Second Line Security Event Analyst

Vector Synergy
Brussel, Belgium
about 1 month ago
Apply on be.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Data Analysis Microsoft Azure Cloud Computing Security Cyber Security Network Security Log Analysis Security Information and Event Management Microsoft Sentinel Fortinet Splunk Cisco

Job description

  • Reviewing and validating investigations, supporting First-Line Analysts to ensure that alert closures, escalations, supporting evidence, and investigation notes meet CSOC quality standards, while confirming completeness, accuracy, and procedural compliance;
  • Acting as the technical escalation point for cyber security monitoring;
  • Performing in-depth log analysis and threat triage using SIEM and SOAR platforms, including Splunk Enterprise Security, Splunk SOAR, Microsoft Sentinel, and supporting security tools and data sources.

Requirements

  • Experience in designing, developing and maintaining detection rules, alerts and analytics across SIEM, EDR/XDR and cloud security tools (e.g., Splunk, Microsoft Sentinel, Azure, AWS);
  • Experience supporting or mentoring less-experienced analysts, providing constructive feedback on investigation quality and reporting standards;
  • Practical experience with automation or SOAR use cases, identifying repetitive manual tasks and creating enrichment or workflow improvements.

Desirable:

  • Experience working in a regulated, high control environment such as defence, government, financial services or other enterprise sectors;
  • Hands on experience with cloud native security monitoring (Azure, AWS) and hybrid environments;
  • Experience with developing detections from network and Edge security devices such as Cisco, Fortinet/Fortigate, Palo Alto, or comparable appliances.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on be.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Fortinet firewall administrative passwords leaked on the dark net

Chris Heilmann Chris Heilmann +1 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:05 min

Automating threat detection with SIEM solutions

Antonio De Mello +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all