IT Security Analyst
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Location: Antwerp, Belgium (hybrid working may be available)
Rate: €600/day
Industry: Life Sciences
Role Overview
You will strengthen the organisation’s cyber defence capability across enterprise and regulated environments, focusing on Cybersecurity Analysis & Detection, Incident Management and Crisis Management. You will monitor, analyse and respond to threats, working closely with IT, compliance and business stakeholders to reduce risk and improve security posture.
Key Responsibilities
- Perform security monitoring and triage using SIEM/EDR tooling; investigate suspicious activity and validate alerts.
- Lead and support incident response activities, including containment, eradication, recovery and post-incident lessons learnt.
- Handle Priority 1 security incidents and contribute to crisis communications and decision-making under pressure.
- Develop and tune detection use-cases, correlation rules and threat-hunting hypotheses; reduce false positives.
- Conduct root cause analysis, document evidence, timelines and actions; produce clear incident reports for technical and non-technical audiences.
- Collaborate with infrastructure, cloud and application teams to remediate vulnerabilities and harden systems.
- Support security governance in regulated settings (e.g., GxP considerations), ensuring procedures are followed and auditable.
- Contribute to continuous improvement of playbooks, runbooks, response plans and tabletop exercises.
On-Call Duty
On-call duty according to a rotation system of approximately one week every 3 to 4 weeks. During this period, you may be assigned to handle Priority 1 security incidents, among other things.
Requirements
- Proven experience in SOC, security operations or incident response roles.
- Strong knowledge of attacker techniques (MITRE ATT&CK), malware behaviour, phishing, identity compromise and lateral movement.
- Hands-on experience with SIEM (e.g., Splunk, Sentinel, QRadar) and EDR/XDR platforms.
- Understanding of networking (TCP/IP, DNS, HTTP/S), Windows and Linux security, and logging/telemetry.
- Experience with cloud security monitoring (Azure/AWS) and identity platforms (e.g., Azure AD/Entra).
- Ability to manage incidents end-to-end, including stakeholder management, prioritisation and crisis coordination.
- Familiarity with security standards and best practice (e.g., ISO 27001, NIST) and working in regulated industries.
- Excellent documentation and communication skills; able to explain risk clearly in British English.
We believe in equal opportunity for all and actively encourage applications from diverse backgrounds, experiences, and perspectives.