Job details
About this role
Role overview
This position sits within an IT Infrastructure team that supports a large-scale cloud platform used for AI workloads. The security analyst will focus on maintaining compliance posture, responding to incidents, and building automation that keeps the technology environment aligned with recognized security standards. The work blends hands-on incident handling with control validation, evidence collection, and cross-team collaboration with auditors and engineering groups.
Responsibilities
- Monitor, investigate, and respond to security incidents across SIEM, CSPM, and related security tooling. - Evaluate how incidents affect compliance posture and remediate technical compliance violations. - Design and implement detections that surface compliance drift or policy violations. - Partner with internal and external auditors, supplying evidence of adherence to control requirements. - Build and maintain automation for compliance checks and incident investigations, including Logic Apps, PowerShell scripts, and Sentinel playbooks. - Produce reporting and documentation covering incidents, investigations, and compliance activities, working alongside Technology, SecOps, Compliance, and Audit teams.
Requirements
- At least two years of hands-on experience as a security analyst using enterprise security technologies such as SIEM, EDR, and CSPM. - Working knowledge of Microsoft Sentinel, including KQL queries, analytic rules, automation playbooks, and dashboards. - Familiarity with Microsoft Entra ID (identity protection, conditional access, PIM) and Microsoft Purview (DLP, sensitivity labels, insider risk, eDiscovery). - Experience collaborating with auditors and validating evidence for controls such as SOX, DORA, GDPR, or SOC 2 in cloud environments. - Practical experience remediating security incidents, an understanding of the identity and access management lifecycle, and working knowledge of SIEM/SOAR concepts. - Grounding in compliance frameworks such as NIST, SOX, and GDPR, plus intermediate written and spoken English.
Nice to have
- Microsoft certifications SC-200, SC-300, or SC-400. - Exposure to cloud security posture management and vulnerability management tools, plus EDR platforms. - Familiarity with DevOps practices for security automation, including Git and Azure DevOps. - Scripting experience with PowerShell, RESTful or Microsoft Graph APIs, Python, or Bash.
Benefits and work setup
- Competitive compensation with structured opportunities for career growth and continued learning. - Flexible work arrangements, with the option to work remotely across Europe or from an Amsterdam office. - Collaborative, international team culture focused on meaningful infrastructure and AI projects, with room for ownership and innovation.