SOC Engineer (Temp-to-Perm)

Shape the Future of Renewable Energy Security as SOC Engineer!

Are you a seasoned Splunk expert passionate about safeguarding critical infrastructure? We're looking for a talented SOC Engineer with 3-5 years of experience in Splunk engineering and detection engineering to join our growing Security Operations Center.

You'll be instrumental in ensuring the stability, reliability, and long-term security of our client's digital platform, a cornerstone for renewable energy professionals across Europe. If you value transparency, predictable system behavior, accountable data handling, and robust security as core design principles, this is your opportunity to make a significant impact.

Join us and contribute to a secure and sustainable energy future!
The Hague
IT
Zuid Holland
Bachelor Master
Temp to perm Hybrid
4500 - 5000 5000 - 6000 6000 - 7000

Company profile

Shape the Future of Renewable Energy Security as SOC Engineer!

Are you a seasoned Splunk expert passionate about safeguarding critical infrastructure? We're looking for a talented SOC Engineer with 3-5 years of experience in Splunk engineering and detection engineering to join our growing Security Operations Center.

You'll be instrumental in ensuring the stability, reliability, and long-term security of our client's digital platform, a cornerstone for renewable energy professionals across Europe. If you value transparency, predictable system behavior, accountable data handling, and robust security as core design principles, this is your opportunity to make a significant impact.

Join us and contribute to a secure and sustainable energy future!

Job profile

  • Administer Splunk stack components relevant to SOC operations, including the search tier, data ingestion path, forwarders, licensing, and availability model;
  • Own the data onboarding and normalization pipeline, encompassing inputs, CIM-aligned mapping, and the quality of index-time and search-time extractions;
  • Build and maintain correlation searches, Risk-Based Alerting (RBA) logic, and detection content aligned with the MITRE ATT&CK framework;
  • Maintain the quality of the Asset & Identity framework within Splunk Enterprise Security (ES) to ensure accurate enrichment and risk scoring;
  • Create analyst-facing dashboards, investigation views, and workflow automation using SPL and adaptive response actions;
  • Integrate Security Orchestration, Automation, and Response (SOAR) playbooks for repeatable tier-1 automation;
  • Conduct platform health reviews, tuning sessions, and capacity planning;
  • Define and enforce Role-Based Access Control (RBAC) in Splunk ES in alignment with least-privilege principles.

Requirements

  • Completed HBO or university degree in IT (preferably Software Engineering or Cybersecurity);
  • Minimum 3 years of experience as a Security Engineer;
  • 3-5 years of Splunk administration and security-content engineering (including ES/Security Premium Apps);
  • Strong SPL proficiency (macros, lookups, accelerated data models, tstats-based search patterns);
  • Hands-on integration of log sources (firewall, EDR, AD/identity, cloud telemetry) with CIM normalization;
  • Practical detection engineering mindset (signal-to-noise tuning, risk scoring, false-positive control);
  • Knowledge of operating system security, network security, and secure development methods;
  • Hands-on knowledge of AWS cloud security and operations;
  • Good spoken and written Dutch;
  • Clear communication of technical decisions to both analyst and non-technical stakeholders;
  • Linux/Unix operational capability for Splunk infrastructure support;
  • Splunk Certified Architect and/or Splunk ES Certified Admin;
  • At least one valid technical security certification (e.g., OSCP, GCIH, GMON, GCIA, AWS Certified Security) or willingness to obtain one;
  • Experience with other SIEM/SOAR platforms (e.g., Elastic).

Offer

A temp-to-perm, hybrid role in The Hague area, with a competitive salary of €5,000 - €7,000 gross per month. Initially, you will get a flex contract via Independent Recruiters with a possibility to be taken over by the client after a period of time that will be agreed upon.

How we'll proceed. Within four working days we will let you know if you qualify for the position. We will schedule an introductory interview, either digitally or in-person. During this interview we will inform you as fully as possible about the vacancy, the company and the following steps in the procedure. After consulting with you, we will introduce you to our client and then continue to guide you through the application process. The Independent Recruiters Group has a large team of specialized recruiters. Each recruiter has a strong focus on their own area of expertise. This makes them the ideal sparring partner for both the candidate and the client.

SOC Engineer (Temp-to-Perm)
Independent Recruiters Groep BV uses cookies to remember certain preferences and align jobs interests.
Close