Cyber Security SOC Analyst
Itonga Resourcing · Johannesburg, Gauteng · Negotiable
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
Our client is looking for an experienced Cyber Security SOC Analyst to join a critical cybersecurity and security operations environment.
We are looking for a hands-on SOC professional with strong experience in security monitoring, SIEM, threat detection, incident investigation, vulnerability management and incident response .
The successful candidate must be able to demonstrate strong practical experience working within a Security Operations Centre (SOC) and across enterprise cybersecurity environments.
Experience with Microsoft Azure / Microsoft security technologies will be highly advantageous.
Duties & Responsibilities
- Monitor security events and alerts across the organisation's security environment.
- Analyse and investigate security alerts and potential cyber incidents.
- Perform first-line and second-line security event analysis and triage.
- Investigate suspicious activity, threats and indicators of compromise.
- Work with SIEM platforms to identify and investigate security events.
- Perform incident response and escalation in accordance with SOC procedures.
- Conduct threat hunting and identify potential security threats.
- Analyse logs from endpoints, servers, networks, cloud environments and security tools.
- Investigate phishing, malware, ransomware and other security incidents.
- Support vulnerability identification, assessment and remediation activities.
- Monitor endpoint detection and response (EDR/XDR) alerts.
- Develop and improve security monitoring and detection use cases.
- Support security investigations and root-cause analysis.
- Maintain accurate incident and investigation records.
- Prepare daily, weekly and monthly SOC/security reports .
- Analyse security trends, incidents, alerts and key performance indicators.
- Escalate significant security incidents to the appropriate technical teams.
- Work closely with infrastructure, networking, cloud and cybersecurity teams.
- Assist with security incident response exercises and continuous improvement.
- Support the development and maintenance of SOC procedures, playbooks and documentation.
Desired Experience & Qualification
- 5+ years of relevant Cyber Security / SOC experience.
- Strong hands-on experience in a Security Operations Centre environment .
- Experience across:
- SOC Operations
- Security Monitoring
- SIEM
- Threat Detection
- Incident Response
- Incident Investigation
- Vulnerability Management
- Threat Hunting
- Experience analysing security logs and alerts.
- Experience investigating security incidents and indicators of compromise.
- Experience with enterprise security technologies and security monitoring tools.
- Strong understanding of networking, operating systems and cybersecurity principles.
- Experience working with security incidents from detection through to resolution or escalation.
- Strong analytical and investigative skills.
Priority Certifications
- GICSP
- IEC/ISA 62443
- SANS/GIAC OT-ICS certifications
- OT OEM certifications , including:
- Siemens
- Schneider Electric
- Rockwell Automation
- ABB
- Honeywell
- CISSP
- CISM
- OSCP
Additional SOC/security certifications will also be considered, including:
- GIAC Security Essentials (GSEC)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Detection Analyst (GCDA)
- GIAC Certified Intrusion Analyst (GCIA)
- CompTIA Security+
- CompTIA CySA+
- Microsoft Certified: Security Operations Analyst Associate
- Microsoft Azure Security Engineer Associate
Interested?
Shortlisted candidates may be required to demonstrate practical experience through examples or high-level evidence of:
- SIEM monitoring – platforms used and types of security events investigated.
- Incident investigation – examples of incidents detected, investigated and escalated.
- Threat detection – detection rules, use cases or methodologies developed or used.
- Incident response – involvement in containment, remediation and recovery.
- Threat hunting – examples of proactive threat-hunting activities.
- Vulnerability management – assessments, prioritisation and remediation tracking.
- Security reporting – examples of weekly/monthly SOC reports, incident analysis and alert trends.
- SOC dashboards – examples of monitoring metrics and security KPIs.
- Security playbooks – examples of incident-response or SOC procedures developed or improved.
If you have strong hands-on SOC and Cyber Security experience and can demonstrate expertise across security monitoring, SIEM, threat detection, incident response and security investigations , we would like to hear from you
Please note: Due to the volume of applications received, only shortlisted candidates will be contacted. If you have not heard from us within two weeks of submitting your application , please consider your application unsuccessful on this occasion .