Skip to main content
Defensive Security

Medior SOC Analyst.

Location
Netherlands
Hybrid + on-call, Zoetermeer
Employment
Full-time
Team
Detect

As a Medior SOC Analyst, you are the sharp eye in our detection and response. You spar with threat hunters, ethical hackers and DFIR specialists, and handle most response actions yourself.

Apply now
About the role

Separate signal from noise, own the response

Our Detect business unit delivers Managed Detection & Response built on the full Microsoft Security ecosystem, with solutions such as NDR and OT Security added on top, plus extra log sources such as application logs. The result is holistic, multi-layered monitoring that looks beyond a single layer of a client environment.

You work daily with the Microsoft Security ecosystem and the other platforms we deploy for our clients, analyzing, assessing and following up on threats. You spar with fellow analysts, threat hunters, ethical hackers and DFIR specialists, so every incident gets looked at from more than one angle. You quickly separate signal from noise, false positive or something real, and handle most response actions yourself. When an incident turns genuinely complex, you bring in a senior analyst in good time and solve it together. You work hybrid, three days a week in our Zoetermeer office, and take part in the on-call rota for 24/7 client coverage.

What you will do

  • Investigate and follow up on security incidents, in Microsoft Defender and Microsoft Sentinel and in the other systems we monitor for clients
  • Interpret alerts and translate them into clear reports with concrete recommended actions
  • Carry out response actions independently, handling most of them yourself as a medior
  • Improve detections, gather threat intelligence and tune playbooks
  • Share knowledge, mentor junior analysts where needed and work with threat hunters and incident responders, including across borders
  • Actively help make SOC processes smarter, faster and better

What you bring

Must have:

  • MBO-4 or HBO level of working and thinking
  • At least 3 years of experience in a Security Operations Center
  • At least 3 years of experience following up on incidents in Microsoft Defender and Microsoft Sentinel
  • Broad knowledge of Microsoft 365, Azure AD / Entra ID and endpoint security
  • SC-500 and SC-300 or SC-401, or working toward them. Vendor-neutral certifications are a welcome addition
  • Clear and proactive communication, structured way of working, calm under pressure
  • You guide and coach junior analysts where needed, supporting their development
  • Good command of Dutch and English, spoken and written (B2 level)

Nice to have:

  • Experience with CrowdStrike Falcon EDR or other Falcon products, given the collaboration with our international SOC
What we offer

Why you will love working here

Competitive salary

Market-competitive salary, mobility and phone allowance, 24 vacation days.

Close-knit SOC team

A close-knit, technically strong team where knowledge sharing comes naturally.

Real independence

The freedom to work independently and make an impact within a growing MDR service.

Room to grow

Training and certification opportunities to keep your knowledge up to date.

Hybrid + free lunch

Hybrid working with modern tools and a healthy dose of humor in the team.

Social events + study trip

Monthly social events, team outings and an annual study trip.

Apply now

Share your LinkedIn profile and motivation with us. We'll get in touch as soon as possible.

PDF or Word, max. 10 MB

By applying you agree to our privacy policy.