Security Operations Center Analyst

BrightStone Group

Den Haag

On-site

EUR 42,000 - 50,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

BrightStone Group in Den Haag runs a dedicated Security Operations Centre for an international institution. The job is on-site, 40 hours weekly, with a 24/7 rota and employment with BrightStone Group. You will monitor, triage and analyse security events using Splunk as the main platform, provide first response, document incidents, and help improve detections through threat hunting, vulnerability management and threat intelligence.

Qualifications

  • A year or more as a SOC analyst, actually working shifts.
  • Splunk, or a SIEM you know well enough to move across from – Sentinel, QRadar, Elastic, ArcSight.
  • Good English, written and spoken. Dutch is not required here and you will barely use it.
  • EU nationality and ten years of history you can document, because you will be screened to EU Secret level.

Responsibilities

  • Monitor, triage and analyse security events, and provide first response.
  • Document incidents and write-up post-event reports to stakeholders.
  • Contribute to detection engineering, threat hunting, vulnerability management and threat intelligence.
  • Collaborate across the organisation to improve detections.

Skills

SOC analyst experience
Shift work experience
English proficiency

Education

EU nationality with ten years history

Tools

Splunk
SIEM (Sentinel/QRadar/Elastic/ArcSight)

Job description

40 hours · 24/7 shifts · employment with BrightStone Group

€ 4.100 gross per month including holiday allowance, plus shift allowance for the rota

A dedicated Security Operations Centre inside an international institution in Den Haag. One client, one team, on-site, around the clock. You would join the rota that keeps it running.

The work itself is monitoring, triage and analysis of security events, and first response when something turns out to be real. Splunk is the platform. Between alerts you write up what happened and answer questions from people across the organisation — and you help make the detections better than they were last month. Detection engineering, threat hunting, vulnerability management, threat intelligence. How much of that you take on is mostly up to you.

One position. The bar on paper is low: a year on shift in a SOC. The bar in practice is a different question, and it has nothing to do with your CV.

What you need
  • A year or more as a SOC analyst, actually working shifts. A day job with occasional on-call is not the same thing and the client will spot the difference
  • Splunk, or a SIEM you know well enough to move across from – Sentinel, QRadar, Elastic, ArcSight
  • Good English, written and spoken. Dutch is not required here and you will barely use it
  • EU nationality and ten years of history you can document, because you will be screened to EU Secret level

Helpful, none of it required: BTL1 or BTL2, GCIH, GSOM, CySA+, CISSP. Writing your own SPL rather than running someone else's. Sigma rules. Any time spent in a defence or NATO environment.

The parts most ads leave out
  • Rotating 24/7 shifts. Nights, weekends, and whichever holiday falls on your week. If you have never worked a rota, speak to someone who has before you reply to this
  • On-site in Den Haag, every shift. No hybrid days. The environment does not permit it
  • Screening runs to roughly three months and you cannot start until it clears. If you already hold EU Secret, NATO Secret or a current Dutch AIVD clearance, lead with that in your first message. It changes your entire timeline and it is the first thing I will ask
  • Employment with BrightStone Group. No ZZP, no doorleen construction
  • The assignment runs to 31 October 2027, with an option to extend

One thing worth saying about the screening. A clearance takes three months, costs you nothing, and stays with you afterwards. There is a small group of people in this country who can walk into work like this, and the only reason the group is small is that most people never start the process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center Analyst
Security Operations Center Analyst

CBSbutler • Randstad

Hybrid
EUR 65,000 - 85,000
Competitive day rates
Referral fees
Principal SOC Analyst
Principal SOC Analyst

Fox-IT • Rijswijk

Hybrid
EUR 90,000 - 120,000
Competitive salary
Hybrid/Remote work option
Pension scheme
+7
Security Operations Center Analyst
Security Operations Center Analyst

Amoria Bond • Utrecht

On-site
EUR 55,000 - 70,000
Security Operations Center – Tier 2 Analyst
Security Operations Center – Tier 2 Analyst

Vanderlande • Veghel

On-site
EUR 65,000 - 90,000
40 vacation days
Flexible hours
Hybrid workplace
+8
SOC Analyst — 24/7 Ops, Detection & Threat Hunting
SOC Analyst — 24/7 Ops, Detection & Threat Hunting

BrightStone Group • Den Haag

On-site
EUR 42,000 - 50,000
Information Security Analyst
Information Security Analyst

BrightStone Group • Amsterdam

On-site
EUR 76,000 - 80,000
SOC Analyst
SOC Analyst

NCC Group • Netherlands

On-site
EUR 48,000 - 65,000
Competitive salary
Pension scheme
Twenty-six vacation days
+5
SOC Analyst
SOC Analyst

Fox-IT • Rijswijk

On-site
EUR 50,000 - 70,000
Competitive salary
Pension scheme
26 vacation days + 4 mandatory days
+6
Security Operations Center Analist
Security Operations Center Analist

Olympia • Eemshaven

On-site
Reiskostenvergoeding
Goede pensioenregeling
Ontwikkelmogelijkheden
+1
SOC Lead (Cybersecurity)
SOC Lead (Cybersecurity)

Openbaar Ministerie • Utrecht

On-site
EUR 75,000 - 110,000
IKB-budget
Reiskostenvergoeding woon-werkverkeer
Studiefaciliteiten
+2