Get more replies from employers
Send a job-specific resume in minutes.
Vanderlande is seeking a Security Operations Center – Tier 2 Analyst to lead complex investigations, coordinate incident response, and improve threat detection and response capabilities. You will serve as an escalation point for Tier 1 analysts and work across customer environments with strong SIEM/EDR, forensic tooling, and MITRE ATT&CK knowledge.
You will develop detection rules, hunt threats, mentor peers, and contribute to playbooks and training programs while maintaining high standards in
Job Description Introduction As the Security Operations Center – Tier 2 Analyst will lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation point for Tier 1 analysts, customers or other departments. This role supports incident detection, escalation, and response activities within customer environments, in line with agreed SOC service scope and service level agreements (SLAs). You will have had previous experience in handling escalation from Tier 1 and direct work in security monitoring, threat intelligence, or incident response
Validate complex alerts escalated by Tier 1; determine scope, impact, and severity of confirmed incidents. Perform deep log analysis, forensic investigations, and develop custom detection rules. Implement containment, mitigation and remediation actions in accordance with playbooks and customer agreements. Understanding TTPs (tactics, techniques, procedures) of threat actors. Ability to develop custom detection rules and correlation logic.
Analyze data patterns and outliers to identify threat actor behaviors and insider threats. Conduct deep investigations into logs, network telemetry, and endpoint activity. Document findings, actions taken, and recommended next steps.
Support Assist the SOC team during active security incidents by collecting evidence and containing low‑severity threats as per playbooks. Follow established runbooks to ensure consistent and compliant response actions. Respond to escalated security incidents requiring advanced analysis. Provide containment recommendations and support remediation.
Processing user access requests (add, remove, modify) following established workflows. Enforcing least‑privilege principles and role‑based access standards. Conducting periodic access reviews (user accounts, permissions, group memberships). Investigating and escalating suspicious access activities or unauthorized access attempts.
Assist with tracking and verifying system patch status as part of vulnerability review activities. Monitor patch‑related alerts (failed deployments, outdated versions) within security tools and coordinate remediation with IT operations. Support the vulnerability management process by validating missing patches identified during scans and escalating high‑risk findings. (This is aligned with Tier 1’s documented tasks involving vulnerability scans and reporting.)
Generate clear, accurate incident reports and daily shift summaries. Communicate event details with internal teams in a professional and timely manner.
Recommend improvements to detection rules, response processes, and SOC procedures. Stay current on cyber threat trends, attacker techniques (TTPs), and security best practices.
In this challenging and responsible position, you will have the chance to make a significant contribution to industry‑leading projects and be connected to our dedicated people and customers. We offer a position in an informal, international and professional working environment with a lot of scope for personal development. By joining our profitable and growing company you will be able to reach your goals and focus on your future. This position offers a competitive salary range of € 4347 to € 5900 gross per month (excluding 8% holiday allowance). Through exceeding performance expectations, you even have the possibility to grow outside this scale.
Important: 24/7 SOC environment (shift work may be required) Fast-paced operational setting with tight response timelines. Collaboration with cross‑functional IT and security teams.
For this position it is possible that a background screening will be conducted. This screening can include checks such as verification of identity, qualifications or other relevant records, which may include criminal background or sanctions list checks, in accordance with our internal policies and applicable laws. Any job offer may be extended under the condition that the screening does not give reason to reconsider the hiring decision. Candidates will always be informed about the process and their rights before any screening is initiated.
Vanderlande is an equal opportunity/affirmative action employer. Qualified applicants will be considered without regards to race, religion, color, national origin, gender, sexual orientation, age, marital status, or disability status.
Every day, millions of people rely on Vanderlande without even knowing it. From baggage checked in at the airport to parcels on their way to someone’s doorstep, our automation solutions help keep the world moving. Vanderlande designs, delivers, and supports automation technology, operational software, and lifecycle services for leading airports and parcel operations worldwide. Across more than 100 countries, our customers rely on us to keep their operations moving reliably, efficiently, and sustainably. Behind every solution are the people who make it happen. At Vanderlande, how we work matters just as much as what we deliver. Our values, Every Day Better, We Care, and Team Play, guide how we collaborate, support each other, and create value for our customers. Here, you can work with colleagues across disciplines and cultures, contribute to work that makes a difference, and build your future in an organisation that invites you to grow. Explore what is possible at Vanderlande and discover how you can make an impact. Aspire. Grow. Achieve. Together.