IT Security Analyst
The Skills Mine · Johannesburg, Gauteng · Market Related
Posted 8 September 2026
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
Our client is a Leading Full-Service Legal Firm.
Description
Requirements
- Diploma or NQF Level 6 qualification in Computer Science, Information Systems, Information Technology, or a related field.
- Up to 3 years of relevant experience in IT security or information security.
- Essential experience with ISO 27001 certification, consulting, and advisory activities.
- Preferred ISO 27001 Information Security Management Systems (ISMS) certification.
- Preferred Microsoft Azure Security Technologies AZ-500 certification.
- Experience in IT security operational execution, including security monitoring, incident response, and vulnerability management.
- Strong analytical, problem-solving, judgment, communication, integrity, and advisory capabilities.
Responsibilities
- Conduct IT security log analysis and monitor security events for potential threats and incidents.
- Collaborate with internal and external stakeholders to investigate and resolve identified malware and security incidents.
- Maintain security incident records, perform initial assessments, and support incident response investigations and remediation.
- Lead annual vulnerability scanning and penetration testing activities.
- Analyse information security risks and recommend appropriate solutions to protect information against unauthorised access, modification, destruction, or disclosure.
- Log and manage information security risks, track remediation measures, provide stakeholder updates, and escalate critical risks.
- Conduct periodic risk and vulnerability assessments, document findings, and track remediation activities.
- Coordinate and support internal and external ISO 27001 audits, including documentation preparation, scheduling, and follow-up on findings.
- Develop, maintain, and update ISO 27001 compliance documentation, including the Statement of Applicability, risk treatment plans, asset inventories, and ISMS documentation.
- Monitor compliance with ISO 27001 and other relevant information security standards, reporting nonconformities and supporting corrective actions.
- Administer information security governance documentation, policies, access controls, security audits, and service-provider compliance assessments.
- Provide information security advice to business units and assist with the development and delivery of security awareness training.
- Evaluate and test new technologies, security controls, policies, procedures, licensing, and project capabilities to ensure security requirements are met.
- Analyse internal and external cyber threats, recommend infrastructure improvements, maintain awareness of emerging threats and technologies, and ensure security throughout the DevSecOps lifecycle.