About the Role
<div><p>Shape the Future of Renewable Energy Security as SOC Engineer!<br /><br />Are you a seasoned Splunk expert passionate about safeguarding critical infrastructure? We're looking for a talented SOC Engineer with 3-5 years of experience in Splunk engineering and detection engineering to join our growing Security Operations Center.<br /><br />You'll be instrumental in ensuring the stability, reliability, and long-term security of our client's digital platform, a cornerstone for renewable energy professionals across Europe. If you value transparency, predictable system behavior, accountable data handling, and robust security as core design principles, this is your opportunity to make a significant impact.<br /><br />Join us and contribute to a secure and sustainable energy future!</p><h3>Description</h3><h2>Responsibilities SOC Engineer (Splunk ES)</h2><ul><li>Administer Splunk stack components relevant to SOC operations, including the search tier, data ingestion path, forwarders, licensing, and availability model;</li><li>Own the data onboarding and normalization pipeline, encompassing inputs, CIM-aligned mapping, and the quality of index-time and search-time extractions;</li><li>Build and maintain correlation searches, Risk-Based Alerting (RBA) logic, and detection content aligned with the MITRE ATT&CK framework;</li><li>Maintain the quality of the Asset & Identity framework within Splunk Enterprise Security (ES) to ensure accurate enrichment and risk scoring;</li><li>Create analyst-facing dashboards, investigation views, and workflow automation using SPL and adaptive response actions;</li><li>Integrate Security Orchestration, Automation, and Response (SOAR) playbooks for repeatable tier-1 automation;</li><li>Conduct platform health reviews, tuning sessions, and capacity planning;</li><li>Define and enforce Role-Based Access Control (RBAC) in Splunk ES in alignment with least-privilege principles.</li></ul><h3>Requirements</h3><h2>Requirements SOC Engineer (Splunk ES)</h2><ul><li>Completed HBO or university degree in IT (preferably Software Engineering or Cybersecurity);</li><li>Minimum 3 years of experience as a Security Engineer;</li><li>3-5 years of Splunk administration and security-content engineering (including ES/Security Premium Apps);</li><li>Strong SPL proficiency (macros, lookups, accelerated data models, tstats-based search patterns);</li><li>Hands-on integration of log sources (firewall, EDR, AD/identity, cloud telemetry) with CIM normalization;</li><li>Practical detection engineering mindset (signal-to-noise tuning, risk scoring, false-positive control);</li><li>Knowledge of operating system security, network security, and secure development methods;</li><li>Hands-on knowledge of AWS cloud security and operations;</li><li>Good spoken and written Dutch;</li><li>Clear communication of technical decisions to both analyst and non-technical stakeholders;</li><li>Linux/Unix operational capability for Splunk infrastructure support;</li><li>Splunk Certified Architect and/or Splunk ES Certified Admin;</li><li>At least one valid technical security certification (e.g., OSCP, GCIH, GMON, GCIA, AWS Certified Security) or will