L2 SOC Analyst / Cybersecurity Analyst (Microsoft
Executive Placements · Bo-Kaap, Western Cape
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →ENVIRONMENT
An innovative, End-to-end Cybersecurity firm based in Cape Town is seeking a strong technical L2 SOC Analyst / Cybersecurity Analyst to join its Cybersecurity team and support multiple client environments within its MSP/MSSP operation. This role will go beyond basic SOC alert monitoring. The successful candidate will independently investigate security alerts and incidents, analyse security telemetry, perform threat hunting, contribute to SIEM and detection improvements, and support a range of cybersecurity projects across the client base. You must be comfortable working across multiple technologies, clients and competing priorities and should be capable of working independently with limited supervision. Applicants will require Certifications such as Microsoft SC-200/Microsoft AZ-500/Microsoft SC-100/CompTIA Security+ with 2–4 years' practical cybersecurity / SOC experience & proficiency with Microsoft Sentinel, KQL, SIEM, EDR/XDR & a solid understanding of MITRE ATT&CK.
DUTIES
· Investigate and analyse security alerts and incidents across multiple client environments.
· Perform L2 SOC investigations and determine the nature, severity and potential impact of security events.
· Work with Microsoft Sentinel and KQL for incident investigation, log analysis, threat hunting and detection development.
· Review, tune and improve SIEM detection rules and identify detection gaps.
· Contribute to MITRE ATT&CK mapping and detection coverage assessments.
· Conduct proactive threat hunting and contribute to monthly threat-hunting reporting.
· Analyse EDR/XDR alerts and endpoint security events.
· Investigate Microsoft 365, Entra ID, endpoint, email and network security events.
· Assist with vulnerability management, security hardening and remediation activities.
· Support SIEM onboarding, optimisation and cybersecurity projects.
· Produce technical and client-facing security reports and recommendations.
· Work across multiple clients and technologies while prioritising incidents and tasks according to risk and business impact.
· Maintain accurate technical documentation and investigation records.
Candidate Profile
The ideal candidate should be able to operate beyond
Alert ? Basic Investigation ? Escalation
and instead demonstrate
Alert ? Investigation ? Correlation ? Analysis ? Risk Assessment ? Response ? Documentation ? Improvement
They should be able to independently determine
Ø What happened?
Ø Why did it happen?
Ø What is affected?
Ø What is the security risk?
Ø What should be done?
Ø Does the detection need to be improved?
REQUIREMENTS
Qualifications -
· Relevant certifications are a MUST but hands-on
.special-hidden { display: none; }