SOC Analyst (Temp-to-Perm)
About this role
Ready to be the guardian of the digital pulse of Europe's clean energy future? Our client is building a cornerstone for renewable energy, a stable, future-proof platform that empowers professionals to design, monitor, and operate critical assets across the continent. Imagine a place where trust, reliability, and long-term vision are built into the very code, all while upholding the highest standards of European governance and data responsibility. We're seeking a sharp, investigative mind to join our Security Operations Center. You'll be at the forefront, diving deep into alerts generated by our powerful Splunk Enterprise Security platform, uncovering threats, and ensuring the continued integrity of our vital operations.
If you thrive on dissecting complex events, applying sound judgment, and contributing to a secure, sustainable energy landscape, this is your chance to make a real impact!
- Monitor, triage, and investigate notable events and RBA-driven alerts in Splunk Enterprise Security;
- Perform log correlation and threat analysis across endpoint, network, identity (AD/Okta), and cloud telemetry;
- Execute the incident response flow: triage, containment support, escalation, and documentation, with a focus on Mean Time To Respond (MTTR) reduction;
- Map findings to MITRE ATT&CK to strengthen context and improve detection capabilities;
- Maintain auditable incident records in ticketing/case tooling, including a clear timeline and decision rationale;
- Collaborate with the SOC Engineer to tune noisy detections and reduce false positives;
- Participate in shift handovers and weekly intelligence sharing on Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs).
Requirements
- 2-4 years in SOC or blue-team operations;
- Splunk Proficiency: Hands-on experience with Splunk, including practical SPL usage for searching, dashboard analysis, and incident review;
- Solid understanding of TCP/IP, DNS, HTTP(S), authentication protocols, and common attacker patterns;
- Working knowledge of Windows Event Logs, Sysmon, firewall/proxy logs, and EDR telemetry;
- Familiarity with MITRE ATT&CK and NIST incident response lifecycle;
- Experience with at least one EDR stack (e.g., CrowdStrike, SentinelOne);
- Strong written communication skills for both technical and management audiences.
Nice-to-Have Requirements:
- Splunk Certifications/Admin: Splunk Core Certified Power User and/or Splunk ES administration exposure;
- Basic Python or PowerShell scripting for investigation acceleration;
- Cloud security monitoring exposure in AWS (e.g., CloudTrail, GuardDuty, Security Hub, VPC Flow Logs);
- Security Certifications: CySA+, GCIA, GCIH, or comparable blue-team certification.
Salary
A temp-to-perm, hybrid role in The Hague area, with a competitive salary of €4.500 - €5.500 gross per month. Initially, you will get a flex contract via Independent Recruiters with a possibility to be taken over by the client after a period of time that will be agreed upon.
How we'll proceed. Within four working days we will let you know if you qualify for the position. We will schedule an introductory interview, either digitally or in-person. During this interview we will inform you as fully as possible about the vacancy, the company and the following steps in the procedure. After consulting with you, we will introduce you to our client and then continue to guide you through the application process. The Independent Recruiters Group has a large team of specialized recruiters. Each recruiter has a strong focus on their own area of expertise. This makes them the ideal sparring partner for both the candidate and the client.