IT Security Analyst

Il y a 2 jours

Antwerpen, Antwerpen, Belgique Source Technology Limited Temps plein 28 € - 33 € Contrat

Location: Antwerp, Belgium (hybrid working may be available)

Rate: €600/day

Industry: Life Sciences

Role Overview

You will strengthen the organisation’s cyber defence capability across enterprise and regulated environments, focusing on Cybersecurity Analysis & Detection, Incident Management and Crisis Management. You will monitor, analyse and respond to threats, working closely with IT, compliance and business stakeholders to reduce risk and improve security posture.

Key Responsibilities

  • Perform security monitoring and triage using SIEM/EDR tooling; investigate suspicious activity and validate alerts.
  • Lead and support incident response activities, including containment, eradication, recovery and post-incident lessons learnt.
  • Handle Priority 1 security incidents and contribute to crisis communications and decision-making under pressure.
  • Develop and tune detection use-cases, correlation rules and threat-hunting hypotheses; reduce false positives.
  • Conduct root cause analysis, document evidence, timelines and actions; produce clear incident reports for technical and non-technical audiences.
  • Collaborate with infrastructure, cloud and application teams to remediate vulnerabilities and harden systems.
  • Support security governance in regulated settings (e.g., GxP considerations), ensuring procedures are followed and auditable.
  • Contribute to continuous improvement of playbooks, runbooks, response plans and tabletop exercises.

On-Call Duty

On-call duty according to a rotation system of approximately one week every 3 to 4 weeks. During this period, you may be assigned to handle Priority 1 security incidents, among other things.

Requirements

  • Proven experience in SOC, security operations or incident response roles.
  • Strong knowledge of attacker techniques (MITRE ATT&CK), malware behaviour, phishing, identity compromise and lateral movement.
  • Hands-on experience with SIEM (e.g., Splunk, Sentinel, QRadar) and EDR/XDR platforms.
  • Understanding of networking (TCP/IP, DNS, HTTP/S), Windows and Linux security, and logging/telemetry.
  • Experience with cloud security monitoring (Azure/AWS) and identity platforms (e.g., Azure AD/Entra).
  • Ability to manage incidents end-to-end, including stakeholder management, prioritisation and crisis coordination.
  • Familiarity with security standards and best practice (e.g., ISO 27001, NIST) and working in regulated industries.
  • Excellent documentation and communication skills; able to explain risk clearly in British English.

We believe in equal opportunity for all and actively encourage applications from diverse backgrounds, experiences, and perspectives.