description

What if your work directly strengthens the digital and physical resilience of the country? You’re not just defending networks, you’re defending the future of the Netherlands. At BAM, we design and build the infrastructure that keeps the Netherlands running, from dikes, bridges, and energy networks to hospitals and other public facilities. These are the systems a nation depends on. As a Security Analyst, you help protect that foundation. You’ll be part of a modern, Microsoft-native Security Operations Center (SOC), where you detect, investigate, and help contain cyber threats that could disrupt vital infrastructure. What you’ll do Your day starts with reviewing the latest alerts in Microsoft Sentinel and Defender XDR. A login attempt from an unusual location catches your eye. You dig in, correlate logs, and confirm it’s a phishing attempt. You isolate the account, raise an incident, and work with IT to strengthen MFA rules Later, you join a threat hunting session with senior analysts, tuning detection rules and testing new use cases. In the afternoon, you validate new log sources, write documentation for a recent incident, and share insights with the team. Every day you’re learning, not just tools and techniques, but how to think like an attacker and respond like a defender. Furthermore:

  • Monitor & detect: Analyse alerts and events in Microsoft Sentinel and Defender XDR, validate and investigate alerts, and support continuous tuning of detection logic;
  • Respond: Support investigations and coordinate response actions, document findings, remediation steps, and lessons learned;
  • Hunt & improve: Participate in threat hunting sessions and help fine-tune detection logic and alert quality;
  • Analyse: Conduct basic malware and behavioral analysis to support incident investigations, escalating complex cases to senior analysts;
  • Support vulnerability management: Review scan results and help coordinate remediation with IT teams;
  • Enhance telemetry: Assist in log onboarding and data validation across endpoints and cloud systems;
  • Collaborate & grow: Work closely with senior analysts, improve playbooks, and continuously expand your skills. Your team You’ll join a young, dynamic SOC team within BAM’s IT & Security organisation, reporting into the Security Operations team. The team combines curiosity with expertise, they monitor, analyse, and continuously improve. The atmosphere is open and supportive, colleagues help each other, share knowledge, and celebrate progress together. You’ll work hybrid, primarily from Bunnik, with flexibility to work from home and visit project sites when needed.

Requirements

  • A Bachelor’s or Master’s degree in Cyber Security, Computer Science, Information Security, or a related technical field;
  • 2-4 years of experience in a SOC, CSIRT, or similar security monitoring role;
  • Familiarity with Microsoft Sentinel, Defender XDR, or other SIEM/EDR tools;
  • Experience in triaging alerts and understanding incident response workflows;
  • Strong analytical and problem-solving mindset, eager to learn and grow;
  • Fluent in Dutch (B2 or higher) and English (spoken and written);
  • Experience with scripting for automation purposes (e.g. Python, PowerShell, or KQL) is a plus. Nice-to-have:

  • Experience with Microsoft Defender for Endpoint, Identity, or Cloud Apps;
  • Some scripting knowledge (KQL, PowerShell, or Python);
  • Understanding of MITRE ATT&CK, threat intelligence, or vulnerability management;
  • Certifications like SC-200, CompTIA Security+, or equivalent.

Benefits & conditions

At BAM, we believe in investing in our people and creating a positive, inclusive culture where you can grow your expertise and make an impact.

  • A competitive salary between €5.100 - €7.000 based on experience and a 40-hour workweek, plus 8% holiday allowance;
  • Excellent secondary benefits under the Bouw & Infra collective labour agreement, including a sustainable employability budget (2.18%), 25 vacation days, 15 roster-free days, and 3 short-leave days per year;
  • Travel allowance, laptop, and iPhone;
  • Unique learning opportunities through our in-house platform BAM Learning, plus Microsoft certifications and external courses;
  • Extras like 40% discount on gym memberships, and discounts on private insurance and Microsoft Office. At BAM, you’ll grow as a professional, and as part of a team that protects the foundations of society.

About the company

At BAM, we believe everyone should have the opportunity to bring out the best in themselves. We are committed to creating an environment where everyone feels valued. That’s why we welcome people from diverse backgrounds, experiences, and perspectives.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.nationalevacaturebank.nl

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all