> Markdown version of [/jobs/ext/2737906-cyber-security-detection-engineer-soc-escalation-analyst](https://www.wearedevelopers.com/jobs/ext/2737906-cyber-security-detection-engineer-soc-escalation-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Detection Engineer & SOC Escalation Analyst - **Company:** Spektrum - **Location:** Bergen, Belgium - **Experience:** Experienced - **Contract:** Contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Linux, Event Logging, Log Analysis, Packet Analyzer, Security Information and Event Management, Syslog, Tcpdump, Wireshark, Information Technology, Microsoft Sentinel, Fortinet, Kibana, Splunk, SentinelOne Expertise, Cisco - **Published:** September 6, 2026 - **Apply:** https://www.adzuna.be/details/5872063924 ## About the Role * Bachelor's degree in a related field + 3 years post-related experience, or 5+ years of equivalent progressive experience * Minimum 3 years' hands-on SOC/CSOC/GSOC or equivalent monitoring environment experience * Expert-level incident analysis and reporting skills * Strong log analysis skills across Windows Event Logs, Linux syslog, Sysmon, and EDR/XDR platforms (Defender, SentinelOne, CrowdStrike) using SIEM tools (Splunk, Sentinel, Kibana) * Hands-on packet capture analysis (Wireshark, tcpdump, Zeek) * Experience designing/maintaining detection rules across SIEM, EDR/XDR and cloud platforms (Azure, AWS) * Experience mentoring or supporting less experienced analysts * Practical SOAR/automation experience * Strong written and verbal English communication (STANAG 6001 Level 3 equivalent) Desirable: * Bachelor's in Cyber Security, IT, Computer Science, or related field * Experience in defence, government, financial services or other regulated environments * Cloud-native security monitoring experience (Azure/AWS) * Experience with network/edge security devices (Cisco, Fortinet/Fortigate, Palo Alto) * Certifications: CISSP, CISM, GCIH, GCFA, GSEC, CompTIA CySA+ * Experience supporting military or government organizations ## Description This role acts as the technical escalation point within a Cyber Security Operations Centre (CSOC), reviewing and validating investigations from First-Line Analysts, performing deep-dive log and threat analysis, and building/tuning detection content across a modern SIEM/SOAR/EDR toolset, while mentoring junior analysts and contributing to a 24×7 monitoring roster., * Review and quality-check First-Line Analyst investigations, alert closures and escalations * Serve as technical escalation point, performing in-depth log analysis and threat triage (Splunk ES, Splunk SOAR, Microsoft Sentinel) * Provide on-call coverage as part of a 24×7 second-line roster * Design, develop and continuously tune detection rules, alerts and analytics * Coach and mentor First-Line Analysts; support onboarding of new team members * Support the Duty Second-Line Analyst with weekly operational responsibilities * Participate in purple teaming exercises and collaborate with the Threat Hunting Team to operationalize findings * Write and maintain SOPs, runbooks and knowledge-base documentation * Represent CSOC in project/transition planning for monitoring and detection requirements ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)