A complete application in a minute — tailored resume and cover letter, ready to send.
Defenced is seeking an experienced SOC Analyst to join a close-knit, dedicated team in the Netherlands. You will own the full security operations chain—from onboarding and detection engineering to incident response and client conversations—driving proactive security beyond traditional SOC roles.
The role emphasizes collaboration across a non-siloed SOC, with continuous development of detections, automation, and mentoring of peers, alongside direct client communication and 24/7 protection of
Are you an experienced SOC Analyst who gets excited about staying one step ahead of hackers?
Then you're the new SOC analyst we're looking for!
You know that most SOC roles ultimately boil down to the same thing: triaging alerts, closing tickets, sending reports. So do we. That's why we're building something different.
At Defenced, you're not just another specialist on the team. You're a Defender. That might sound like marketing speak, but it describes how we work. We think like attackers. We don't sell peace of mind to clients; we deliver control. And yes, that demands more from you.
You work in a SOC without silos. Every Defender on our team owns the full chain: from onboarding and detection engineering to incident response and client conversation. Not because we're too small to do it differently, but because we believe the best detection comes from someone who also understands what's behind those data streams.
Monitor, analyse and respond to security incidents for Dutch organisations
Develop and improve detections and use cases on our next-generation platform - no separate SIEM and SOAR, one integrated platform
Onboard new clients, including setting up data streams and detection scenarios
Contribute to automation and improvement projects within the SOC
Coach fellow analysts
Work with the SOC Lead on the continued development of the SOC
Client contact is not a side note. You explain what you see, what it means and what needs to happen. Directly, substantively, without an intermediary.
Our SOC protects client environments 24/7. Shifts outside office hours are part of the role.
Demonstrable experience in a SOC or comparable security operations environment
Knowledge of incident response, detection and log analysis
Experience with SIEM or XDR platforms
The drive to improve, not just to process
The ability to guide colleagues and own projects end to end
Proficiency in Dutch and English, spoken and written
Relevant certifications (GSOC, GMON, GCIA, GOSI or equivalent) - or the willingness to pursue them. We actively invest in that.
Nice to have: experience with scripting or automation, threat hunting or purple teaming.
Defenced has been certified Great Place to Work three years running. Not as a goal, but as an outcome. 99% of our Defenders say they are treated fairly. That's culture, not HR policy.
Beyond that:
We help organisations discover their real risk, make bold decisions and take control of their digital world. No fear as a sales argument. No checkbox security. That's what we do, every day.
If that's where you want to go too - let's talk.