Department: Cyber Services and Capabilities
Location: NLD Rijswijk (3 days per week onsite)
This position is a critical role within the organization, serving as the technical lead for our SOC and the primary point of contact for potential security incident escalation during significant incidents or crisis situations. The role involves close collaboration with Senior Management and Senior Analysts, provides guidance and mentorship to junior staff, develops continuous improvement processes, and contributes to business development opportunities within Global Management Solutions. It requires deep technical knowledge of IDS/IPS, full packet capture devices, firewalls, DDoS detection, and SIEM platforms, and serves as the technical escalation point for incidents, incident handlers, and incident remediation documentation.
Key Responsibilities
- Serve as the technical conscience of the SOC
- Represent the SOC in Service Activations
- Perform quality assurance processes & procedures and continuous improvement of the SOC
- Act as the principal point of contact for potential security incident escalation during significant incidents or crisis situations, in collaboration with the Computer Incident Response Team, Senior Management, and Senior Analysts
- Guide and mentor junior staff members
- Act as a functional team lead and escalation point for Senior Analysts
- Contribute to continuous business development opportunities within Global Management Solutions
- Maintain an advanced understanding of emerging threats and vulnerabilities
- Develop and maintain training plans for all analysts within the Security Operations Centre
- Foster collaborative relationships with internal stakeholders and clients, with a strong emphasis on growth
- Document and develop new processes related to security monitoring procedures
- Deliver customer service that consistently exceeds customer expectations
- Serve as an escalation point for all members of the SOC team, offering assistance and mentorship as necessary
Minimum Requirements
- Minimum HBO working/thinking level
- Experience within a SOC Senior Analyst role
- Previous experience working in a technical client‑facing capacity within a SOC
Desirable Requirements
- Splunk Certified Power User / Advanced Power User
- CompTIA Certifications (Security+, Network+, Linux+, Cloud+)
- Crest, GIAC or CISSP Certification
- Degree in a related field
- Understanding of compliance standards & frameworks
- Other relevant certifications
Behaviors
- Working hours: 0900‑1730 Mon‑Fri, with 24/7 on‑call roster every 6 weeks
- Professionalism – conduct yourself with integrity and ethical behaviour in all interactions and situations
- Proactive – demonstrate a proactive approach to process improvement and creation, ensuring conformity to the standards of the MXDR SOC
- Collaboration – work well within a team environment, communicating effectively with colleagues from different departments and sharing insights to improve security posture
- Adaptability – embrace changes in technology and processes, adapting to new challenges and learning quickly in a dynamic security landscape
Job Benefits
- Competitive salary commensurate with experience
- Flexible working hours and the option to work from home or at the office
- Favourable pension scheme, 26 vacation days (+4 mandatory days off), and 8% holiday pay with a full‑time contract
- Extensive development opportunities through training, TechTalks, events, and the internal Fox Academy
- Company‑provided laptop and business phone (up to €25 per month reimbursement for personal phone use)
- Remote work allowance for hybrid working
- Performance bonus and profit sharing
- Daily lunch meal provided in office locations
Please note that we are currently unable to sponsor visas for this position.
This role involves mandatory pre‑employment background checks due to the nature of the work NCC Group does.
We are committed to diversity and flexibility in the workplace.