Second Line Security Event Analyst

Hainaut Region
Belgium
Onsite
All
NATO Secret
Inter - Igd
Scroll
Ref: 150362

Job description

* Minimum three years of hands-on experience in a Security

 

Operations Centre (SOC, CSOC, GSOC or equivalent) or a closely

 

related cyber monitoring environment.

 

* Proven expert‑level track record of conducting in‑depth analysis

 

of complex cyber‑security incidents and producing clear,

 

authoritative reports and recommendations for supporting teams

 

and external partners.

 

* Adept at extracting, normalising and interrogating raw log data

 

from diverse sources (e.g., Windows Event Logs, Linux syslog,

 

Sysmon, EDR/XDR platforms such as Microsoft Defender,

 

Sentinel One, or CrowdStrike) using SIEM and query tools

 

(Splunk, Microsoft Sentinel, Elastic Kibana). Able to filter, correlate

 

and visualise events to verify alerts, reconstruct attacker activity

 

across hosts, and provide actionable evidence for escalation and

 

remediation decision

 

* Hands-on packet-capture (PCAP) analysis experience –

 

extracting, filtering and interpreting network traffic with tools such

 

as Wireshark, tcpdump or Zeek to corroborate alerts, reconstruct

 

attack timelines and support escalation decisions.

 

Skill, Knowledge & Experience:

 

* Demonstrable ability to translate attacker TTPs and threat intel

 

into operational detection logic and to conduct structured quality or

 

peer reviews of analyst investigations, identifying gaps and

 

recommending improvements.

 

* Experience in designing, developing and maintaining detection

 

rules, alerts and analytics across SIEM, EDR/XDR and cloud

 

security tools (e.g., Splunk, Microsoft Sentinel, Azure, AWS).

 

* Experience supporting or mentoring less-experienced analysts,

 

providing constructive feedback on investigation quality and

 

reporting standards.

 

* Practical experience with automation or SOAR use cases,

 

identifying repetitive manual tasks and creating enrichment or

 

workflow improvements.

 

* Strong written and verbal communication skills, with a history of

 

producing clear investigation notes, escalation summaries and

 

documentation.
 

Apply for this role

Ben Mellor

Hi I'm Ben.

I manage this role

If you would like to know more about this role or similar jobs, please get in contact with me.

Recommend.

this role to a friend

Is this role revelant to any one you know?
Share it with them now.

Email to a friend