SOC Cyber Security Specialist
- On-site
- Zaltbommel, Gelderland, Netherlands
- SOC
Job description
THE ROLE
Our customers trust us to keep their networks out of the news. You are the person who makes that true.
You analyze what is really happening on a customer's network, decide what matters, and configure the controls that stop the next attempt. You work in our Global Security Operations Center (GSOC) in Zaltbommel, part of a global team that runs 24x7. One shift you untangle a routing problem; on another you segment a customer's network into Protect Surfaces and tune the policy that guards them. Always with prevention as the goal: we stop the incident, not just report it.
WHAT YOU WILL DO
Analyze anomalies, alerts and threats, and decide what is real
Fix security issues in routing and networks
Configure security controls along Zero Trust principles
Work hands-on with protocols like SSH, SSL, HTTPS, SMTP and DHCP
Document your work so the next colleague hits the ground running
Advise customers and colleagues, and make complex things simple
WORKING IN SHIFTS
Our SOC does not close.
We work in shifts to ensure 24/7 security for our customers, alongside colleagues in Europe and the US. You will work a rotating pattern:
Two morning shifts (06:00 - 14:30)
Two afternoon shifts (14:00 - 22:30)
Two night shifts (22:00 - 06:30)
Followed by 4 days off
HOW WE WORK WITH AI
AI is built into our service, not bolted on: MDR Detect runs AI-assisted case handling behind our 24x7 human-led GSOC. We also build our own bespoke AI tooling on top of our platform, and the specialists who use it help shape it.
We expect you to understand prompting (structure and context change the answer), reuse (turn a repeated prompt into a skill), verification (a model can be confident and wrong) and privacy (know what goes into which tool). Not an expert yet? Curious and honest about the gaps is what matters.
Job requirements
WHO YOU ARE
● You pull the thread until you understand it
● You can say "I don't know yet" and then go find out
● You care about doing it properly: a sloppy investigation is worse than none
● You can explain a technical problem without making anyone feel stupid
WHAT YOU BRING
Technical Foundation
Networking at CCNA level
Concepts network segmentation, VPN, NAT, DNS and certificates
Security thinking least privilege, defense in depth, and how an attack moves once inside
Systems Windows, macOS and Linux
Protocols the common ones (SSH, SSL, HTTPS, SMTP, DHCP), and the confidence to pick up the rest
Certifications willing to get them. We pay, you study
Ways of working
You use AI daily and can explain how, not just that you do
You can use git (clone, branch, commit, merge request) and write Markdown: our runbooks and AI context live in plain text under version control. This is not a developer role
You respect confidentiality: customer data does not go just anywhere
The rest
Excellent English, spoken and written
Willing to join a 24x7 shift rotation
On-site: this is not a hybrid role, and you live within ~50 minutes of Zaltbommel
Pre-employment screening, due to the sensitive nature of the job
Nice to have: experience with Palo Alto Strata or Cortex, Microsoft Defender or Fortinet FortiGate; SOC, NOC or managed services experience; Dutch; Python, Bash or similar scripting.
WHAT WE OFFER
You will grow fast, because we make sure of it.
A clear path Junior to Medior to Senior, with explicit criteria for each step
Cutting-edge technology for customers all over the world; no two environments are the same
Colleagues who teach and unlimited learning: training, certification and the time to do it
24 vacation days (option to buy more), mobility allowance, shift compensation, catered lunch
Our customers are hospitals, research labs, retailers, banks and manufacturers. When you catch something early, their operation keeps running and the people who depend on it never notice anything happened. That is the point of the job.
Want to join the team? Apply now.
or
All done!
Your application has been successfully submitted!
You've already applied for this job
We appreciate your interest in this position. Unfortunately, you have already applied for this job.
Who are we?
ON2IT is an international cybersecurity company with Dutch origins. In 2005, the company was founded by Lieuwe Jan Koning and Marcel van Eemeren and in 2018 we expanded internationally to the US with an office in Plano, TX. We now have over 300 customers around the world and continue to grow.
More than 20 years of experience has taught us that cybersecurity needs and priorities vary greatly from one company to another. Therefore, together with our customers, we look at which parts of their cybersecurity need the most attention.
The ON2IT team consists of driven employees who want to add something to their profession and want to make a difference. Personal development is important to us. We strive to be the best in the field of IT security.
We are successful in what we do, as evidenced by the growth we experience as an organization year after year. Together we are building an even brighter future. This year, we are growing faster than ever before. Will you be joining our team?

Are you joining our team?
Have we managed to excite you about this job and our company? Then we look forward to receiving your application! Don’t have an up-to-date resume or have questions about our job procedure? Don’t hesitate to call to our HR-team at +31 (88) 22 66 200 to discuss the possibilities.

our locationS
Our Netherlands office is located in the province of Gelderland, directly next to the A2 highway. From both directions (Utrecht and ‘s-Hertogenbosch) you take exit 17 to Zaltbommel. Address (Netherlands) Hogeweg 35 5301 LJ Zaltbommel, Netherlands Address (US, Texas, Plano) 5717 Legacy Dr Suite 250, Plano, TX 75024, United States
