Your impact.
As a Senior SOC Engineer, you’ll shape and implement the future of detection engineering and incident response at ANVA. You’ll be responsible for ensuring visibility into telemetry data, building and optimizing detections, leading incident investigations, developing automation, and serving as the primary technical expert in the areas of monitoring and response. You’ll work directly with the IT Security Lead and have a great deal of autonomy and influence over the company’s security strategy.
You will be responsible for further developing our detection engineering and incident response capabilities. In doing so, you will collaborate with our Managed Detection & Response (MDR) partner and support the technical controls underlying our ISAE 3000 assurance program.
Instead of adopting an existing security operations model, you’ll have the opportunity to shape it yourself. In two years, you’ll be able to look at a fully developed detection and response organization and proudly say, “I built that.”
Your main responsibilities.
Detection & Visibility
- Own telemetry coverage across cloud, endpoint, identity, application, and infrastructure log sources.
- Assess and prioritize the detection and response roadmap against a defined threat model.
- Tune MDR-managed and baseline detections to the insurance and fintech threat landscape.
- Develop custom detection logic where coverage gaps exist.
- Balancing detection effectiveness against alert fatigue and operational noise.
Incident Response & Automation
- Designing and maintaining incident response playbooks for situations such as unauthorized access, data exfiltration, and security incidents.
- Developing automation for triage and evidence collection.
- Define the alert thresholds and escalation criteria used by the MDR partner.
- Leading investigations during security incidents.
- Organizing tabletop exercises and continuously improving response procedures.
Incident Response & Automation
- Designing and maintaining incident response playbooks for situations such as unauthorized access, data exfiltration, and security incidents.
- Developing automation for triage and evidence collection.
- Define the alert thresholds and escalation criteria used by the MDR partner.
- Leading investigations during security incidents.
- Organizing tabletop exercises and continuously improving response procedures.
This is what we offer you.
At ANVA, you’ll have the freedom to experiment and deliver results. You’ll work with modern technology in an environment where you’re taken seriously. We offer trust, autonomy, and the opportunity to collaborate with experienced engineers, with a focus on personal development and a healthy work-life balance.
Salary and Benefits
A salary commensurate with your seniority, experience, and impact, with a maximum of €6,965. We consider who you are and what you bring to the table. In addition, you’ll receive benefitsthat make a difference, so you can focus entirely on what you’re here to do.
Vacation days
You get 27.5 vacation days to recharge, travel, or just do nothing. Because sustainable performance starts with sufficient rest. We believe it is important that you have time for yourself, your family, or your passions.
Non-contributory pension
We pay your pension contributions in full. This means you automatically build up your pension for later, without it costing you anything now. That gives you peace of mind and security, just as it should be.
Growth
At ANVA, you will be given the opportunity to develop yourself. Through training, coaching, and (international) career opportunities, you can broaden or deepen your role. Your ambition determines the direction.
Workation
Ready for some sun and inspiration? You will have the opportunity to work temporarily from the Caribbean. This allows you to combine productivity with a unique experience at one of our international locations.
AI First Tech Vision
In every role, we encourage the use of AI as a smart tool to support your daily work. Not as a replacement, but as a powerful complement to help you work faster, better, and more efficiently. This approach fosters innovation while also valuing your own expertise.
Working from home
Hybrid working is a matter of course for us. You will receive a work-from-home budget of €750 to set up a comfortable and professional workspace. This allows you to work just as comfortably at home as you would in the office.
Food & drink
At the office, you can enjoy barista coffee, fresh juices, and fresh fruit. Our hospitality colleagues ensure that you have everything you need. Small details that make your working day just that little bit better.
Fun!
We regularly organize staff events, ranging from substantive sessions to sporting and social activities. Participation is always voluntary, but having fun together is part of who we are.
Financially Fit
You can make use of independent financial advice for your personal situation. Whether it concerns your pension, mortgage, or other financial questions, we are happy to help you look ahead with confidence.
Who are you?
You are a Security Engineer with:
- At least 7 years of experience in Security Operations, Incident Response, or Detection Engineering.
- Proven experience in developing, testing, and optimizing detection logic within SIEM or security data platforms.
- Experience leading incident investigations, from defining the scope to containment and post-incident reporting.
- Experience with MDR partners or outsourced SOC services.
- Strong knowledge of cloud and application telemetry, including AWS environments.
- Experience with CloudTrail, VPC Flow Logs, GuardDuty, IAM, and identity attack paths.
- Familiarity with Spring Boot applications and containerized microservices.
- Experience with endpoint telemetry on Windows, Linux, and macOS.
- Knowledge of CrowdStrike, AWS Security Lake, the Elastic Stack, or similar platforms.
- Experience with Infrastructure-as-Code and Detection-as-Code methodologies.
- Scripting skills in Python, Bash, or similar languages.
- Strong communication skills and stakeholder management capabilities.
- Nice to have: experience with SSDLC and application security tooling such as Aikido, SAST, and SCA platforms
Where will you end up?
For over 50 years, we at ANVA have been developing software for the insurance industry. What began as an industry-led initiative has grown into an innovative fintech company used by more than 10,000 professionals every day. With our software, we help insurers, Managing General Agents and advisors serve millions of customers more effectively and efficiently.

From our offices in Amersfoort and Bergen op Zoom, our team of around 200 colleagues is shaping the future of financial services. We do this using smart technology. For us, AI isn’t just an experiment, but a core and essential component in the development and continuous improvement of our platform. But beyond smart technology, what really sets us apart is our teamwork: collaborating, taking initiative, and getting a little better every day.
When you walk into ANVA, you’ll notice it right away: there’s a great mix of focus, innovation, and fun here! You’ll be working alongside smart, thoughtful, and curious colleagues who love to get things done but also know how to keep things in perspective. We work hard, brainstorm a lot, learn quickly, and celebrate both small and big successes along the way. Where will you end up? A place where your ideas are welcome, new ideas are valued, your growth is taken seriously, and your colleagues are always willing to brainstorm (or grab coffee)!
Sounds like a place where you could settle down? Great. We'd love to get to know you.
Your future colleagues.
Why this job opening does suit you.
Why this job opening doesn't suit you.
Application process
Ready to make a difference?








