> Markdown version of [/jobs/ext/3573479-lead-security-analyst](https://www.wearedevelopers.com/jobs/ext/3573479-lead-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Analyst - **Company:** i3D.net - **Location:** Capelle aan den IJssel, Netherlands - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Azure, CompTIA Security+, Cyber Security, Monitoring of Systems, Identity and Access Management, Intrusion Detection and Prevention, Microsoft Security Essentials, Microsoft Servers, Secure Coding, Security Information and Event Management, Software Vulnerability Management, Microsoft InTune, Ddos, Splunk, Blue Team (Cyber Security), Security Orchestration, Automation & Response - **Published:** October 4, 2026 - **Apply:** https://www.adzuna.nl/details/5754985218 ## About the Role * Broad security ownership experience: You bring 5+ years of experience securing enterprise environments and have owned security outcomes across identity, infrastructure, endpoints, cloud, and incident response. You have been responsible for improving security posture, not just monitoring it. * Deep Microsoft security expertise: You have hands-on experience securing Azure, Entra ID, Conditional Access, Privileged Identity Management (PIM), Intune, and Microsoft Defender. You understand how to design and implement secure identity and access controls at scale. * SOC/Blue Team experience: You've monitored, detected, and responded to security threats in live environments, led incident investigations, and coordinated remediation across multiple teams. * Security tooling and detection engineering: You have experience implementing and improving SIEM, SOAR, and detection capabilities, developing use cases, tuning alerts, and increasing the effectiveness of security monitoring. * Vulnerability management leadership: You have driven vulnerability remediation programs, partnered with infrastructure teams to prioritize risks, and ensured critical findings are resolved effectively. * Security architecture and stakeholder influence: You are comfortable advising technical teams, challenging existing approaches, and helping shape security controls, standards, and processes across the organization. * Reliable and flexible when needed: You're available when something urgent comes up, even outside of regular hours. * Netherlands-based and Hybrid-ready: You live in the Netherlands and are happy to join us on-site around two days a week. * Experience with SIEM and SOAR tooling: It's a plus if you've worked with tools like Wazuh, Sentinel or Splunk and helped set them up or improve how they're used. * Certifications: CISSP, CISM, CompTIA Security+, CySA+, AZ-500, or SC-900 or other relevant security certifications help, but your real experience matters most. * Familiarity with secure development practices is a bonus. ## Description At i3D.net, we're building our internal security foundation, and you'll be right at the center of it. As our Lead Security Analyst, you'll play a key role in securing our Microsoft environment (including Azure, Entra ID, and IAM), while also working on broader topics like incident response, tooling improvements, and DDOS investigations. We're currently moving to a new Microsoft tenant, which means you'll help shape security from the ground up. This includes defining how access is managed, working closely with the Workspace Management (WSM) team, and supporting the rollout of new security controls and monitoring tools. You'll collaborate closely with our other Security Analysts and subject matter experts to strengthen detection and response and help support our future SOC capabilities and i3D's overall security program. * Ownership of securing our environment from the physical layer all the way up to application: Help design and improve the security of our Azure tenant, Entra ID, and identity and access setup. * Partner with the Workspace Management (WSM) team: You'll guide protecting employees, endpoints and tools. Coordinate with the team that manages rights, starters, movers, and leavers, so access stays under control and risks are caught early. * Tracking, and handling escalated alerts and incidents: Investigate alerts, respond to breaches or policy violations, and make sure issues are resolved properly. * Drive continuous improvement: Suggest smarter ways of working, contribute to the development of security tools and processes, and strengthen the overall security posture of the company. * Partnering with Risk and Compliance teams: maintain and enable our compliance with frameworks such as ISO27001 and NIS2 * Lead vulnerability management: Drive system patching efforts for user endpoints and server infrastructure, making sure vulnerabilities are addressed quickly and effectively. * Support our SOC setup: Help implement or improve tooling like SIEM and SOAR together with the other Security Analyst(s) and partners. * Stay ahead of threats: Track what's happening in the security world and help us stay a step ahead. * Keep others informed: Make sure relevant updates get to the right people, and that security processes are well documented. * Collaborate with external partners: Join conversations with groups like CSIRT-DSP and handle outside security contacts when needed. * Work with internal teams: Server as a SME and business partner to aid other departments and product teams to improve how they handle security in their own systems and workflows. * Our technology environment is safer, easier to manage, and aligned with best practices. * Alerts and incidents are handled faster and with more confidence, reducing overall risk. * Our SOC tooling and processes have improved, thanks to your input and collaboration. * Vulnerability management is running smoothly, and critical systems are patched on time. * The company's overall security posture has strengthened - security is embedded in workflows and visible across teams. * You've made yourself known across the company as someone who drives security forward and gets things done. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Micro-frontends anti-patterns](https://www.wearedevelopers.com/videos/299-micro-frontends-anti-patterns) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)