Senior Security Analyst - Hybrid
Recru-IT · Somerset West, Western Cape
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Reference: PE011720-Tabz-1
Our client based in Somerset West is looking for a Senior Security Analyst for a hybrid role.
Required
- Seven or more years of ICT experience.
- Five or more years of cybersecurity experience.
- Experience managing enterprise security technologies.
- Experience in incident response and threat investigation.
- Experience with vulnerability management programmes.
- Experience securing cloud platforms.
- Experience working within regulated environments.
Duties & Responsibilities
Description: Security operations and monitoring:
- Monitor security events across infrastructure, cloud platforms, endpoints, networks and applications.
- Investigate security alerts and incidents.
- Perform threat hunting and root cause analysis.
- Maintain and enhance SIEM and security monitoring capabilities.
- Coordinate incident response activities and post-incident reviews.
- Develop and maintain security playbooks and response procedures.
Vulnerability management
- Manage vulnerability scanning programmes.
- Analyse vulnerability assessment results.
- Coordinate remediation efforts with ICT teams.
- Validate remediation activities.
- Produce regular vulnerability and risk reports.
- Establish risk-based prioritisation of vulnerabilities
Security engineering
- Design and implement security controls across Microsoft 365, Azure, Active Directory / Entra ID, Linux and Windows servers, network infrastructure and DevOps platforms.
- Implement and maintain multi-factor authentication, Privileged Access Management, Endpoint Detection and Response, Data Loss Prevention and security automation solutions.
- Evaluate and implement new security technologies.
Cloud security
- Secure Azure cloud environments.
- Review cloud configurations and architecture.
- Conduct cloud security assessments.
- Implement Microsoft security best practices.
- Support Zero Trust initiatives.
Governance, risk and compliance
- Maintain cybersecurity risk registers.
- Conduct risk assessments.
- Support internal and external audits.
- Assist with policy and standard development.
- Support compliance requirements including POPIA, CIS Controls, and regulatory and client requirements.
Security architecture
- Review and approve security designs.
- Assess new solutions and projects for security risks.
- Define security standards and baselines with Team Lead and Line Manager.
- Develop secure architecture patterns with Team Lead.
Security awareness
- Promote security awareness initiatives.
- Conduct security training.
- Guide technical and business teams.
- Support organisational cyber resilience programmes.
DevSecOps
- Support secure software development practices.
- Review security testing and code scanning.
- Assist development teams with remediation activities.
Qualifications Minimum
- Matric with 10 years' work experience/or a bachelor’s degree or National Diploma in Information Security, Computer Science, Information Technology, Engineering or analytical related field.
Preferred certifications
- CISSP
- CISM
- CompTIA Security+
- Microsoft Security certifications
- Microsoft Azure Security Engineer Associate (AZ-500)
Experience: Required:
- Seven or more years of ICT experience.
- Five or more years of cybersecurity experience.
- Experience managing enterprise security technologies.
- Experience in incident response and threat investigation.
- Experience with vulnerability management programmes.
- Experience securing cloud platforms.
- Experience working within regulated environments.
Preferred
- Experience with the Microsoft security stack.
- Experience with DevSecOps practices.
- Experience with SIEM and SOAR platforms.
- Experience with Zero Trust architecture.
Technical skills: Security technologies:
- Microsoft Defender suite, Zabbix, Vulnerability management tools, Privileged Access Management solutions, Email security platforms, Data Loss Prevention solutions, Identity Access Management, Endpoint Management, Certificate Authority.
Infrastructure
- Azure, Microsoft 365, Active Directory, Entra ID, Windows Server, Linux, VMware.
Networking
- TCP/IP, Firewalls, IDS/IPS, VPN technologies, Network segmentation, ZTNA technologies (Netskope).
Automation and scripting
- PowerShell, Python, Bash, REST APIs, Security automation.
Behavioural competencies
- Analytical thinking
- Problem solving
- Risk-based decision-making
- Attention to detail
- Accountability
- Communication skills
- Stakeholder management
- Teamwork and collaboration
- Customer focus
- Continuous learning
- Integrity and professionalism
Key performance indicators
- Reduction in critical vulnerabilities.
- Incident response service-level adherence.
- Security control effectiveness.
- Completion of risk assessments.
- Audit finding remediation rate.
- Security awareness participation rates.
- Compliance maturity improvements.
- Security monitoring coverage.
Package & Remuneration
Annually