744,295open jobs
44,695companies
107,333added this week
Browse all
Salary
≈ $94k – $200k per year (Estimated)
Location
In office (Vancouver)
Seniority
Senior · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Sep 24, 2026. Vanderlande scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Vanderlande is a Dutch company founded in 1949 and headquartered in Veghel. It builds automated baggage handling, parcel sortation and warehouse systems together with the software that runs them. Its systems operate in hundreds of airports and distribution centres worldwide.

Job Title

Cybersecurity Analyst - Tier 2

Job Description

The Security Operations Center - Tier 2 Analyst will lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation point for Tier 1 analysts, customers or other departments. This role supports incident detection, escalation, and response activities within customer environments, in line with agreed SOC service scope and service level agreements (SLAs). You will have had previous experience in handling escalation from Tier 1 and direct work in security monitoring, threat intelligence, or incident response

Key Responsibilities

  • Perform advanced analysis of escalated security incidents and support investigation efforts.
  • Act as an escalation point for Tier 1 analysts and provide expert guidance during incident response activities.
  • Develop and tune detection rules and use cases in SIEM and other platforms.
  • Perform threat hunting based on intelligence and behavioral analysis.
  • Conduct forensic analysis and reverse engineering of malware when needed.
  • Collaborate with threat intelligence teams to enrich investigations.
  • Provide strategic recommendations to improve SOC processes and technologies.
  • Mentor junior analysts and contribute to training programs.
  • Participate in detection validation and lessons-learned activities to enhance SOC detection and response.

Additional Responsibilities

Monitoring & Detection

  • Validate complex alerts escalated by Tier 1
  • Determine scope, impact, and severity of confirmed incidents.
  • Perform deep log analysis, forensic investigations, and develop custom detection rules.
  • Implement containment, mitigation and remediation actions.in accordance with playbooks and customer agreements
  • Understanding TTPs (tactics, techniques, procedures) of threat actors
  • Ability to develop custom detection rules and correlation logic

Investigation & Analysis

  • Analyze data patterns and outliers to identify threat actor behaviors and insider threats.
  • Conduct deep investigations into logs, network telemetry, and endpoint activity.
  • Document findings, actions taken, and recommended next steps.

Incident Response Support

  • Assist the SOC team during active security incidents by collecting evidence and containing low-severity threats as per playbooks.
  • Follow established runbooks to ensure consistent and compliant response actions.
  • Respond to escalated security incidents requiring advanced analysis.
  • Provide containment recommendations and support remediation.

Access Management

  • Processing user access requests (add, remove, modify) following established workflows.
  • Enforcing least-privilege principles and role-based access standards.
  • Conducting periodic access reviews (user accounts, permissions, group memberships).
  • Investigating and escalating suspicious access activities or unauthorized access attempts.

Patch Management

  • Assist with tracking and verifying system patch status as part of vulnerability review activities.
  • Monitor patch-related alerts (failed deployments, outdated versions) within security tools and coordinate remediation with IT operations.
  • Support the vulnerability management process by validating missing patches identified during scans and escalating high-risk findings. (This is aligned with Tier 1’s documented tasks involving vulnerability scans and reporting.)

Reporting & Communication

  • Generate clear, accurate incident reports and daily shift summaries.
  • Communicate event details with internal teams in a professional and timely manner.

Continuous Improvement

  • Recommend improvements to detection rules, response processes, and SOC procedures.
  • Stay current on cyber threat trends, attacker techniques (TTPs), and security best practices.

Required Qualifications

  • 5+ years of experience in cybersecurity, with at least 2 years in a SOC or IR role.
  • Advanced expertise in SIEM, EDR, and forensic tools.
  • Strong understanding of MITRE ATT&CK framework and threat actor TTPs.
  • Experience with scripting and automation (e.g., Python, PowerShell).
  • Ability to lead and manage incident response efforts under pressure.
  • Relevant security certifications from ISC2 or ISACA
  • Excellent communication and leadership skills.

Preferred Qualifications

  • Bachelor’s degree in IT, Cybersecurity, or CS
  • Certifications such as:
  • CompTIA Security+
  • Microsoft SC-200
  • CEH, CySA+
  • GIAC certifications (GSEC, GCIH, GMON)
  • Experience with:
  • EDR, IDS/IPS, and network security tools
  • SIEM/SOAR workflows/playbooks
  • Threat intelligence platforms

Key Competencies

  • Strong analytical and problem-solving skills
  • Attention to detail
  • Ability to work under pressure during incidents
  • Team-first mindset and willingness to learn
  • Ability to recognize patterns and anomalies
  • Prior SOC or IR experience
  • Strong analysis and investigation skills
  • Familiarity with threat intelligence and adversary behavior
  • Ability to perform forensic/log analysis
  • More advanced certifications preferred

Work Environment

  • 24/7 SOC environment - day shift with weekend coverage
  • Fast-paced operational setting with tight response timelines
  • Collaboration with cross-functional IT and security teams

Salary range:

This is a full-time, exempt position, eligible to receive a base salary and to participate in an annual performance bonus program. The salary range listed represents the maximum and minimum starting base pay for this position as of the time of posting. Final salary offered will be determined based on factors including but not limited to the candidate's skills and experience. The annual performance bonus program is preset and not candidate dependent.

Salary range for this position is CAD$90,000 to CAD$115,000.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
744,295 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Vancouver
≈ $78k – $166k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Ottawa • Vancouver
DevOps
Incident Management
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
HIPAA
Threat Modeling
Apply
$128k – $161k per year • Hybrid • Full-Time • 5+ years exp • Ottawa
DevOps
VMWare
Apply
≈ $102k – $219k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Calgary
DevOps
Azure
CI/CD
AWS
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Management
ServiceNow
Apply
≈ $64k – $146k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Vancouver
DevOps
GCP
Azure
AWS
IAM
Linux
Windows
Cybersecurity
MITRE ATT&CK
Zero Trust
Least Privilege
Threat Modeling
Active Directory
SIEM
Apply
$70k – $93k per year • Equity • Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • Toronto
DevOps
Azure
AWS
Cybersecurity
SOC 2
GDPR
FedRAMP
Apply
In office • Taipei
Python
JavaScript
Databases
Redis
Frontend
Vue.js
React.js
DevOps
GCP
Azure
CI/CD
AWS
Apply
In office • Taipei
Python
JavaScript
SQL
DevOps
GCP
Azure
AWS
Apply
In office • Taipei
Python
JavaScript
Databases
Redis
Frontend
Vue.js
React.js
DevOps
GCP
Azure
CI/CD
AWS
Apply
≈ $20k – $40k per year (Estimated) • In office • Internship • Taipei
Python
Java
Databases
MySQL
AI/ML
Speech Recognition
Text-to-Speech
DevOps
Terraform
Ansible
CI/CD
Git
Docker
Kubernetes
FinOps
Linux
Cybersecurity
ISO 27001
Management
Jira
QA
Postman
Apply
In office • Taipei
Python
Java
Python
Flask
FastAPI
DevOps
GCP
AWS
Kubernetes
Apply
≈ $47k – $114k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Veghel
Cybersecurity
ISO 27001
Management
ITIL
Apply
≈ $37k – $65k per year (Estimated) • In office • Full-Time • Netherlands
Apply
Site Manager 7 hours ago
≈ $37k – $79k per year (Estimated) • In office • Full-Time • 3+ years exp • Taipei
JavaScript
Node JS
Node JS
PM2
Apply
≈ $50k – $137k per year (Estimated) • Hybrid • Full-Time • Mönchengladbach
Apply
Director Corporate HSE 10 hours ago
$119k – $141k per year (gross) • Hybrid • Full-Time • 10+ years exp • Master's Degree • Veghel
Management
Agile
Apply
≈ $27k – $51k per year (Estimated) • Remote (Canada) • Full-Time • 1+ year exp • Bachelor's Degree • Vancouver
Apply
Hybrid • Full-Time • 8+ years exp • PhD • Vancouver
Python
JavaScript
PHP
SQL
Databases
PostgreSQL
Redis
Memcached
Frontend
Next.js
React.js
DevOps
CI/CD
AWS
Apply
$36k – $42k per year • In office • Full-Time • Vancouver
Apply
$74k – $92k per year • In office • 5+ years exp • Master's Degree • Vancouver
Apply
$58k per year • In office • 3+ years exp • Vancouver
Apply
See all jobs
This is one of many
744,295 more open roles from verified company boards, updated every day.