Second Line SOC Analyst (Splunk, Sentinel and Detection Engineering) for NATO with security clearance
WLG
Bergen, Belgium
2 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.adzuna.be
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Amazon Web Services
Microsoft Azure
Cloud Computing Security
Cyber Security
Linux
Event Logging
Intrusion Detection and Prevention
Log Analysis
Packet Analyzer
Runbook
Smart Devices
+10 more
Wireshark
EndPointSecurity
Information Technology
Palo Alto Networks
Microsoft Sentinel
Fortinet
Kibana
Splunk
SentinelOne Expertise
Cisco
Job description
- Reviewing and validating investigations, supporting first-line analysts so that alert closures, escalations, evidence and notes meet the standard - complete, accurate and procedurally sound
- Acting as the technical escalation point for security monitoring: in-depth log analysis and threat triage across Splunk Enterprise Security, Splunk SOAR and Microsoft Sentinel, plus the supporting data sources and security appliances, and deciding what goes to incident handling
- Providing on-call cover as part of a 24x7 roster, so second-line escalations are answered round the clock
- Designing, developing, testing and maintaining detection rules, alerts and analytics across the monitoring tool-set - tuning logic, thresholds, allow-lists, suppression and severity so false positives fall and coverage of new threats rises
- Giving first-line analysts regular, constructive feedback and coaching on technique, analytical approach and reporting, and helping new joiners find their feet
- Supporting the duty second-line analyst through the week - watching open tasks, chasing pending actions, and flagging anything that threatens service continuity
- Taking part in purple-team exercises to test and improve detection coverage
- Working with the threat hunting team to turn their findings into automated detections wherever that is possible
- Contributing to service improvement: finding the workflow inefficiencies, the monitoring blind spots, and saying what should change
- Writing and updating the operational documentation, procedures, run-books and knowledge-base articles the whole team relies on
- Representing the monitoring function in project planning, implementation and transition, so visibility requirements are considered early, and advising on detection content, log-source integration and security-tool configuration
- Working with colleagues across the wider security organisation and with external partners
- Ad-hoc work when it is needed - special investigations, projects, whatever keeps the operation effective
Requirements
- At least three years hands-on in a security operations centre or a closely related monitoring environment
- A proven expert-level record of analysing complex security incidents and writing clear, authoritative reports and recommendations for the teams and partners who act on them
- Real fluency extracting, normalising and interrogating raw log data from varied sources - Windows event logs, Linux syslog, Sysmon, endpoint detection platforms such as Microsoft Defender, SentinelOne or CrowdStrike - using Splunk, Microsoft Sentinel or Elastic Kibana. Filtering, correlating and visualising events to verify an alert, reconstruct what an attacker did across hosts, and hand over evidence someone can act on
- Hands-on packet capture analysis with Wireshark, tcpdump or Zeek - pulling traffic apart to corroborate an alert and rebuild a timeline
- The ability to turn attacker techniques and threat intelligence into working detection logic, and to run structured peer reviews of other analysts’ investigations that actually find the gaps
- Designing, developing and maintaining detections across monitoring, endpoint and cloud security tooling - Splunk, Microsoft Sentinel, Azure, AWS
- Supporting or mentoring less experienced analysts, with feedback they can use
- Practical automation work: spotting the repetitive manual task and building the enrichment or workflow that removes it
- Strong written and spoken communication - investigation notes, escalation summaries and documentation that read well under pressure
- Professional English
- A bachelor’s degree in a related discipline with three years of related experience - or, exceptionally, five years of extensive and progressive expertise in this kind of work
- A relevant certification such as CISSP, CISM, a GIAC credential (GCIH, GCFA, GSEC) or CompTIA CySA+
Nice to have
- A degree in cyber security, IT or computer science
- Time in a regulated, high-control environment - defence, government, financial services or comparable
- Cloud-native security monitoring on Azure or AWS, and hybrid estates
- Building detections from network and edge devices such as Cisco, Fortinet, Palo Alto or similar
- Work for or with a military or governmental organisation
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.adzuna.be
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
EM
Eli McGarvie
Data Analyst Salary in the UK
about 3 years ago
EM
Eli McGarvie
7 Most Popular Web Developer Jobs in Europe
over 3 years ago
LM
Luis Minvielle
Why Upskilling And Reskilling is Important For Developers
over 2 years ago