Security Operations Center – Tier 2 Analyst

Vanderlande

Veghel

On-site

EUR 65,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

40 vacation days
Flexible hours
Hybrid workplace
Health budget
Commuting allowance
Home office stipend
Pension scheme
On-site health facilities
Training facilities
Employee networks
Company restaurant

Job summary

Vanderlande in Veghel, Netherlands is seeking a Security Operations Center - Tier 2 Analyst to lead complex investigations and drive improvements in threat detection and response. You will mentor junior analysts and act as escalation point for Tier 1, customers, and other teams.

The role requires 3+ years in cybersecurity with strong SIEM/EDR skills and applicable certifications. You will work in a 24/7 SOC environment with cross-functional collaboration and a focus on continuous improvement.

Qualifications

  • 3+ years in cybersecurity, with at least 2 years in a SOC or IR role.
  • Advanced expertise in SIEM, EDR, and forensic tools.
  • Strong understanding of MITRE ATT&CK and threat actor TTPs.
  • Experience with scripting and automation (Python/PowerShell).
  • Ability to lead and manage incident response under pressure.
  • Relevant security certifications (ISC2/ISACA).
  • Bachelor’s degree in IT, Cybersecurity, or CS.
  • Certifications such as CompTIA Security+, Microsoft SC-200, CEH, CySA+, GIAC (GSEC/GCIH/GMON).
  • Experience with SIEM/SOAR workflows and playbooks.
  • Experience with threat intelligence platforms.

Responsibilities

  • Validate complex alerts and determine scope, impact, and severity.
  • Develop custom detection rules and correlation logic.
  • Lead incident response efforts under pressure.
  • Assist access management and enforcement of least-privilege.
  • Coordinate patch-related remediation and vulnerability reviews.
  • Generate incident reports and daily shift summaries.
  • Contribute to continuous improvement of SOC processes.
  • Collaborate with cross-functional IT and security teams.

Skills

SIEM
EDR
Forensic tools
Python
PowerShell
MITRE ATT&CK
Leadership

Education

Bachelor's degree in IT/Cybersecurity/CS

Tools

EDR
SIEM/SOAR
IDS/IPS
Threat intel platforms

Job description

Introduction

As the Security Operations Center - Tier 2 Analyst, you will lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation point for Tier 1 analysts, customers, or other departments. This role supports incident detection, escalation, and response activities within customer environments, in line with agreed SOC service scope and service level agreements (SLAs). You will have previous experience in handling escalations from Tier 1 and direct work in security monitoring, threat intelligence, or incident response.

What will you be doing?
  • Perform advanced analysis of escalated security incidents and support investigation efforts.
  • Act as an escalation point for Tier 1 analysts and provide expert guidance during incident response activities.
  • Develop and tune detection rules and use cases in SIEM and other platforms.
  • Perform threat hunting based on intelligence and behavioral analysis.
  • Conduct forensic analysis and reverse engineering of malware when needed.
  • Collaborate with threat intelligence teams to enrich investigations.
  • Provide strategic recommendations to improve SOC processes and technologies.
  • Mentor junior analysts and contribute to training programs.
  • Participate in detection validation and lessons-learned activities to enhance SOC detection and response.
A day in this role:
Monitoring & Detection
  • Validate complex alerts escalated by Tier 1.
  • Determine scope, impact, and severity of confirmed incidents.
  • Perform deep log analysis, forensic investigations, and develop custom detection rules.
  • Implement containment, mitigation, and remediation actions in accordance with playbooks and customer agreements.
  • Understand TTPs (tactics, techniques, procedures) of threat actors.
  • Develop custom detection rules and correlation logic.
Investigation & Analysis
  • Analyze data patterns and outliers to identify threat actor behaviors and insider threats.
  • Conduct deep investigations into logs, network telemetry, and endpoint activity.
  • Document findings, actions taken, and recommended next steps.
Incident Response Support
  • Assist the SOC team during active security incidents by collecting evidence and containing low-severity threats as per playbooks.
  • Follow established runbooks to ensure consistent and compliant response actions.
  • Respond to escalated security incidents requiring advanced analysis.
  • Provide containment recommendations and support remediation.
Access Management
  • Process user access requests (add, remove, modify) following established workflows.
  • Enforce least-privilege principles and role-based access standards.
  • Conduct periodic access reviews of user accounts, permissions, and group memberships.
  • Investigate and elevate suspicious access activities or unauthorized access attempts.
Patch Management
  • Assist with tracking and verifying system patch status as part of vulnerability review activities.
  • Monitor patch-related alerts such as failed deployments and outdated versions within security tools and coordinate remediation with IT operations.
  • Support the vulnerability management process by validating missing patches identified during scans and escalating high-risk findings.
Reporting & Communication
  • Generate clear, accurate incident reports and daily shift summaries.
  • Communicate event details with internal teams in a professional and timely manner.
Continuous Improvement
  • Recommend improvements to detection rules, response processes, and SOC procedures.
  • Stay current on cyber threat trends, attacker techniques (TTPs), and security best practices.
What do we ask from you?
Experience:
  • 3+ years of experience in cybersecurity, with at least 2 years in a SOC or IR role.
  • Advanced expertise in SIEM, EDR, and forensic tools.
  • Strong understanding of the MITRE ATT&CK framework and threat actor TTPs.
  • Experience with scripting and automation, such as Python and PowerShell.
  • Ability to lead and manage incident response efforts under pressure.
  • Relevant security certifications from ISC2 or ISACA.
  • Excellent communication and leadership skills.
Qualifications
  • Bachelor's degree in IT, Cybersecurity, or CS.
  • Certifications such as CompTIA Security+, Microsoft SC-200, CEH, CySA+, and GIAC certifications including GSEC, GCIH, and GMON.
  • Experience with EDR, IDS/IPS, and network security tools.
  • Experience with SIEM/SOAR workflows and playbooks.
  • Experience with threat intelligence platforms.
Desired competencies
  • Strong analytical and problem-solving skills.
  • Attention to detail.
  • Ability to work under pressure during incidents.
  • Team-first mindset and willingness to learn.
  • Ability to recognize patterns and anomalies.
  • Prior SOC or IR experience.
  • Strong analysis and investigation skills.
  • Familiarity with threat intelligence and adversary behavior.
  • Ability to perform forensic and log analysis.
  • More advanced certifications preferred.
Important
  • 24/7 SOC environment; shift work may be required.
  • Fast-paced operational setting with tight response timelines.
  • Collaboration with cross-functional IT and security teams.
What we offer

In this challenging and responsible position, you will have the chance to make a significant contribution to industry-leading projects and be connected to dedicated people and customers. We offer a position in an informal, international, and professional working environment with a lot of scope for personal development. By joining our profitable and growing company, you will be able to reach your goals and focus on your future.

  • 40 vacation days (20 statutory days and a flexible budget worth 20 days).
  • Flexible working hours.
  • A hybrid workplace (40% working from home and 60% in the office).
  • A Health & Wellbeing budget worth €300 per calendar year.
  • Commuting allowance, including full reimbursement of travel by public transport.
  • Working from home allowance.
  • Collective pension scheme and discount on additional health insurance.
  • On-site company health centres with a gym, physiotherapists, and occupational therapists.
  • Vanderlande Academy and training facilities to boost your skills.
  • A variety of Vanderlande Network communities and initiatives.
  • A great company restaurant and coffee bar with barista.
Background screening

For this position, it is possible that a background screening will be conducted. This screening can include checks such as verification of identity, qualifications, or other relevant records, which may include criminal background or sanctions list checks, in accordance with internal policies and applicable laws. Any job offer may be extended under the condition that the screening does not give reason to reconsider the hiring decision.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center – Tier 2 Analyst
Security Operations Center – Tier 2 Analyst

Vanderlande Industries B.V. • Veghel

On-site
EUR 49,000 - 66,000
40 vacation days
Hybrid workplace
Health & Wellbeing budget
+2
Senior SOC Analyst
Senior SOC Analyst

Northwave • Utrecht

Hybrid
EUR 70,000 - 100,000
Pension plan
25 vacation days
Remote working allowance
+2
Information Security Governance & Compliance Officer
Information Security Governance & Compliance Officer

Vanderlande • Veghel

Hybrid
EUR 60,000 - 80,000
40 vacation days
Flexible working hours
Hybrid workplace
+4
SOC Analyst
SOC Analyst

Northwave Cyber Security • Utrecht

On-site
EUR 55,000 - 75,000
25 vacation days plus all Dutch national holidays
€200 net annual allowance for flexible and remote working
Learning budget from €700 to €1,200 per year
SOC Analyst
SOC Analyst

NCC Group • Netherlands

On-site
EUR 48,000 - 65,000
Competitive salary
Pension scheme
Twenty-six vacation days
+5
Principal SOC Analyst
Principal SOC Analyst

Fox-IT • Rijswijk

Hybrid
EUR 90,000 - 120,000
Competitive salary
Hybrid/Remote work option
Pension scheme
+7
Security Automation Engineer
Security Automation Engineer

Northwave • Utrecht

Hybrid
EUR 50,000 - 70,000
Competitive salary with annual review
Pension contributions
25 vacation days plus national holidays
+3
SOC Cyber Security Specialist
SOC Cyber Security Specialist

ON2IT B.V. • Zaltbommel

On-site
EUR 45,000 - 65,000
24 vacation days with the possibility to buy extra
Mobility allowance
Unlimited learning
SOC Analyst
SOC Analyst

Fox-IT • Rijswijk

On-site
EUR 50,000 - 70,000
Competitive salary
Pension scheme
26 vacation days + 4 mandatory days
+6
SOC Cyber Security Specialist
SOC Cyber Security Specialist

On2IT • Netherlands

On-site
EUR 55,000 - 75,000
24 vacation days with the option to buy extra
Mobility allowance
Advancement opportunities
+1