Enter a job title or keyword

Senior Security Analyst (Threat Triage, PCAP and Escalation) for NATO with security clearance

WLG


Job Location:

Mons - Belgium

Monthly Salary: Not provided by the employer
Posted: 16 September 2026 (18 hours ago)
Application Deadline: 14 December 2026
Vacancies: 1 Vacancy

Job Summary

Second line is where an alert stops being noise and becomes a decision.

You would be the technical escalation point in a large defence security operations centre inMons Belgium validating what the first line produces digging into the cases they cannot closeand building the detections that stop the same thing reaching them twice.

What you would be doing

  • Reviewing and validating investigations supporting first-line analysts so that alert closuresescalations evidence and notes meet the standard complete accurate and procedurally sound
  • Acting as the technical escalation point for security monitoring: in-depth log analysis andthreat triage across Splunk Enterprise Security Splunk SOAR and Microsoft Sentinel plus thesupporting data sources and security appliances and deciding what goes to incident handling
  • Providing on-call cover as part of a 24x7 roster so second-line escalations are answered roundthe clock
  • Designing developing testing and maintaining detection rules alerts and analytics across themonitoring tool-set tuning logic thresholds allow-lists suppression and severity so falsepositives fall and coverage of new threats rises
  • Giving first-line analysts regular constructive feedback and coaching on technique analyticalapproach and reporting and helping new joiners find their feet
  • Supporting the duty second-line analyst through the week watching open tasks chasing pendingactions and flagging anything that threatens service continuity
  • Taking part in purple-team exercises to test and improve detection coverage
  • Working with the threat hunting team to turn their findings into automated detections whereverthat is possible
  • Contributing to service improvement: finding the workflow inefficiencies the monitoring blindspots and saying what should change
  • Writing and updating the operational documentation procedures run-books and knowledge-basearticles the whole team relies on
  • Representing the monitoring function in project planning implementation and transition sovisibility requirements are considered early and advising on detection content log-sourceintegration and security-tool configuration
  • Working with colleagues across the wider security organisation and with external partners
  • Ad-hoc work when it is needed special investigations projects whatever keeps the operationeffective

What you would bring

  • At least three years hands-on in a security operations centre or a closely related monitoringenvironment
  • A proven expert-level record of analysing complex security incidents and writing clearauthoritative reports and recommendations for the teams and partners who act on them
  • Real fluency extracting normalising and interrogating raw log data from varied sources Windows event logs Linux syslog Sysmon endpoint detection platforms such as Microsoft DefenderSentinelOne or CrowdStrike using Splunk Microsoft Sentinel or Elastic Kibana. Filteringcorrelating and visualising events to verify an alert reconstruct what an attacker did acrosshosts and hand over evidence someone can act on
  • Hands-on packet capture analysis with Wireshark tcpdump or Zeek pulling traffic apart tocorroborate an alert and rebuild a timeline
  • The ability to turn attacker techniques and threat intelligence into working detection logicand to run structured peer reviews of other analysts investigations that actually find the gaps
  • Designing developing and maintaining detections across monitoring endpoint and cloud securitytooling Splunk Microsoft Sentinel Azure AWS
  • Supporting or mentoring less experienced analysts with feedback they can use
  • Practical automation work: spotting the repetitive manual task and building the enrichment orworkflow that removes it
  • Strong written and spoken communication investigation notes escalation summaries anddocumentation that read well under pressure
  • Professional English
  • A bachelors degree in a related discipline with three years of related experience orexceptionally five years of extensive and progressive expertise in this kind of work
  • A relevant certification such as CISSP CISM a GIAC credential (GCIH GCFA GSEC) or CompTIACySA

Nice to have

  • A degree in cyber security IT or computer science
  • Time in a regulated high-control environment defence government financial services orcomparable
  • Cloud-native security monitoring on Azure or AWS and hybrid estates
  • Building detections from network and edge devices such as Cisco Fortinet Palo Alto orsimilar
  • Work for or with a military or governmental organisation

Why this one is worth a look

Detection engineering and deep analysis in the same seat at a scale where the telemetry isgenuinely interesting and the escalations are real.


About Company

Company Logo

Work Life Group Sp. z o.o., agencja zatrudnienia (employment agency) KRAZ no. 19578. NIP 7010247728. ul. Nowogrodzka 50/54 lok. 515, 00-695 Warszawa, Poland.

View Profile View Profile