6 дней назад
SOC Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SOC Analyst (Cybersecurity): Monitoring, investigating, and responding to security incidents across managed detection and response services with an accent on SIEM, SOAR, EDR/XDR, threat hunting, and log analysis. Focus on tuning detection rules, automating workflows, investigating indicators of compromise, and maintaining continuous 24/7 security monitoring.
Location: Cape Town, South Africa; hybrid with a minimum of two days per week in the office
Work includes a 24/7 shift rotation with evening, night, and weekend shifts.
Company
is a global intelligence and cybersecurity consultancy providing managed services, advisory, and incident response.
What you will do
- Monitor and analyse security alerts from EDR, SIEM, and other security tools.
- Investigate and respond to security incidents, including containment, mitigation, and remediation.
- Conduct threat hunting for indicators of compromise and advanced threats.
- Tune detection rules, automate workflows, and improve incident detection accuracy.
- Perform detailed log analysis and collaborate with threat intelligence specialists.
- Document incidents, investigations, responses, and resolutions while participating in 24/7 shift rotations.
Requirements
- 2–3 years of experience working in a Security Operations Centre with hands-on alert and incident response experience.
- Experience with XDR, SIEM, and EDR platforms such as SentinelOne Singularity, Microsoft Sentinel, Microsoft Defender for Endpoint, or CrowdStrike.
- Knowledge of alert triage, event correlation, threat investigation, incident escalation, common cyber threats, attack techniques, and security frameworks.
- Working knowledge of Windows, Linux, Active Directory, and Microsoft 365 security monitoring.
- Bachelor’s degree in cybersecurity, information security, computer science, or a related discipline.
- Permission to work in South Africa by the start of employment and availability for shift and on-call rotations.
Nice to have
- Experience with SOAR platforms, Azure and Microsoft 365 cloud security monitoring, or MSSP/MDR environments.
- Experience developing detection rules, SIEM use cases, and security playbooks.
- Knowledge of threat intelligence feeds and MITRE ATT&CK mapping.
- Certifications such as CompTIA CySA+, SC-100/SC-200, GCIH, Certified SOC Analyst, or Blue Team/SOC Level 1 or 2.
Culture & Benefits
- Hybrid working and flexible working hours.
- 23 days of annual holiday, increasing to 28 days, plus bank holidays.
- Private pension with up to 7% company-matched contributions and life insurance of four times annual salary.
- Medical aid, gap cover, employee assistance support, flu vaccinations, and eye-care reimbursement.
- Parental support, fertility treatment leave, recognition programmes, and access to Headspace.
Hiring process
- Submit an up-to-date CV through the application link.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →