> Markdown version of [/jobs/ext/2784154-it-security-analyst](https://www.wearedevelopers.com/jobs/ext/2784154-it-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Analyst - **Company:** Source - **Location:** Antwerpen, Belgium - **Salary:** €156,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Identity and Access Management, Linux Security Modules, Azure Active Directory, Phishing, Security Information and Event Management, TCP/IP, Data Logging, Mitre Att&ck, QRadar, Cyber Threat Analysis, Splunk, GXP - **Published:** September 8, 2026 - **Apply:** https://www.careerboard.com/be/en/find-jobs-in-Belgium/-6A279C772E94D451DC/ ## About the Role * Proven experience in SOC, security operations or incident response roles. * Strong knowledge of attacker techniques (MITRE ATT&CK), malware behaviour, phishing, identity compromise and lateral movement. * Hands-on experience with SIEM (eg, Splunk, Sentinel, QRadar) and EDR/XDR platforms. * Understanding of networking (TCP/IP, DNS, HTTP/S), Windows and Linux security, and logging/telemetry. * Experience with cloud security monitoring (Azure/AWS) and identity platforms (eg, Azure AD/Entra). * Ability to manage incidents end-to-end, including stakeholder management, prioritisation and crisis coordination. * Familiarity with security standards and best practice (eg, ISO 27001, NIST) and working in regulated industries. * Excellent documentation and communication skills; able to explain risk clearly in British English. By applying for this role, you consent to SGI contacting you by telephone regarding recruitment services, market updates, and relevant business opportunities ## Description Role Overview You will strengthen the organisation's cyber defence capability across enterprise and regulated environments, focusing on Cybersecurity Analysis & Detection, Incident Management and Crisis Management. You will monitor, analyse and respond to threats, working closely with IT, compliance and business stakeholders to reduce risk and improve security posture., * Perform security monitoring and triage using SIEM/EDR tooling; investigate suspicious activity and validate alerts. * Lead and support incident response activities, including containment, eradication, recovery and post-incident lessons learnt. * Handle Priority 1 security incidents and contribute to crisis communications and decision-making under pressure. * Develop and tune detection use-cases, correlation rules and threat-hunting hypotheses; reduce false positives. * Conduct root cause analysis, document evidence, timelines and actions; produce clear incident reports for technical and non-technical audiences. * Collaborate with infrastructure, cloud and application teams to remediate vulnerabilities and harden systems. * Support security governance in regulated settings (eg, GxP considerations), ensuring procedures are followed and auditable. * Contribute to continuous improvement of playbooks, runbooks, response plans and tabletop exercises. On-Call Duty On-call duty according to a rotation system of approximately one week every 3 to 4 weeks. During this period, you may be assigned to handle Priority 1 security incidents, among other things. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)