Skip to content

Open nowPosted 12 hours agoWe saw it 36 min after it went up

Senior Security Operations Engineer

Jobgether4,394 open roles

Where
Netherlands
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Operations EngineerJobgether · Netherlands
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 4 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 12 hours ago

Jobgether median: 4 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Operations Engineer based in Netherlands.

This role offers the opportunity to turn advanced offensive security research into production-ready detection capabilities for modern application security. You will build and maintain security checks designed to identify vulnerabilities, malware, and emerging attack patterns with high accuracy and low false-positive rates. The position combines hands-on security research, detection engineering, testing, and continuous experimentation across evolving threat landscapes. You will work with technologies including OpenGrep, JavaScript, Python, static analysis, cloud infrastructure, and CI/CD pipelines. Your work will also extend into emerging areas such as AI security, LLM vulnerabilities, agentic systems, and MCP security. Collaboration spans engineering, product, AI/ML, and infrastructure teams to ensure detection content is effectively developed, tested, and deployed. This is a hands-on environment for an experienced security professional who enjoys solving complex problems and improving security capabilities at scale.

Accountabilities:

  • Build and maintain production-ready security checks and detection content with a focus on accuracy, broad coverage, and low false-positive rates.
  • Develop new detection rules, primarily using OpenGrep, to identify novel malware and vulnerability patterns.
  • Research vulnerability classes, exploitation techniques, and emerging attack patterns and translate findings into effective production detections.
  • Extend analysis capabilities to support additional programming languages and evolving application technologies.
  • Triage analysis pipeline packages, investigate findings, and validate detection results.
  • Develop attack-chain templates that combine lower-severity findings into higher-impact security scenarios.
  • Create and maintain evaluation harnesses, benchmarks, and testing frameworks to measure detection coverage, accuracy, false-positive rates, exploit reproducibility, and regression performance.
  • Investigate difficult or ambiguous findings and help maintain consistent detection quality across the platform.
  • Apply established detection and exploitation principles while contributing to internal standards and methodologies.
  • Experiment with new security tools and techniques for detecting threats and malware at scale.
  • Monitor developments in application security, offensive security, AI security, LLM vulnerabilities, agentic systems, and MCP ecosystems and incorporate relevant insights into detection engineering.
  • Collaborate with engineering, product, AI/ML, and infrastructure teams to develop, test, integrate, and operate detection content.
  • Integrate detection, testing, and validation into cloud-native and CI/CD development environments.
  • 5+ years of experience in offensive security or application security research, or equivalent experience, with a relevant bachelor's degree plus 2 years of experience.
  • Broad programming knowledge, with strong JavaScript skills required and Python highly desirable.
  • Strong understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomies.
  • Experience writing detection logic for DAST scanners, fuzzers, or comparable security systems, including response interpretation and false-positive management.
  • Hands-on web application penetration testing experience covering OWASP Top 10 vulnerabilities, authentication, authorization, business logic, REST, GraphQL, and related application security areas.
  • Ability to research complex technical problems and work with algorithms and concepts such as Abstract Syntax Trees (ASTs).
  • Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems is highly valued.
  • Familiarity with offensive security tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload-generation techniques.
  • Understanding of HTTP and modern web protocols.
  • Familiarity with cloud infrastructure, containers, CI/CD, and modern DevOps practices is advantageous.
  • Fluent English communication skills, with the ability to explain technical concepts to both technical and non-technical audiences.
  • Strong collaboration skills and good judgment around when to escalate complex or high-impact issues.
  • Hands-on mindset, intellectual curiosity, and willingness to investigate both established application security challenges and emerging threats.
  • OpenGrep or Semgrep experience, static analysis expertise, production system development experience, or exposure to LLMs and prompt engineering are advantageous.
  • Security research contributions such as CVEs, advisories, technical talks, open-source tools, or technical writing experience are a plus.
  • YARA experience is also beneficial.
  • Fully remote working options.
  • Health, pension, and statutory benefits tailored to the employee's country of residence.
  • 24/7 Employee Assistance Program offering emotional support counseling, life coaching, dependent and elder care, financial and legal support, wellness coaching, and new-parent support.
  • Quarterly Thrive-Wellness Days, providing one additional day off each quarter for company-wide rest and renewal.
  • 5 days of paid volunteer time off each year.
  • Paid birthday day off.
  • Employee recognition and rewards programs.
  • Opportunities for personal and professional growth and development.
  • Flexible, globally oriented Total Rewards approach adapted to regional needs.
  • Inclusive and collaborative environment supporting diversity and individuality.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.