Medior SOC Analyst.
As a Medior SOC Analyst, you are the sharp eye in our detection and response. You spar with threat hunters, ethical hackers and DFIR specialists, and handle most response actions yourself.
Apply nowSeparate signal from noise, own the response
Our Detect business unit delivers Managed Detection & Response built on the full Microsoft Security ecosystem, with solutions such as NDR and OT Security added on top, plus extra log sources such as application logs. The result is holistic, multi-layered monitoring that looks beyond a single layer of a client environment.
You work daily with the Microsoft Security ecosystem and the other platforms we deploy for our clients, analyzing, assessing and following up on threats. You spar with fellow analysts, threat hunters, ethical hackers and DFIR specialists, so every incident gets looked at from more than one angle. You quickly separate signal from noise, false positive or something real, and handle most response actions yourself. When an incident turns genuinely complex, you bring in a senior analyst in good time and solve it together. You work hybrid, three days a week in our Zoetermeer office, and take part in the on-call rota for 24/7 client coverage.
What you will do
- Investigate and follow up on security incidents, in Microsoft Defender and Microsoft Sentinel and in the other systems we monitor for clients
- Interpret alerts and translate them into clear reports with concrete recommended actions
- Carry out response actions independently, handling most of them yourself as a medior
- Improve detections, gather threat intelligence and tune playbooks
- Share knowledge, mentor junior analysts where needed and work with threat hunters and incident responders, including across borders
- Actively help make SOC processes smarter, faster and better
What you bring
Must have:
- MBO-4 or HBO level of working and thinking
- At least 3 years of experience in a Security Operations Center
- At least 3 years of experience following up on incidents in Microsoft Defender and Microsoft Sentinel
- Broad knowledge of Microsoft 365, Azure AD / Entra ID and endpoint security
- SC-500 and SC-300 or SC-401, or working toward them. Vendor-neutral certifications are a welcome addition
- Clear and proactive communication, structured way of working, calm under pressure
- You guide and coach junior analysts where needed, supporting their development
- Good command of Dutch and English, spoken and written (B2 level)
Nice to have:
- Experience with CrowdStrike Falcon EDR or other Falcon products, given the collaboration with our international SOC
Why you will love working here
Competitive salary
Market-competitive salary, mobility and phone allowance, 24 vacation days.
Close-knit SOC team
A close-knit, technically strong team where knowledge sharing comes naturally.
Real independence
The freedom to work independently and make an impact within a growing MDR service.
Room to grow
Training and certification opportunities to keep your knowledge up to date.
Hybrid + free lunch
Hybrid working with modern tools and a healthy dose of humor in the team.
Social events + study trip
Monthly social events, team outings and an annual study trip.
Apply now
Share your LinkedIn profile and motivation with us. We'll get in touch as soon as possible.
Other open positions
Junior SOC Analyst
Grow into a full-fledged SOC analyst in practice, coached by experienced colleagues.
Defensive SecuritySenior SOC Analyst
Handle complex incidents independently and deepen your expertise in a SOC specialization.
Defensive SecurityDetection Engineer
Design advanced detection rules for SIEM, EDR, and XDR platforms in Barcelona.
®