L3 Security Incident Handling Analyst

2 weeks ago


Midrand, Gauteng, South Africa Nexio Full time

ROLE PURPOSE

As part of the Customer-facing Nexio SOC team, the L3 Security Incident Handling Analyst will be responsible for monitoring enterprise networks and systems, detecting events and reporting on any and all threats that are directed against those systems regardless of their classification level or type.

The L3 Security Incident Handling Analyst is expected to collaborate with leadership to develop metrics based on situational awareness and threat monitoring at an enterprise level that will be reported based on the approved plan and supporting checklists.

The L3 Security Incident Handling Analyst must be able to rapidly address security incidents alerted primarily by an industry recognised Security Information and Events Management [SIEM].


He/She should ideally have advanced security incident handling analysis experience in an established SOC environment where ArcSight, or Azure Sentinel, or QRadar was the SIEM platform.


ROLE REQUIREMENTS

  • Is familiar with the tactical and longterm vision across the Cyber Security function.
  • Team lead on Security Incident Analysis and Handling within the SOC function.
  • Adheres to the standard operating procedure and playbooks in the SOC.
  • Direct impact on the SOC performance.
  • Impacts on team's runbooks and operational processes in the SOC Service.
  • Provides security incident handling and technical guidance to SOC Teams.
  • Gives regular, comprehensive and constructive feedback, and coaching and mentoring to team.
  • Delegates work to team members taking into account their capacity, level of skill and exposure to different types of work and complexity; provides clear instructions and direction, with reasonable deadlines.
  • Provides support for complex computer network exploitation and defence techniques to include deterring, identifying and investigating computer and network intrusions
  • Provides incident response and remediation support; performing comprehensive computer surveillance/monitoring, identifying vulnerabilities; developing secure network designs and protection strategies, and audits of information security infrastructure.
  • Provides technical support for continuous monitoring, computer exploitation and reconnaissance; target mapping and profiling; and, network decoy and deception operations in support of computer intrusion defence operations.
  • Provides technical support for forensics services to include evidence seizure, computer forensic analysis and data recovery, in support of computer crime investigation.
  • Researches and maintains proficiency in open and closed source computer exploitation tools, attack techniques, procedures and trends. Performs research into emerging threat sources and develops threat profiles.
  • Provides technical support for a comprehensive risk management program identifying mission critical processes and systems; current and projected threats; and system vulnerabilities.
  • Lead Red Team / Blue Team exercises and identify gaps in current monitoring tools and processes.
  • Develops playbooks for various incident scenarios and have a knowledge of automation processes and products.
  • Mentors Junior Analysts to become more effective in their roles.
  • Application of security settings and other commercial best practices such as SIEM Analysis operations.
  • Incident analysis from ingested source systems combined with threat intelligence feeds into the SIEM from open source and commercial feeds.

Additional Information:

  • Individuals at this level have fully developed knowledge of best practices in security incident handling in an established SOC.
  • Able to build strong interpersonal relationships with the SOC team and customer stakeholders.
  • Excellent verbal and written communication skills.
  • Able to align multiple strategies and ideas.
  • Confident in producing and presenting work.
  • Indepth understanding of best security incident analysis and incident handling practices in an established SOC.

QUALIFICATIONS & EXPERIENCE

  • Grade 1
  • Bachelor's Degree in Computer Science or a related technical discipline, or the equivalent combination of education, technical certifications
  • One or more these industry

Cybersecurity Certifications:
CISSP-ISSEP, CISSP-ISSAP, GIAC Certified Incident Handler (GCIH), Certified Computer Security Incident Handler (CSIH), CEH, OSCP, CompTiA

  • Minimum of five (5) years of work experience, and two (2) years of relevant experience in and established SOC and information security/cybersecurity
  • Experience with defining SOC playbooks.
  • Experience with a ticketing system such as BMC Remedy.
  • Basic Linux and Windows Server experience.
  • Experience working with virtual environments.
  • Strong analytical and organizational skills.
  • Concise writing skills, excellent MS Word skills as well as other MS Office Applications.
  • Experience with securing various environments preferred.
  • Experience in working across security frameworks.
  • Experience in working across security technologies.
  • Poss


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE PURPOSEAs part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and...

  • L1 Incident Analyst

    1 week ago


    Midrand, Gauteng, South Africa Liquid Tech (Pty) Ltd. Full time

    Role PurposeTo deliver day-to-day managed security services (MSS), related to SOC deliverables. Critical in this regard is to execute according to Standard Operating Procedure (SOP) expectations and meeting all related service level agreements (SLAs). It is further expected that these services will be enhanced and matured so that customer value can be...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE PURPOSEAs part of the Customer-facing Nexio SOC team, the Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and provide...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE PURPOSEAs part of the Customer-facing Nexio SOC team, the Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and provide...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE PURPOSEAs part of the Customer-facing Nexio SOC team, the Cybersecurity Threat Analyst will be responsible for monitoring enterprise networks and systems, deterring, identifying, investigating, and mitigating, any and all threats that are directed against those systems regardless of their classification level or type. The Cybersecurity Threat Analyst is...

  • Incident Manager

    1 week ago


    Midrand, Gauteng, South Africa Nexio Full time

    Nexio is a specialist ICT solution provider that helps clients build, support, and manage their IT infrastructures. We have operations in all 9 provinces across the country, over 200 clients and over 600 employees and as a Level 1 BBBEE we put to practice our commitment to South Africa's transformation agenda, we are at the forefront of digital...


  • Midrand, Gauteng, South Africa Fidelity Services Group Full time

    Job Title: Cybersecurity AnalystLocation: Ulwazi Campus Midrand/HelderkruinReports to: Information Security Manager**Job Summary:We are seeking a skilled and dedicated Cybersecurity Analyst to join our Cybersecurity team in the physical security industry. As a Cybersecurity Analyst, you will play a crucial role in ensuring the security of our diverse client...

  • SOC Analyst

    2 weeks ago


    Midrand, Gauteng, South Africa Datacentrix Full time

    Gauteng, Midrand (Market related, Negotiable)Datacentrix is looking for SOC Analysts Level 1 & Level 3 to provide initial investigation of all security incidents, and management of incident from inception to resolution and liaise with vendor and Engineers to resolve incidents where required. Must have experience in installing, configuring, and maintaining...


  • Midrand, Gauteng, South Africa WSP Africa Full time

    Job DescriptionWSP's Security Engineering and Operations Team is responsible for managing the global organization's security technologies and systems. The role of Director Security Operations reports directly to the Global Vice President Security Engineering and Operations and is responsible for leading our Security Operations Centre and working with the...


  • Midrand, Gauteng, South Africa WSP Africa Full time

    Company DescriptionWe are WSP - Join us and make your career future readyThink bigger scale. Think higher profile. Think ground-breaking. Join WSP, and you'll be at the heart of a team of international experts all dedicated to growing and sharing their expertise, and working on projects that transform society for all of us.WSP is one of the most diverse...


  • Midrand, Gauteng, South Africa Network Contracting Full time

    Outputs:Consultancy services Document solutions Liaise with Development teams on proposed solutions.Technical Analyst Understanding the business requirements, and through a structured process documenting, validating, and translating it into functional specifications that are used by developers to craft a technical solution. Create functional solutions with...


  • Midrand, Gauteng, South Africa MSD Full time

    Reporting to the Associate Director, Regional Security Middle East Africa (MEA), the Regional Security Senior Specialist will be responsible for supporting Global Security Group (GSG) Operations in Sub-Sahara Africa (French West Africa, English & Portuguese Africa, South Africa). He/She will be responsible for providing primary security support for all...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Cyber Defence is one of MPA's critical Cyber Security teams. The Cyber Defence team's mission is to deliver a highly effective end to end 24x7 Cyber Defence service. They are responsible for proactively identifying threats and vulnerabilities; detecting and mitigating cyber events; and managing cyber security incident responses to minimise...


  • Midrand, Gauteng, South Africa RJPersonnel Full time

    2years Configure and support Symantec Endpoint Protection antivirus. Knowledge of firewall rules and should be involved in the review of the firewall policies. Identify threats and working on steps to defend against them. General or basic knowledge of vulnerability assessments and penetration tests. Security awareness/procedures. Participate in audit...


  • Midrand, Gauteng, South Africa Xcellency Human Capital (Pty) Ltd Full time

    Responsibilities: Microsoft Security: Implement and manage Microsoft security solutions, including but not limited to Microsoft Defender ATP, Azure Security Centre, and Windows Defender Firewall. Conduct regular security assessments and audits to identify and address vulnerabilities. Sophos Firewall Management: Configure, deploy, and manage Sophos firewalls...


  • Midrand, Gauteng, South Africa TRSS 24 Full time

    Employer:Tactical Reaction ServicesCONTROL ROOM OPERATOR (SECURITY)We are a leading company in the security industry that strive for service excellence and quality products.Professionalism, Proficiency and a Proactive attitude support our mission in being the BEST security company in SA.We require the services of a _Control Room Supervisor/Administrator _to...

  • SOC Analyst

    2 weeks ago


    Midrand, Gauteng, South Africa Data Centrix Full time

    Minimum Qualification: Matric plus Diploma/Degree in Information Security MS Security Certification years of experience working in IT or SOC environmentRole Description: Providing supporting security services and actionable reporting Analyze threats and logs, alerts and reports Proactively look for suspicious anomalous activity based on data alerts or data...

  • Security Guard

    1 week ago


    Midrand, Gauteng, South Africa SaiFleet Full time

    Security GuardWe are a car rental company based in Johannesburg looking for a Security Guard to work in our offices based in Halfway House, Midrand. We offer long-term rental solutions to our clients (Corporate & Individuals).Responsibilities: Protect the business' property, staff and the environment by keeping the location secure. Keep trespassers away and...

  • Security Officer

    2 weeks ago


    Midrand, Gauteng, South Africa Maanda Nes Investments Full time

    Job Title: Security Guard _05_ _Februa_ _ry_ _2_ _023_JOB SPECIFICATIONResponsibilities: Conduct regular foot patrols of the office premises both indoors and outdoors Monitor security systems, including CCTV cameras, alarm systems, and access control points Respond to alarms, incidents, and emergencies promptly and professionally Document all incidents and...

  • Security Specialist

    1 week ago


    Midrand, Gauteng, South Africa Jurumani Solutions Full time

    Jurumani offers an environment where creativity and the practice of building things is believed to be fundamentally useful to both the Client and Jurumani Solutions. Providing opportunity to focus on making products and business operating capabilities work, which means we often are more concerned with how systems align, orchestrate and integrate to achieve...