Senior Cyber Security Analyst

Life Healthcare Group (Pty) Ltd · Johannesburg

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Function

Information technology

Facility

Life Head Office, Dunkeld

Position

Senior Cyber Security Analyst

Introduction

Job Title : Senior Cyber Security Analyst

Location: Group Information Security Office (Head Office)

Reporting Line: Head: Cyber Security

Job Summary

A vacancy exists for a Senior Cyber Security Analyst based at Life Healthcare Head Office reporting to the Head: Cyber Security . The successful incumbent will be responsible for identifying, assessing, and mitigating cybersecurity risks across the organisation's network, systems, and applications. This role focuses on vulnerability management, penetration testing, and network security, ensuring proactive threat detection and robust defense mechanisms and being proactive within incident response.

Critical Outputs

  • Vulnerability Management
  • Lead and support the enterprise vulnerability management programme across infrastructure, endpoints, applications, databases, cloud environments and internet-facing assets.
  • Conduct regular vulnerability scanning using tools such as Qualys, Tenable, Rapid7 or similar platforms.
  • Analyse vulnerability scan results and prioritise remediation based on severity, exploitability, asset criticality, exposure, business impact and active threat activity.
  • Validate vulnerabilities to reduce false positives and confirm actual risk to the organisation.
  • Collaborate with infrastructure, endpoint, network, application and cloud teams to ensure timely remediation of identified vulnerabilities.
  • Track remediation progress against agreed service levels and escalate overdue or high-risk vulnerabilities where required.
  • Validate patching and remediation effectiveness through rescans and evidence review.
  • Maintain vulnerability dashboards, remediation trackers, risk exception registers and executive-level reporting.
  • Identify recurring vulnerabilities, root causes and systemic control weaknesses requiring long-term remediation.
  • Web Application and API Security Scanning
  • Perform or coordinate web application and API vulnerability scanning using Qualys WAS or similar approved application security scanning platforms.
  • Analyse web application scanning results to identify valid findings, false positives, duplicate findings and recurring weaknesses.
  • Assess web application and API findings against common security risks such as the OWASP Top 10.
  • Work with application owners, developers and third-party providers to clarify findings and support remediation.
  • Track application security findings from identification through to closure.
  • Validate remediation evidence for web application and API security findings.
  • Identify recurring application security weaknesses and recommend improvements to secure development practices, configuration standards and control design.
  • Penetration Testing Governance and Third-Party Coordination
  • Act as the internal cyber security custodian for penetration testing and security assessment activities.
  • Coordinate third-party penetration testing engagements, including scope definition, rules of engagement, asset confirmation, timelines, evidence requirements and reporting expectations.
  • Ensure penetration testing activities are properly authorised, risk-managed and aligned with business, operational and change management requirements.
  • Review third-party penetration testing reports in detail and interpret the technical findings, exploitability, business impact and remediation requirements.
  • Engage with external testers to clarify, challenge or negotiate findings where required, including severity ratings, false positives, duplicate findings, compensating controls and practical remediation options.
  • Translate penetration testing findings into clear remediation actions for infrastructure, network, application, cloud and system owners.
  • Track penetration testing findings through to closure and provide regular progress updates to management.
  • Validate remediation actions and supporting evidence before closing findings.
  • Prepare management reporting on penetration testing outcomes, recurring themes, overdue findings, remediation progress and residual risk.
  • Network and Infrastructure Security Assessment
  • Assess security weaknesses across network infrastructure, servers, cloud services, firewalls, remote access, wireless, segmentation and internet-facing services.
  • Review exposed services, insecure configurations, weak protocols, missing patches and unnecessary attack surface.
  • Support security reviews of network architecture, firewall rules, segmentation and access controls from a vulnerability and exposure perspective.
  • Work with network and infrastructure teams to reduce unnecessary exposure and improve secure configuration.
  • Support initiatives relating to secure baselines, hardening standards, patch compliance and attack surface reduction
  • Identify technical control gaps that increase vulnerability exposure or remediation complexity.
  • Provide practical recommendations to reduce risk across infrastructure and network environments.
  • Risk Management, Exceptions and Governance
  • Align vulnerability management and penetration testing processes with recognised frameworks and standards such as ISO 27001, NIST, CIS Controls and internal cyber security policies.
  • Support cyber risk assessments by providing vulnerability data, remediation status, exposure information and technical context.
  • Maintain records of accepted risks, remediation exceptions, compensating controls and overdue findings.
  • Ensure exceptions are documented, time-bound, justified and reviewed periodically.
  • Provide vulnerability and remediation evidence for audits, compliance reviews and governance reporting.
  • Assist with the development and maintenance of vulnerability management standards, procedures, reporting templates and operational processes.
  • Identify control weaknesses and recommend practical improvements to reduce cyber risk.
  • Incident and Threat Exposure Support
  • Provide vulnerability and exposure context during security incidents or investigations where required.
  • Assist in determining whether known vulnerabilities, exposed services, weak configurations or missed remediation activities may have contributed to an incident.
  • Support root cause analysis by identifying relevant vulnerability history, asset exposure and remediation gaps.
  • Recommend corrective actions to reduce the likelihood of repeat incidents.
  • Support lessons learned activities where vulnerability management, patching, configuration or exposure issues are identified.
  • Stakeholder Engagement & Reporting
  • Communicate vulnerability and penetration testing findings clearly to technical and non-technical stakeholders.
  • Prepare regular operational, management and executive reports covering vulnerability exposure, remediation progress, penetration testing outcomes, overdue items and key risk themes.
  • Work closely with infrastructure, network, application, cloud, endpoint, risk and governance teams to drive remediation.
  • Provide clear remediation guidance to asset owners and technical teams.
  • Build strong working relationships across IT and business teams to ensure cyber security risks are understood and addressed.
  • Provide technical leadership and guidance to junior analysts where required.

Requirements

  • Diploma or Degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • Minimum 4 to 6 years of experience in cyber security, with practical experience in vulnerability management, infrastructure security, application security, network security or security assurance.
  • Certifications such as CompTIA Security+, CompTIA CySA+, CEH , Microsoft security certifications and IC2 certifications.
  • Hands-on experience with vulnerability management platforms such as Qualys VMDR, Tenable, Rapid7 or similar.
  • Experience with web application vulnerability scanning tools such as Bur
Auto-apply to this jobView original posting ↗