Security Operations Analyst
Swan iT Recruitment Ltd · Stellenbosch, Western Cape · Negotiable
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
We are looking for an experienced Security Operations Analyst to join our Technology team in a hands-on security role.
You will be responsible for monitoring, investigating and continuously improving the organisation's security posture across identity, endpoint, cloud and network environments .
The role will focus heavily on security monitoring, vulnerability management, incident response, threat detection and security control optimisation , with a strong focus on the Microsoft Defender security stack and future SIEM capabilities.
You will work closely with internal engineering teams and external service providers to identify security risks, coordinate remediation and strengthen the organisation's ability to detect and respond to security incidents.
Duties & Responsibilities
Key Responsibilities
Security Monitoring & Detection
- Monitor security alerts across identity, endpoint, cloud, email and network environments.
- Triage alerts and investigate suspicious activity and indicators of compromise.
- Maintain and tune security detections to improve alert quality and reduce unnecessary noise.
- Develop monitoring and detection capabilities using Microsoft Defender and SIEM platforms.
Incident Response
- Investigate security incidents and coordinate containment, remediation and recovery.
- Work closely with Microsoft 365 and Modern Desktop Engineers during technical response activities.
- Maintain incident records, timelines, evidence and investigation notes.
- Conduct post-incident reviews and track corrective actions through to completion.
Vulnerability & Exposure Management
- Coordinate vulnerability scanning and assess findings according to risk and business impact.
- Develop prioritised remediation plans across endpoint, identity, cloud and network environments.
- Track remediation activities with internal teams and service providers.
- Monitor Secure Score, exposure indicators and security control coverage.
Threat Hunting & Security Intelligence
- Conduct threat-hunting activities using available security telemetry.
- Develop queries and detection rules to identify suspicious behaviour.
- Monitor relevant threat intelligence, indicators of compromise and emerging attack techniques.
- Map detections and security gaps against recognised frameworks such as MITRE ATT&CK.
Security Governance
- Coordinate phishing simulations and security awareness initiatives.
- Maintain security procedures, investigation playbooks and response runbooks.
- Support audit evidence collection, log-retention requirements and control assessments.
- Coordinate security testing and track remediation of findings.
Desired Experience & Qualification
Minimum Requirements
- Relevant diploma or degree in Cybersecurity, Information Technology, Computer Science or a related field, or equivalent practical experience.
- Approximately 5–7 years' experience in security operations, infrastructure security or a related technical security role.
- Hands-on experience with security monitoring, alert triage, investigation and incident response.
- Experience with Microsoft Defender or comparable endpoint, identity, email and cloud-security technologies.
- Practical experience with vulnerability management, remediation tracking and security posture reporting.
- Working knowledge of SIEM concepts, security telemetry and query languages such as KQL .
- Knowledge of security frameworks such as MITRE ATT&CK, CIS Controls and/or ISO 27001 .
- Strong analytical, investigation and documentation skills.
- Ability to communicate security findings effectively to technical and business stakeholders.
Advantageous Skills
- Microsoft Sentinel experience.
- Strong KQL experience.
- Threat hunting and detection engineering.
- Microsoft Defender for Endpoint, Identity, Office 365 and Cloud Apps.
- Microsoft Purview DLP and data-labelling experience.
- Firewall monitoring and policy review.
- Experience with Secure Score and security exposure management.
- Knowledge of identity, endpoint, email, cloud and network security.
Certifications
Microsoft Security Operations Analyst Associate certification is required or strongly preferred.
The following certifications would also be advantageous
- CompTIA Security+
- CompTIA CySA+
- Equivalent security certifications
What We're Looking For
We're looking for someone who is naturally curious, analytical and comfortable thinking like an attacker.
You should be able to distinguish genuine threats from alert noise, remain calm and structured during incidents, work methodically with evidence and collaborate effectively with technical teams to resolve security issues.
If you're passionate about cybersecurity, threat detection and continuously improving security operations, this could be an excellent opportunity to make a meaningful impact.