*** Stay up to date with the GPC's latest opportunities ***  Upload your CV   Register   

[6322] Second Line Security Event Analyst

Start date: Negotiable
Clearance: NATO Secret or equivalent
Location: Mons, BE

Skill, Knowledge & Experience:
• Minimum three years of hands-on experience in a Security Operations Centre (SOC, CSOC, GSOC or equivalent) or a closely related cyber monitoring environment.
• Proven expert level track record of conducting in depth analysis of complex cyber security incidents and producing clear, authoritative reports and recommendations for supporting teams and external partners.
• Adept at extracting, normalising and interrogating raw log data from diverse sources (e.g., Windows Event Logs, Linux syslog, Sysmon, EDR/XDR platforms such as Microsoft Defender, Sentinel One, or CrowdStrike) using SIEM and query tools (Splunk, Microsoft Sentinel, Elastic Kibana). Able to filter, correlate and visualise events to verify alerts, reconstruct attacker activity across hosts, and provide actionable evidence for escalation and remediation decision
• Hands-on packet-capture (PCAP) analysis experience – extracting, filtering and interpreting network traffic with tools such as Wireshark, tcpdump or Zeek to corroborate alerts, reconstruct attack timelines and support escalation decisions.
• Demonstrable ability to translate attacker TTPs and threat intel into operational detection logic and to conduct structured quality or peer reviews of analyst investigations, identifying gaps and recommending improvements.
• Experience in designing, developing and maintaining detection rules, alerts and analytics across SIEM, EDR/XDR and cloud security tools (e.g., Splunk, Microsoft Sentinel, Azure, AWS).
• Experience supporting or mentoring less-experienced analysts, providing constructive feedback on investigation quality and reporting standards.
• Practical experience with automation or SOAR use cases, identifying repetitive manual tasks and creating enrichment or workflow improvements.
• Strong written and verbal communication skills, with a history of producing clear investigation notes, escalation summaries and documentation.
• Relevant cyber security certifications (e.g., CISSP, CISM, GIAC certified credentials such as GCIH, GCFA, or GSEC; CompTIA CySA+) or equivalent recognised professional training.

Desirable
• A university degree (Bachelor's) in Cyber Security, Information Technology, Computer Science or a related discipline.
• Experience working in a regulated, high control environment such as defence, government, financial services or other enterprise sectors.
• Hands on experience with cloud native security monitoring (Azure, AWS) and hybrid environments.
• Experience with developing detections from network and edge security devices such as Cisco, Fortinet/Fortigate, Palo Alto, or comparable appliances.
• Experience in working for or supporting a military or governmental organization

Contract
Belgium
Negotiable
GPC006322
Emilio Perri
emilio@gpc.work
02031545027