Senior SOC Engineer

ANVA

Amersfoort

On-site

EUR 90,000 - 120,000

Full time

15 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

ANVA is seeking a Senior SOC Engineer to build and own our detection and incident response capability. You will define telemetry visibility, tune detections, and lead investigations, working with MDR partners and supporting the ISAE 3000 assurance program.

In this role you will shape the security operations model, own security telemetry across cloud and endpoints, and drive automation and playbooks to mature our cloud-native SaaS platform.

Qualifications

  • 7+ years in Security Operations, Incident Response, or Detection Engineering.
  • Proven experience creating, testing, and tuning detection logic within SIEM or security data platforms.
  • Experience leading incident investigations from scoping through containment and post-incident reporting.
  • Experience working with MDR or outsourced SOC partners.

Responsibilities

  • Own telemetry coverage across cloud, endpoint, identity, application, and infrastructure log sources.
  • Assess and prioritize the detection and response roadmap against a defined threat model.
  • Tune MDR-managed and baseline detections to the insurance and fintech threat landscape.
  • Develop custom detection logic where coverage gaps exist.
  • Balance detection effectiveness against alert fatigue and operational noise.
  • Design and maintain incident response playbooks covering unauthorized access, data exfiltration, and breach scenarios.
  • Build triage and evidence collection automation.
  • Define alert thresholds and escalation criteria used by the MDR partner.
  • Lead investigations during security incidents.
  • Run tabletop exercises and continuously improve response procedures.
  • Own technical controls supporting the ISAE 3000 assurance program
  • Support auditors with detection and response-related inquiries
  • Develop and hand over operational runbooks and logging standards

Skills

Security Operations
Incident Response
Detection Engineering
SIEM
MDR / SOC
Cloud telemetry
Python / Bash

Tools

CrowdStrike
Elastic Stack
GuardDuty
CloudTrail
IAM
Terraform

Job description

ANVA has developed a new multi-tenant SaaS contract management platform for insurers, combining new technology with fifty years of domain expertise. Security is a strategic investment at ANVA as we continue to scale our cloud-native SaaS platform in a highly regulated industry.

We are looking for a SOC Engineer to build and own ANVA's detection and incident response capability from the ground up. This role focuses on building monitoring capabilities, detections, automation, and response playbooks.

Your Impact

As a Senior SOC Engineer, you will define and implement the future of detection engineering and incident response across ANVA. You will own telemetry visibility, build and tune detections, lead incident investigations, develop automation, and serve as the primary technical expert on monitoring and response. Working directly with the IT Security Lead, you will have significant autonomy and influence over the security direction of the company.

You will own the build-out of our detection engineering and incident response capability, working alongside our managed detection and response (MDR) partner and supporting the technical controls behind our ISAE 3000 assurance program.

Rather than inheriting someone else's security operations model, you will define it yourself. Within two years, you will be able to look at a mature detection and response capability and confidently say: "I built that."

Key Responsibilities
Detection & Visibility
  • Own telemetry coverage across cloud, endpoint, identity, application, and infrastructure log sources
  • Assess and prioritize the detection and response roadmap against a defined threat model
  • Tune MDR-managed and baseline detections to the insurance and fintech threat landscape
  • Develop custom detection logic where coverage gaps exist
  • Balance detection effectiveness against alert fatigue and operational noise
  • Design and maintain incident response playbooks covering unauthorized access, data exfiltration, and breach scenarios
  • Build triage and evidence collection automation
  • Define alert thresholds and escalation criteria used by the MDR partner
  • Lead investigations during security incidents
  • Run tabletop exercises and continuously improve response procedures
Compliance & Governance
  • Own technical controls supporting the ISAE 3000 assurance program
  • Support auditors with detection and response-related inquiries
  • Develop and hand over operational runbooks and logging standards to IT, Development, and Operations teams
  • Ensure monitoring controls remain aligned with regulatory and customer expectations
Who Are You?

You are a Security Engineer with:

  • 7+ years of experience in Security Operations, Incident Response, or Detection Engineering
  • Proven experience creating, testing, and tuning detection logic within SIEM or security data platforms
  • Experience leading incident investigations from scoping through containment and post-incident reporting
  • Experience working with MDR or outsourced SOC partners
  • Strong knowledge of cloud and application telemetry, including AWS environments
  • Experience with CloudTrail, VPC Flow Logs, GuardDuty, IAM, and identity attack paths
  • Familiarity with Spring Boot applications and containerized microservices
  • Experience working with endpoint telemetry across Windows, Linux, and macOS
  • Knowledge of CrowdStrike, AWS Security Lake, Elastic Stack, or equivalent platforms
  • Experience with Infrastructure-as-Code and Detection-as-Code approaches
  • Scripting skills in Python, Bash, or similar languages
  • Strong communication skills and stakeholder management capabilities
  • Nice to have: experience with SSDLC and application security tooling such as Aikido, SAST, and SCA platforms
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC Engineer: Detection & Incident Response Lead
Senior SOC Engineer: Detection & Incident Response Lead

ANVA • Amersfoort

On-site
EUR 90,000 - 120,000
Manager of Proactive Cyber Defence & Engineering
Manager of Proactive Cyber Defence & Engineering

Booking.com • Amsterdam

On-site
EUR 150,000 - 210,000
Health insurance
Headspace access for you and family
Global Employee Assistance Program
+1
Enterprise Security Engineer
Enterprise Security Engineer

Atlassian • Amsterdam

On-site
EUR 120,000 - 150,000
DevSecOps Engineer
DevSecOps Engineer

Huxley • Veldhoven

On-site
EUR 65,000 - 90,000
Senior Software Engineer, Agents
Senior Software Engineer, Agents

Eye Security • Rotterdam, Den Haag

On-site
EUR 90,000 - 130,000
Real ownership in a small autonomous 팀
AI-augmented engineering focus
Competitive compensation package
+1
SOC Analyst
SOC Analyst

Northwave Cyber Security • Utrecht

On-site
EUR 55,000 - 75,000
25 vacation days plus all Dutch national holidays
€200 net annual allowance for flexible and remote working
Learning budget from €700 to €1,200 per year
Security Operations Center – Tier 2 Analyst
Security Operations Center – Tier 2 Analyst

Vanderlande • Veghel

On-site
EUR 65,000 - 90,000
40 vacation days
Flexible hours
Hybrid workplace
+8
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Workatbackbase • Amsterdam

On-site
EUR 90,000 - 130,000
SOC Lead
SOC Lead

ANWB • Wassenaar

On-site
EUR 52,965 - 85,753
Eindejaarsuitkering van 5,58%
25 verlofdagen en 13 adv-dagen
Thuiswerkvergoeding van € 2,45 per dag
+1
Security Operations Engineer
Security Operations Engineer

Nutanix • Amsterdam

On-site
EUR 65,000 - 85,000