ANVA logo

Senior SOC Engineer

ANVA

Amersfoort
Full-time
5-10 years experience
On-site

Key Skills

Security Operations
Incident Response
Detection Engineering
SIEM
Cloud Security
AWS
Telemetry Monitoring
Detection Logic
Incident Investigation
Automation
Python
Bash
Infrastructure As Code
Detection As Code
CrowdStrike
Elastic Stack

Job Description

Introduction ANVA has developed a new multi-tenant SaaS contract management platform for insurers, combining new technology with fifty years of domain expertise. Security is a strategic investment at ANVA as we continue to scale our cloud-native SaaS platform in a highly regulated industry. We are looking for a SOC Engineer to build and own ANVA's detection and incident response capability from the ground up. This role focuses on building monitoring capabilities, detections, automation, and response playbooks. Your Impact As a Senior SOC Engineer, you will define and implement the future of detection engineering and incident response across ANVA. You will own telemetry visibility, build and tune detections, lead incident investigations, develop automation, and serve as the primary technical expert on monitoring and response. Working directly with the IT Security Lead, you will have significant autonomy and influence over the security direction of the company. You will own the build-out of our detection engineering and incident response capability, working alongside our managed detection and response (MDR) partner and supporting the technical controls behind our ISAE 3000 assurance program. Rather than inheriting someone else's security operations model, you will define it yourself. Within two years, you will be able to look at a mature detection and response capability and confidently say: "I built that." Key Responsibilities Detection & Visibility Own telemetry coverage across cloud, endpoint, identity, application, and infrastructure log sources Assess and prioritize the detection and response roadmap against a defined threat model Tune MDR-managed and baseline detections to the insurance and fintech threat landscape Develop custom detection logic where coverage gaps exist Balance detection effectiveness against alert fatigue and operational noise Incident Response & Automation Design and maintain incident response playbooks covering unauthorized access, data exfiltration, and breach scenarios Build triage and evidence collection automation Define alert thresholds and escalation criteria used by the MDR partner Lead investigations during security incidents Run tabletop exercises and continuously improve response procedures Compliance & Governance Own technical controls supporting the ISAE 3000 assurance program Support auditors with detection and response-related inquiries Develop and hand over operational runbooks and logging standards to IT, Development, and Operations teams Ensure monitoring controls remain aligned with regulatory and customer expectations Who Are You? You are a Security Engineer with: 7+ years of experience in Security Operations, Incident Response, or Detection Engineering Proven experience creating, testing, and tuning detection logic within SIEM or security data platforms Experience leading incident investigations from scoping through containment and post-incident reporting Experience working with MDR or outsourced SOC partners Strong knowledge of cloud and application telemetry, including AWS environments Experience with CloudTrail, VPC Flow Logs, GuardDuty, IAM, and identity attack paths Familiarity with Spring Boot applications and containerized microservices Experience working with endpoint telemetry across Windows, Linux, and macOS Knowledge of CrowdStrike, AWS Security Lake, Elastic Stack, or equivalent platforms Experience with Infrastructure-as-Code and Detection-as-Code approaches Scripting skills in Python, Bash, or similar languages Strong communication skills and stakeholder management capabilities Nice to have: experience with SSDLC and application security tooling such as Aikido, SAST, and SCA platforms

Core Responsibilities

Build and own ANVA’s detection and incident response capability, including telemetry coverage, detection logic, incident investigations, response playbooks, and automation. Maintain monitoring controls and operational runbooks, lead incident response improvements, and support technical controls for the ISAE 3000 assurance program.

Requirements

Requires at least 7 years of experience in security operations, incident response, or detection engineering, with proven SIEM detection development and tuning and experience leading investigations. Candidates should have strong AWS and cloud telemetry knowledge, experience with MDR partners and endpoint monitoring, scripting skills, and familiarity with containerized applications and Infrastructure-as-Code or Detection-as-Code approaches.

About ANVA

Industry: Software Development

Company size: 51-200 employees

Vol trots maakt ANVA al meer dan 50 jaar softwareoplossingen voor de verzekeringsbranche. Meer dan 10.000 financieel professionals werken met onze software om miljoenen consumenten en duizenden ondernemers een goede verzekering aan te kunnen bieden. De wensen, eisen en ervaringen van onze klanten staan aan de basis van onze producten. Maar we zijn méér dan alleen softwareleverancier. Met enthousiaste, deskundige medewerkers, korte lijnen en servicegerichte instelling is ANVA op alle fronten jouw partner. Ook als het gaat om een gedegen automatiseringsadvies, hulp en ondersteuning bij het dagelijks gebruik van onze software, ICT-beheer of cursussen voor uw medewerkers. Je kunt altijd bij ons terecht.

Added Today