SOC Specialist
Jarviss · Operations · Reporting to SOC Team Lead
About the role
The SOC Specialist sits at the top of the analyst career path at Jarviss. Where the rest of the SOC responds to what’s happening, you focus on what’s coming next – driving detection coverage, reducing dwell time, and translating findings into concrete improvements for clients. This is not a ticket-processing role. It’s for someone who thinks in hypotheses, takes end-to-end ownership, and raises the technical maturity of the SOC over time.
What you’ll do
Threat hunting & detection engineering
You design and execute structured, hypothesis-driven threat hunts and translate outcomes into permanent, higher-fidelity detections. In practice, that means:
- Building and tuning detection rules and correlation queries in XSOAR and XDR platforms
- Maintaining a hypothesis library tied to real threat intelligence
- Tracking and reporting on detection coverage gaps with a roadmap for improvement
- Keeping clients regularly informed on hunting campaigns and what they mean in practice
Malware analysis
You analyse suspicious files, scripts, and binaries – static and dynamic – and make sure findings don’t stop at a report. Concretely:
- Extracting IOCs and behavioural patterns and feeding them back into detection rules
- Maintaining a sandboxed analysis environment with tooling (e.g. ANY.RUN) kept current
- Writing reports consumable by both technical and non-technical audiences
Customer onboarding & security advisory
You own the technical readiness of new environments before they enter steady-state operations, and stay close to assigned clients throughout the engagement:
- Validating alert fidelity, playbook coverage, and false positive rates before handover
- Briefing Tier 2 on customer-specific context and signing off on readiness
- Preparing and presenting MXDR reports, formulating prioritised remediation recommendations
- Acting as security advisor and liaison for assigned customers, aligned to the agreed reporting frequency
Service improvement & knowledge transfer
- Mentoring SOC analysts and reviewing escalated cases with structured feedback
- Identifying process and tooling improvements based on hunting and incident patterns
- Contributing to after-action reviews and maintaining internal knowledge base content
- Stepping in as Tier 2 during high-volume periods or absences – this is an expected part of the role
What we’re looking for
5-8 years in cybersecurity, at least 3 in a SOC or incident response function. Beyond the experience, you bring:
- Bachelor’s degree in IT, Cybersecurity, or a related field.
- You communicate clearly across audiences, document your reasoning, and take ownership without needing to be managed.
- Proficiency in query languages for investigation and detection rule authoring
- Solid malware analysis skills – static (strings, PE headers, disassembly) and dynamic (sandbox, process monitoring, network capture)
- Working knowledge of Windows and Linux internals from an attacker’s perspective: process injection, persistence mechanisms, LOTL binaries
- Familiarity with MITRE ATT&CK, threat actor profiling, and threat intelligence platforms
- Exposure to cloud environments and cloud-native telemetry
- Understanding of Active Directory and identity infrastructure from both IT and attacker angles
- Familiarity with Cortex XDR, XSOAR, and/or Microsoft Defender is expected.
Relevant certifications:
- XSOAR Engineer
- Cortex XDR Analyst
- Microsoft Security Operations Analyst Associate
What you’re authorised to do
As SOC Specialist you can independently:
- Execute and close threat hunting campaigns
- Create, modify, and retire detection rules across XDR/SOAR platforms
- Publish malware analysis reports for external distribution
- Lead high-severity incident management and client communication
- Represent Jarviss in client-facing advisory and MXDR reporting sessions
- Onboard new customers and sign off on operational readiness
- Escalate directly to the SOC Team Lead or Operations Manager when a finding warrants immediate action
What we offer:
You’ll be part of a scale-up, with real impact on the company’s growth.
Jarviss offers an environment focused on personal development, where eagerness to learn is rewarded with training and study opportunities.
In addition to your salary:
- Group insurance
- Hospitalization insurance
- Smartphone + subscription
- Laptop
- Meal vouchers
- Company car
The Jarviss offices are located in Lochristi and Wommelgem. We give the confidence and freedom to work independently from home (in mutual consultation).
We expect someone who can work independently. Standard office hours are a formality; you get the job done and work when it suits you best as long as the result is there.
You’ll join a dynamic team of entrepreneurs and experts. We work hard, but we invest equally in team building and spirit within the company. Jarviss is a family that values ”together.”
If you’re ready to take the next step in your career and join a fast-paced, innovative
company, we want to hear from you