Cyber Threat Hunter
Ministerie van Defensie
Zeist, Utrecht
The Role
Working within a dedicated DFIR team at a national defence cyber security centre, the role involves proactively hunting for advanced digital threats across military IT infrastructure. Day-to-day responsibilities include analysing suspicious activity, developing detection methods, and deploying modern tooling to identify attacks at an early stage — both remotely and on-site.
Skills & Experience
Candidates require at least five years of experience in digital forensics and cybersecurity, alongside relevant SANS/GIAC certifications such as GCFA, GNFA, GASF or GREM. Strong knowledge of networking, malware analysis, multiple operating systems, and scripting in Python or PowerShell is expected. Experience in forensic tooling and CRRT is also required.
Who It Suits
This lead-level position suits an experienced digital forensics and threat-hunting professional comfortable operating in a high-stakes, security-cleared government environment. The role is well suited to someone who can mentor colleagues, communicate findings clearly, and thrive under pressure within a team protecting national security infrastructure.
Typical advertised salary for Incident Response roles in Netherlands: €66,000–€91,000 (median €78,000 — from 16 recent listings analysed by Forensic Focus).
Compare Incident Response salaries in Netherlands →
Certifications mentioned: GCFA · GREM · GNFA · SANS · GASF — find training for these on the DFIR Training Finder.





