Principal Offensive Security Specialist

1 week ago


Midrand, Gauteng, South Africa Nexio Full time

ROLE REQUIREMENT

  • To increase security threat detection capability and defence effectiveness in the Security Assessment Team, and SOC Team in their engagements with customers.
  • Provides support for Nexio Offensive Security capabilities for the Security Assessment Team, and SOC Team for customers' engagements.
  • Direct impact on business resilience and functionality against cyber security threats facing customers.
  • As an advanced threat hunter, the Principal Offensive Security Specialist continuously detects, analyzes and combats advanced threats. The job role includes detecting vulnerabilities and mitigating the associated cybersecurity risk before it affects customers.
Provides threat hunting technical and thought leadership to customers executive stakeholders, SOC teams, and blue/red teams.

Provides coaching and mentoring to relevant cyber security team members.

Adjusts management style to get the best from the individuals within the team.


Delegates work to team members taking into account their capacity, level of skill and exposure to different types of work and complexity; provides clear instructions and direction, with reasonable deadlines.


  • Responsible for day to day threat hunting and cyber intelligence monitoring and threat analysis in the Nexio SOCs.
Manage threat hunting and security monitoring staff and activities.

Proactively finds vulnerabilities in the customers' estate.

He/She has an overview of the endpoints on the system such as all the IoT devices, phones, IP addresses and desktops, and they help IT teams use the right tools to detect and mitigate threats.

Understands what normal behaviour and patterns look like on the customers' network.


Formulates and develops logical theories on how threat actos could access a network or exploit a system to gain access to specific critical information.

Oversees breach and attack simulations.


Responsible for proactively discovering new attacks, or attacks currently underway, and then working with other expert cyber security resolver teams to contain and remediate the impact as quickly as possible.

Uses advanced security monitoring techniques and advanced cyber systems/tools.

Should a breach occur, he/she helps minimize damage, recover compromised data and preserve evidence for legal action.

Lead Purple Teaming, hence perform threat hunting with customers to proactively reduce attack surface.


Success will rely on the rapid development and deployment of new 'data hunting' use cases and the use of big data analytics.


Responsible for proactively discovering new attacks, or attacks currently underway through the use of advanced security monitoring techniques and advanced cyber systems/tools.


Complex Active Monitoring & Triage - observation, triage, correlation analysis/investigation and closure of real time of information complex security events including false positive identification.

Data Hunting Technology Management - advanced configuration and development of high end data hunting technologies.


Participates in the response, triage and escalation of security events affecting the customers' information assets and activities with the Incident Response team.


Provides input into fine tuning of operational runbooks to improve the efficiency of cyber security team's detection and response capabilities.

Co-ordinates with stakeholders, build and maintain positive working relationships between various service towers of the business and customers.

Provide threat hunting technical leadership and support during high severity security incidents and investigations.

Optimizes the processes to respond to and investigate detected attacks.

Additional Information:
Individuals at this level have fully developed knowledge of the threat landscape and TTPs.

Is recognized as an expert in threat intelligence and threat hunting with special focus and emphasis on SOC, or Advanced Cyber Defence Centre operations.

Interprets internal or external business issues and recommends best practices. Provides technical guidance to SOC Teams and Pen Testing, and Security Assessment Teams.

Able to build strong interpersonal relationships with key customer stakeholders.

Excellent verbal and written communication skills.

Able to align multiple strategies and ideas.

Confident in producing and presenting work.

In-depth understanding of cyber incident response and digital forensics.

Working technical knowledge of SOC tools and SIEM technologies e.g., Azure Sentinel, QRadar, ArcSight.


Advanced technical knowledge in working with threat intelligence feeds for monitoring and analysing indicators or compromise e.g., Bromium, OTX, Talos, Digital Shadows, RiskIQ, etc.

Advanced penetration testing, and red teaming experience across sectors and certification.

QUALIFICATIONS &B EXPERIENCE
Grade 12

BSc/ B Tech /Comps / BEng or equivalent IT Security Diploma

Additionally, one more certifications in the following information security and domains.

CISS

  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.Your responsibilities will include:Provide technology security assurance, guidance and support...


  • Midrand, Gauteng, South Africa Nambiti Technologies Full time

    Gauteng, Midrand- market related (Market related, Negotiable)Our client based in Gauteng is looking for a Cybersecurity Specialist with 5+ years relevant experience in Cybersecurity for a period of 5 yearsRequired skills and knowledge Wellversed with various security tools such as Burp Suite, Nmap. Nessus Qualys, Metaspoilt, etc.; Fully understanding if...


  • Midrand, Gauteng, South Africa Fempower Personnel Full time

    Our client has an exciting opportunity for a Principal Project Preparation Specialist to lead Project Preparation Teams to prepare projects in order to develop the organization's investment pipeline in priority sectors in South Africa, SADC Region and selected African Countries in line with the approved Project Preparation Strategy. The incumbent of this...


  • Midrand, Gauteng, South Africa Adcorp Holdings Full time

    SynopsisOur Client in the Telecommunications industry is hiring for a Cyber Security Specialist as an Independent Contractor for 12 months. This role will allow you to gain experience in working with one of the largest telecommunications companies in South Africa.HybridMidrand basedon the hunt for an experienced and highly skilled Cyber Security Senior...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Defining Cyber Governance, Risk & Compliance to:To lead the ongoing evaluation of security policies, and relevant standards and support the continuous improvement of the security governance program.To ensure that comprehensive Information Security Risk management programs are established.Ensure the alignment of Information Security Risk...

  • Security Specialist

    1 week ago


    Midrand, Gauteng, South Africa Jurumani Solutions Full time

    Jurumani offers an environment where creativity and the practice of building things is believed to be fundamentally useful to both the Client and Jurumani Solutions. Providing opportunity to focus on making products and business operating capabilities work, which means we often are more concerned with how systems align, orchestrate and integrate to achieve...


  • Midrand, Gauteng, South Africa Fempower Personnel Full time

    Looking for an exciting opportunity as a Principal Deal Originator in the Social, Health and Education sectors? Our client is seeking a talented individual to join their team in Midrand As the Principal Deal Originator, you will play a critical role in driving the strategic objectives of the business and be responsible for deal origination, building and...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Responsible for leading and executing compliance assurance audits, reporting and ad hoc management requests across Vodacom Group in support of strengthening the control environment and will include data analytics execution and support across the markets in line with the Vodacom Compliance methodology and professional standards.Your...


  • Midrand, Gauteng, South Africa MSD Full time

    Reporting to the Associate Director, Regional Security Middle East Africa (MEA), the Regional Security Senior Specialist will be responsible for supporting Global Security Group (GSG) Operations in Sub-Sahara Africa (French West Africa, English & Portuguese Africa, South Africa). He/She will be responsible for providing primary security support for all...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Responsible for the management of the Technology Efficiency program and special projects across all Vodacom Opcos. The focus will be on optimizing capex and opex spend through technology innovation, reviewing operating models, benchmarking Opcos and sharing best practice to improve efficiency across our markets.Your responsibilities will...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Responsible for the management of the Technology Efficiency program and special projects across all Vodacom Opcos. The focus will be on optimizing capex and opex spend through technology innovation, reviewing operating models, benchmarking Opcos and sharing best practice to improve efficiency across our markets.Your responsibilities will...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Cyber Defence is one of MPA's critical Cyber Security teams. The Cyber Defence team's mission is to deliver a highly effective end to end 24x7 Cyber Defence service. They are responsible for proactively identifying threats and vulnerabilities; detecting and mitigating cyber events; and managing cyber security incident responses to minimise...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.In performing this role, you will:Identify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. In performing this role you willIdentify potential cyber security risks for new products, services and operations and...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role Purpose:The primary purpose of the role is to support Cyber GRC functions which are all interdependent and would require good teamwork.To ensure the best delivery, exposure and create backfill capability with succession planning, the role and function for a Cyber GRC specialist would require expertise in the following areas broadly covered...


  • Midrand, Gauteng, South Africa Fempower Personnel Full time

    Our client has an exciting EE opportunity for a Project Preparation Specialist.The role of the incumbent is to prepare projects for lending decision.This entails, amongst other things:scope or define a project that is in an early preparation phase, facilitate syndication for participating in the project, identifying and managing feasibility studies required...


  • Midrand, Gauteng, South Africa WSP Africa Full time

    Company DescriptionWSP is one of the most diverse consulting firms in Africa. To further our strategic business execution plan, we are seeking leaders that share our guiding principles - we value our people and our reputation; we are locally dedicated with international scale; we are future focused and challenge the status quo; we foster collaboration in...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role Purpose:The United Nation's (UN) Sustainable Development Goals (SDGs) and the African Union (AU) both acknowledge that Africa's drivers of economic growth and long-term sustainability for emerging markets are dependent on the potential to effectively develop the Small-and-medium size enterprises (SMEs) business model. Furthermore, the AU's African...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture professionals, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. In performing this role you willIdentify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The purpose of this role is to drive the execution of Vodacom's agenda on human rights across Vodacom and its subsidiaries ('Vodacom') and provide expert advice at senior levels (Group and subsidiaries) on human rights within the telecommunications sector.It involves leading engagement with a wide range of internal and external stakeholders so...