The TU/e Department of Mathematics and Computer Science and JADS in ’s-Hertogenbosch are jointly developing CTILab, a laboratory designed to translate cutting-edge research in cybersecurity, cyber monitoring, and threat intelligence into market-ready solutions.
CTILab is being built in close collaboration with the Eindhoven Security Hub Security Operations Center (ESH-SOC), which was also established and is operated by TU/e M&CS. ESH’s success serves as the foundation for the CTILab initiative.
We are therefore looking for a cybersecurity engineer (medior) who will lead the technical security monitoring and threat intelligence operations at the CTILab in close collaboration with ESH-SOC.
As a cybersecurity engineer, you will analyze evidence of incoming threats to our customers based on the latest information that is developing on the market, such as vulnerabilities.
Knowing how to analyze security events using SIEM technologies and being able to handle them is something that you know how to do and gets you excited. We expect you to identify threats to the organizations we monitor and to be active in reporting and evaluating these jointly with colleagues, supervisors and supporting junior analysts. Contributing to the deployment, management, and growth of a cloud-native, next-generation, highly scalable security information platform is also part of the job. You will be involved in the evolution discussion of the platform with all development teams to understand the infrastructure and manage the right technology and business alignment with partners, working closely with engineers, analysts and researchers and help driving the CTILaband ESH-SOC maturity lifecycle to stay ahead of the innovation curve.
Information - Analyze security events (Tier 2): deconstruct and analyze complex patterns from data, relating contextual factors (e.g., related to a customer’s environment) to evidence from the data.
- Inform customers, partners and other stakeholders of security incidents and support remediation efforts.
- Create/expand tools to translate security monitoring use-cases into monitoring rulesets, and to simplify service operation and monitoring.
- Contribute to the development and maintenance of the ESH-SOC infrastructure and of the security sensors deployed at customer facilities, assuring timely updates and a smooth operation cycle.