
Security Operations Center – Tier 2 Analyst
Introduction
As the Security Operations Center – Tier 2 Analystwill lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation pointforTier 1analysts,customersor other departments This role supports incident detection, escalation, and responseactivities withincustomer environments, in line with agreed SOC service scope and service level agreements (SLAs).Youwill have hadpreviousexperience in handling escalation from Tier 1 and direct work in security monitoring, threat intelligence, or incident response
What will you be doing?
Perform advanced analysis of escalated security incidents and support investigation efforts.
Act as an escalation point for Tier 1 analysts andprovideexpert guidance during incident response activities.
Develop and tune detection rules and use cases in SIEM and other platforms.
Perform threat hunting based on intelligence and behavioral analysis.
Conduct forensic analysis and reverse engineering of malware when needed.
Collaborate with threat intelligence teams to enrich investigations.
Provide strategic recommendations to improve SOC processes and technologies.
Mentor junior analysts and contribute to training programs.
Participate in detection validation and lessons‑learned activities to enhance SOC detection and response.
A day in this role:
Monitoring & Detection
Validatecomplexalerts escalatedbyTier 1
Determinescope, impact, and severity of confirmed incidents.
Perform deep log analysis, forensic investigations, and develop custom detection rules.
Implement containment,mitigationand remediationactionsin accordance with playbooks and customer agreements
Understanding TTPs (tactics, techniques, procedures) of threat actors
Ability to develop custom detection rulesand correlation logic
Investigation & Analysis
Analyze data patterns and outliers toidentifythreat actor behaviors and insider threats.
Conduct deep investigations into logs, network telemetry, and endpoint activity.
Document findings, actions taken, and recommended next steps.
Incident Response Support
Assist the SOC team during active security incidents by collecting evidence andcontaininglow‑severity threats as per playbooks.
Follow established runbooks to ensure consistent and compliant response actions.
Respond to escalated security incidents requiring advanced analysis.
Provide containment recommendations and support remediation.
Access Management
Processing user access requests (add, remove,modify) following established workflows.
Enforcing least‑privilege principles and role‑based access standards.
Conducting periodic access reviews (user accounts, permissions, group memberships).
Investigating and escalating suspicious access activities or unauthorized access attempts.
Patch Management
Assistwith tracking and verifying system patch status as part of vulnerability review activities.
Monitor patch‑related alerts (failed deployments, outdated versions) within security tools and coordinate remediation with IT operations.
Support the vulnerability management process byvalidatingmissing patchesidentifiedduring scans and escalating high‑risk findings.
(This is aligned with Tier 1’s documented tasks involving vulnerability scans and reporting.)
Reporting & Communication
Generate clear,accurateincident reports and daily shift summaries.
Communicate event details with internal teams in a professional andtimelymanner.
Continuous Improvement
Recommend improvements to detection rules, response processes, and SOC procedures.
Stay current on cyber threat trends, attacker techniques (TTPs), and security best practices.
What do we ask from you?
Experience:
3+ years of experience in cybersecurity, with at least 2 years in a SOC or IR role.
Advancedexpertisein SIEM, EDR, and forensic tools.
Strong understanding of MITRE ATT&CK framework and threat actor TTPs.
Experience with scripting and automation (e.g., Python, PowerShell).
Ability to lead and manage incident response efforts under pressure.
Relevantsecurity certifications from ISC2 or ISACA
Excellent communication and leadership skills.
Qualifications
Bachelor’s degree in IT, Cybersecurity, or CS
Certifications such as:
CompTIA Security+
Microsoft SC-200
CEH,CySA+
GIAC certifications (GSEC, GCIH, GMON)
Experience with:
EDR, IDS/IPS, and network security tools
SIEM/SOAR workflows/playbooks
Threat intelligence platforms
Desired competencies
Strong analytical and problem‑solving skills
Attention to detail
Ability to work under pressure during incidents
Team‑first mindset and willingness to learn
Ability to recognize patterns and anomalies
Prior SOC or IR experience
Strong analysis and investigation skills
Familiarity with threat intelligence and adversary behavior
Ability to perform forensic/log analysis
More advanced certifications preferred
Important:
24/7 SOC environment (shift work may berequired)
Fast‑paced operational setting with tight response timelines
Collaboration with cross‑functional IT and security teams
What we offer
In this challenging and responsible position, you will have the chance to make a significant contribution to industry-leading projects and be connected to our dedicated people and customers. We offer a position in an informal, international and professional working environment with a lot of scope for personal development. By joining our profitable and growing company you will be able to reach your goals and focus on your future.
This position offers a competitive salary range of € 4347 to € 5900 gross per month (excluding 8% holiday allowance). Through exceeding performance expectations, you even have the possibility to grow outside this scale.
On top of your fixed salary you’ll receive the following secondary benefits:
Your application
Are you interested in this position? Then apply now directly on our workday vacancy link with your resume and a short summary about your interest in this role.
Application timeline: In the event of receiving enough suitable applicants, this vacancy can get closed earlier than the mentioned job posting end date.PS: Due to process compliance, we cannot process email applications. Kindly use the correct vacancy link to apply for this vacancy.
Diversity & Inclusion
Vanderlande is an equal opportunity/affirmative action employer. Qualified applicants will be considered without regards to race, religion, color, national origin, gender, sexual orientation, age, marital status, or disability status.
Background screening
For this position it is possible that a background screening will be conducted. This screening can include checks such as verification of identity, qualifications or other relevant records, which may include criminal background or sanctions list checks, in accordance with our internal policies and applicable laws. Any job offer may be extended under the condition that the screening does not give reason to reconsider the hiring decision. Candidates will always be informed about the process and their rights before any screening is initiated.

Vanderlande is a market-leading, global partner for future-proof logistic process automation in the warehousing, airports and parcel sectors. Its extensive portfolio of integrated solutions – innovative systems, intelligent software and life-cycle services – results in the realisation of fast, reliable and efficient automation technology.
The company focuses on the optimisation of its customers’ business processes and competitive positions. Through close cooperation, it strives for the improvement of their operational activities and the expansion of their logistical achievements.
Established in 1949, Vanderlande has more than 11,000 employees and a turnover of 2.3 billion euros.
Toyota Industries Corporation (TICO) acquired Vanderlande in 2017 to cement its global leading position within material handling. It aims to achieve this by increasing its presence in all integrated and automated projects, and capitalising on the synergies between the organisations and the added value they offer to the market.
TICO therefore launched the Toyota Automated Logistics Group (TALG), which consists of Toyota L&F, Bastian Solutions, Vanderlande and viastore. TALG is a global partner for integrated logistic process automation, with its group companies collaborating under the guiding principle: for every challenge, a reliable solution.
In May 2025, Vanderlande completed the acquisition of Siemens Logistics' operations outside the USA and in doing so welcomed more than 2,000 new employees. The acquisition supports the company’s strategic ambition to accelerate its growth in automated logistics, particularly strengthening its capacity to deliver baggage, cargo and digital airport solutions.