Senior SOC Engineer
# Senior SOC Engineer **ANVA bv** · 3817 Amersfoort · `On-site` 🕒 **Статус:** *Опубликовано: 12 дней назад* · *Источник: Indeed* --- ### About the Role Introduction ANVA has developed a new multi-tenant SaaS contract management platform for insurers, combining new technology with fifty years of domain expertise. Security is a strategic investment at ANVA as we continue to scale our cloud-native SaaS platform in a highly regulated industry. We are looking for a SOC Engineer to build and own ANVA's detection and incident response capability from the ground up. This role focuses on building monitoring capabilities, detections, automation, and response playbooks. Your Impact As a Senior SOC Engineer, you will define and implement the future of detection engineering and incident response across ANVA. You will own telemetry visibility, build and tune detections, lead incident investigations, develop automation, and serve as the primary technical expert on monitoring and response. Working directly with the IT Security Lead, you will have significant autonomy and influence over the security direction of the company. You will own the build-out of our detection engineering and incident response capability, working alongside our managed detection and response (MDR) partner and supporting the technical controls behind our ISAE 3000 assurance program. Rather than inheriting someone else's security operations model, you will define it yourself. Within two years, you will be able to look at a mature detection and response capability and confidently say: "I built that." Your Key Responsibilities Detection & Visibility - Own telemetry coverage across cloud, endpoint, identity, application, and infrastructure log sources - Assess and prioritize the detection and response roadmap against a defined threat model - Tune MDR-managed and baseline detections to the insurance and fintech threat landscape - Develop custom detection logic where coverage gaps exist - Balance detection effectiveness against alert fatigue and operational noise Incident Response & Automation - Design and maintain incident response playbooks covering unauthorized access, data exfiltration, and breach scenarios - Build triage and evidence collection automation - Define alert thresholds and escalation criteria used by the MDR partner - Lead investigations during security incidents - Run tabletop exercises and continuously improve response procedures Compliance & Governance - Own technical controls supporting the ISAE 3000 assurance program - Support auditors with detection and response-related inquiries - Develop and hand over operational runbooks and logging standards to IT, Development, and Operations teams - Ensure monitoring controls remain aligned with regulatory and customer expectations Who Are You? You are a Security Engineer with: - 7+ years of experience in Security Operations, Incident Response, or Detection Engineering - Proven experience creating, testing, and tuning detection logic within SIEM or security data platforms - Experience leading incident investigations from scoping through containment and post-incident reporting - Experience working with MDR or outsourced SOC partners - Strong knowledge of cloud and application telemetry, including AWS environments - Experience with CloudTrail, VPC Flow Logs, GuardDuty, IAM, and identity attack paths - Familiarity with Spring Boot applications and containerized microservices - Experience working with endpoint telemetry across Windows, Linux, and macOS - Knowledge of CrowdStrike, AWS Security Lake, Elastic Stack, or equivalent platforms - Experience with Infrastructure-as-Code and Detection-as-Code approaches - Scripting skills in Python, Bash, or similar languages - Strong communication skills and stakeholder management capabilities - Nice to have: experience with SSDLC and application security tooling such as Aikido, SAST, and SCA platforms Additional benefits - 13th month - 8% holiday allowance per year - 27,5 vacation days per year based on full-time employment - A premium-free pension, meaning ANVA covers the full pension contribution, allowing you to retain more net income - The option to work from abroad for 4 weeks a year - A budget of € 750 to set up your home work environment - Training and development programs at ANVA’s expense - Company-organized events, ranging from karaoke and football tournaments to laser tag - Free coffee, soft drinks, and fruit, plus a partially subsidized lunch by ANVA, with the option to order take away dinner for home. Soort dienstverband: Fulltime, Parttime, Vaste baan Salaris: Tot €6.965,00 per maand Arbeidsvoorwaarden: - Bedrijfsfeesten - Bedrijfsopleiding - Budget voor professionele ontwikkeling - Fietsplan - Gezondheidsprogramma - Kerstpakket - Kosteloos parkeren - Lunchkorting - Mogelijkheid tot promotie - Pensioen - Personeelskorting - Productkorting werknemers - Telefoon van de zaak - Vrijdagmiddagborrel Screeningsvragen: - Do you live in The Netherlands? - Have you built and ran playbooks? - Do you have experience with Threat Hunting? (Not Threat Modeling) - Have you improved Security Lakes? Werklocatie: Hybride werken in 3817 Amersfoort
Наблюдалась 2026-10-07, впервые 2026-09-24, источник — Indeed.