Planon logo

Senior Cybersecurity Operations & Response Lead

Planon

Nijmegen
Full-time
5-10 years experience
Hybrid

€5,300 - €6,000 per month

Key Skills

Cybersecurity Monitoring
Incident Response
SOC Operations
Threat Detection
Security Governance
SIEM Platforms
Detection Engineering
Stakeholder Management
Management Reporting
Risk Management
Regulatory Compliance
SaaS Security
Incident Classification
Remediation Workflows
Audit Evidence Management
Security Metrics

Job Description

At Planon, part of Schneider Electric, this role helps shape, govern and continuously improve our cybersecurity monitoring and incident response capabilities. You will work at the intersection of strategy, governance and operations, ensuring that our monitoring, detection and response processes remain effective, measurable and aligned with business, security and regulatory requirements. Working across Cloud, Product, R&D and Global IT teams, you will define monitoring strategies, drive stakeholder alignment, oversee response performance and help coordinate actions during security incidents. While operational teams remain responsible for day-to-day execution, you play a key role in setting direction, removing obstacles, escalating risks and ensuring critical issues receive the attention they require. What we can challenge you with: Shape the monitoring strategy: Define and continuously improve our monitoring, detection and response approach in collaboration with key business and technology stakeholders. Improve incident response: Strengthen incident response processes, escalation paths and response targets while coordinating significant security incidents and supporting communication and reporting obligations towards the Dutch NCSC (NIS2) and other relevant authorities where required. Drive operational oversight: Monitor incident handling, remediation activities and security service performance, ensuring risks and delays receive appropriate attention. Support security operations: Guide teams on monitoring and response activities, help remove blockers and assist when critical security issues require additional coordination. Deliver management insight: Provide clear reporting on monitoring coverage, incident trends, response performance and key security risks. Lead continuous improvement: Identify opportunities to improve monitoring capabilities, response effectiveness, tooling and operational processes. Support assurance activities: Help maintain audit evidence, support customer assurance activities and demonstrate compliance with security and regulatory requirements. Note: This role combines governance leadership with practical coordination and requires reasonable flexibility to support exceptional security incidents outside normal working hours when needed. Profile You combine cybersecurity depth with a structured and collaborative way of working. You communicate clearly with technical and non-technical stakeholders, create focus when the path is still developing and follow through on priorities without taking over operational ownership. This role is a great fit if you: Have proven of minimum 6 experience in cybersecurity monitoring, incident response, SOC operations, threat detection or security operations governance. Can develop monitoring strategies, governance frameworks, operating models and improvement roadmaps. Understand logging, SIEM platforms, detection engineering, alert management, incident classification, escalation processes and remediation workflows. Have experience coordinating stakeholders during incidents and driving actions across multiple technical teams. Can translate technical findings into clear and actionable management reporting. Are comfortable challenging overdue actions, managing risk discussions and escalating issues when necessary. Have working knowledge of security, privacy and regulatory requirements relevant to European SaaS organizations. Communicate effectively with both technical and non-technical stakeholders and are professionally fluent in English. Good to have A bachelor’s or master’s degree in cybersecurity, information security, computer science, information systems or a related field, or equivalent relevant experience. A relevant certification such as CISSP, CISM, GCIH, CompTIA CySA+ or Microsoft Certified: Security Operations Analyst Associate. Experience with NIS2, the Cyber Resilience Act, BSI C5, SOC operations governance, SIEM capability development, security metrics, audit evidence management or customer assurance activities. Dutch language skills are an advantage. We offer We offer a healthy work-life balance with the flexibility of hybrid working, in a collaborative and learning-oriented environment with opportunities for continuous development. We put our people at the heart of our company and create an inspiring and safe environment that allows everyone to work, learn, live and play. You will work on challenging topics across the organisation and help strengthen Planon’s security resilience. Salary range: EUR 5,300 - EUR 6,000 gross per month, depending on experience. This range reflects a good faith estimate of the expected compensation for this role, based on objective, role-related criteria. The total compensation package includes variable compensation and additional benefits. Would you like to find out more about our salary range and benefits? Click here. Planon is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable law. Excited to build security resilience and drive impact? Join us and help shape how Planon monitors and responds to cybersecurity risk. We may use artificial intelligence (AI) or automated tools to support parts of our recruitment process, such as application screening and candidate assessment. These tools assist our recruiters, and final employment decisions are always made by human professionals.

Core Responsibilities

Shape and govern cybersecurity monitoring and incident response strategies to ensure alignment with business and regulatory requirements. Coordinate significant security incidents and provide management insight through reporting on trends and risks.

Requirements

Requires at least 6 years of experience in SOC operations or incident response with a strong understanding of SIEM and detection engineering. Must be able to communicate technical findings to non-technical stakeholders and have knowledge of European SaaS regulatory requirements.

Benefits

  • Healthy work-life balance
  • Hybrid working
  • Continuous development opportunities
  • Variable compensation

About Planon

Industry: IT Services and IT Consulting

Company size: 1,001-5,000 employees

Planon is the leading global provider of Smart Sustainable Building Management software. We believe building users, owners and services providers deserve better and more integrated experiences. We connect buildings, people and processes, by eliminating data silos and aligning solutions into one shared information platform. By that, we empower all building stakeholders with actionable and meaningful insights. We create places where people work, live, play and learn, that are: • Efficient, attractive, responsive and profitable • Engaging, safe, healthy and resilient • Sustainable and ESG compliant • Powered by data and information We have a positive impact on our users’ lives and our planet, empowering all to answer future needs and upcoming challenges. We build connections. With each other, with our clients and partners, and with our communities. Independent market research and consulting firms have consistently rated Planon as a global leader in the market. Planon has implemented its comprehensive solutions for more than 3,250 clients, supported by offices and partners around the world. Planon. Building Connections.

Added Today