Senior Specialist: Cybersecurity Incident Management
2 days ago
- Jobs by Location
- Job by industries
ROLE REQUIREMENT
- Develop and implement strategies for incident response, ensuring alignment with industry best practices and regulatory requirements.
- Drive improvements in security operations processes and contribute to risk management and mitigation strategies.
- Collaborate with stakeholders to enhance the overall cybersecurity posture and SOC maturity.
- Enforce standard operating procedures (SOC) and continuously refine incident response playbooks.
- Establish and maintain key performance indicators (KPIs) for incident response effectiveness.
- Strengthen the organization's cybersecurity resilience, reducing the impact and frequency of cyber incidents.
- Improve customer trust and confidence by ensuring swift and effective incident response and mitigation
- Provide guidance, mentorship, and training to SOC analysts and junior cybersecurity professionals.
- Lead post-incident review meetings and develop lessons-learned reports to enhance response strategies.
Incident Management & Response:
- Validate and declare security incidents following best-practice incident handling methodologies.
- Determine severity levels (S0 to S4) based on SLA classifications and advise on appropriate escalation.
- Provide technical leadership in real-time incident response, ensuring effective containment, eradication, and recovery measures.
- Lead forensic analysis efforts to collect intrusion artifacts, assess attack vectors, and develop mitigation strategies.
Incident Coordination & Support:
- Coordinate complex security incidents across multiple teams, ensuring swift and thorough resolution.
- Provide expert technical support and mentorship to SOC Analysts during high-severity incidents.
- Act as the primary escalation point for major cybersecurity incidents requiring advanced technical expertise.
Incident Analysis & Remediation:
- Conduct advanced correlation of security events to identify patterns and trends that indicate emerging threats.
- Perform deep-dive log analysis and threat-hunting exercises to uncover hidden or sophisticated attacks.
- Provide recommendations for system hardening, threat mitigation, and proactive security measures.
Incident Reporting & Communication:
- Generate comprehensive incident reports and post-mortem analyses for executive leadership and stakeholders.
- Develop security advisories and risk assessment reports based on incident trends and threat intelligence.
- Facilitate after-action reviews and ensure continuous improvement of response strategies.
Collaboration & Threat Intelligence:
- Act as a key liaison between the SOC and intelligence analysts, security architects, and external cybersecurity partners.
- Monitor emerging cyber threats and collaborate with risk management teams to refine threat detection capabilities.
- Foster collaboration with internal teams and industry peers to enhance cybersecurity defenses and information sharing
Additional Information:
- Individuals at this level are competent in best practices in security incident handling in an established SOC.
- Able to build strong interpersonal relationships with the SOC team and customer stakeholders.
- Competent communication skills and communication of complex information to non-technical stakeholders.
- Competent in producing and presenting work.
- Good understanding of security incident analysis and incident handling practices, proficient knowledge of networking protocols, operating systems, and security architecture in an established SOC.
TECHNICAL / PROFESSIONAL COMPETENCIES
- Extensive experience in cybersecurity incident response, threat analysis, and forensic investigations.
- In-depth knowledge of security frameworks, including NIST CSF, CIS CSC, MITRE ATT&CK, and NIST SP 800-53.
- Expertise in network protocols, security architectures, SIEM platforms, and endpoint security solutions.
- Proficiency in scripting and automation for incident response (Python, PowerShell, Bash, etc.).
- Strong understanding of malware analysis techniques, reverse engineering, and exploit detection.
QUALIFICATIONS & EXPERIENCE
- Grade 12 or equivalent qualification.
- One or more of these industry Cybersecurity Certifications: such as CISSP, GCIH, GCIA, or relevant vendor-specific certifications
- Minimum 6+ years of experience in cybersecurity, with 4+ years of direct experience in an established SOC.Analytical, problem-solving, and critical-thinking skills.
- Strong knowledge of cybersecurity principles, incident response methodologies, and defense-in-depth practices.
- Proficiency in analyzing log files, conducting trend analysis, and correlating incident data.
- Experience with incident triage, vulnerability identification, and remediation recommendations.
- Familiarity with forensic tools and techniques for collecting artifacts.
- Excellent communication, documentation, and report-writing skills.
- Ability to coordinate incident response functions and collaborate with internal and external teams.
- Stay informed about the latest cyber threats and industry developments.
- ICT jobs
-
Senior Cybersecurity Specialist
1 day ago
Johannesburg, Gauteng, South Africa Empact Group Southern Africa Full timeJob Description:As a Senior Cybersecurity Specialist at Empact Group Southern Africa, you will play a vital role in ensuring the confidentiality, integrity, and availability of all systems across our offices. Your primary responsibility will be to actively manage and monitor information security systems to detect, respond, and remediate information security...
-
Senior Cybersecurity Specialist
16 hours ago
Johannesburg, Gauteng, South Africa City of Shakopee, MN Full timeJob Description:As a Senior Cybersecurity Specialist with Emerson Automation Solutions, you will play a key role in delivering cutting-edge security solutions to our customers in the Southern African region. Your primary responsibility will be to craft and implement security solutions based on Emerson's suite of solutions, working closely with customers to...
-
Senior Cybersecurity Leader
1 day ago
Johannesburg, Gauteng, South Africa Network Recruitment Full time**Information Security Leadership Role**This Senior Cybersecurity Leader position involves leading and managing all aspects of information security, risk management, and IT security across our organization. We are looking for someone with a strong background in these areas to oversee our security processes, controls, and...
-
Specialist IT Cybersecurity
2 days ago
Johannesburg, Gauteng, South Africa Nexio Full timeJob title : Specialist IT CybersecurityJob Location : Gauteng, JohannesburgDeadline : March 21, 2025Quick Recommended LinksJobs by Location Job by industries PRIMARY DUTIES AND RESPONSBILITIES- JOB SPECIFIC REQUIREMENTS Vulnerability Management:Oversee regular vulnerability assessments and penetration tests. Identify, analyse, and prioritise...
-
Johannesburg, Gauteng, South Africa Tower Group Full timeAbout the RoleAt Tower Group, we are seeking an experienced Cybersecurity Specialist to join our team and play a crucial role in identifying, measuring, controlling, and minimizing loss associated with uncertain information and cyber security risks throughout our ICT and business environment.The ideal candidate will have a solid understanding of Information...
-
Trainee Cybersecurity and IT Professional
3 days ago
Johannesburg, Gauteng, South Africa Cyber Factor Full timeAbout Cybersecurity at Cyber Factor:Cybersecurity is at the heart of everything we do. Our team of experts works tirelessly to protect our clients' assets from cyber threats, ensuring their data and infrastructure remain secure. As a member of our Cyber & Information Technology Trainee Program, you will join this mission and contribute to our efforts to stay...
-
Senior Cybersecurity Engineer
6 days ago
Johannesburg, Gauteng, South Africa Standard Bank Group Full time**Our Commitment to Excellence**The Standard Bank Group is dedicated to delivering exceptional service to our clients. We strive to create an environment that fosters innovation, collaboration, and continuous learning.We are seeking a talented Senior Cybersecurity Engineer to join our team. The successful candidate will be responsible for developing and...
-
Cybersecurity Risk Manager
15 hours ago
Johannesburg, Gauteng, South Africa Tradelink Retail Systems Full timeAt Tradelink Retail Systems, we are seeking an exceptional Cybersecurity Risk Manager to join our team. As a key member of our IT department, you will be responsible for ensuring the security and integrity of our systems and data.Key Responsibilities:Monitor System Performance: Regularly check system performance and ensure all technical infrastructure is...
-
IT Incident Resolution Specialist
6 days ago
Johannesburg, Gauteng, South Africa FNB Namibia Full timeJob DescriptionTo ensure that our service delivery is of the highest quality, we require an IT Incident and Problem Specialist to be responsible for managing and resolving incidents and problems in a timely manner.Build strong relationships with internal teams to enhance collaboration and innovation.Deliver exceptional customer service by adhering to quality...
-
Head of Cybersecurity Operations
3 days ago
Johannesburg, Gauteng, South Africa Nedbank Namibia Full timeNedbank Namibia is seeking a highly skilled and experienced leader to lead our Information Security department. As Head of Cybersecurity Operations, you will be responsible for overseeing the virtual security operations centre, threat detection and investigation, incident response, SIEM, network security, cloud security, data loss prevention, threat and...
-
Cybersecurity and IT Service Delivery Expert
6 days ago
Johannesburg, Gauteng, South Africa Tangent International Full timeCybersecurity and IT Service Delivery: As a Cybersecurity and IT Service Delivery Expert, you will be responsible for serving as the primary point of contact for MTN stakeholders regarding data centre operations, ensuring effective communication with clients regarding incidents, planned maintenance, and system performance. You will build and maintain strong...
-
Major Incident Manager
2 days ago
Johannesburg, Gauteng, South Africa Cisco Full timeJob title : Major Incident Manager (Johannesburg)Job Location : Gauteng, JohannesburgDeadline : March 28, 2025Quick Recommended LinksJobs by Location Job by industries What you will doWe make every interaction matter. We have a cloud communications platform at the heart of what we do which enables rich and engaging interactions that integrates...
-
Incident Management Professional
6 days ago
Johannesburg, Gauteng, South Africa FNB Namibia Full timeOur Ideal CandidateWe are looking for a highly motivated and experienced IT Incident and Problem Specialist who possesses excellent communication and problem-solving skills. The successful candidate will have:A proven track record of managing and resolving incidents and problems.Strong analytical and problem-solving skills.Excellent communication and...
-
Cybersecurity Strategy Director
6 days ago
Johannesburg, Gauteng, South Africa Network Recruitment Full timeJob Overview:As a Cybersecurity Strategy Director at Network Recruitment, you will be responsible for leading and managing all aspects of information security, risk management, and IT security across the organization. This includes overseeing the development and implementation of security processes, controls, and technologies to mitigate risks.You will work...
-
Change and Incident Specialist
7 days ago
Johannesburg, Gauteng, South Africa A1L Digital Incorporated Full timeA1L Digital Incorporated is a leading provider of digital solutions, and we are currently seeking a highly skilled Change and Incident Specialist.The successful candidate will have a proven track record of successful management and tracking of corrective actions.Job Description:Problem management and Incident and Change ManagementProficiency in maintaining...
-
Cybersecurity Sales Specialist
3 days ago
Johannesburg, Gauteng, South Africa Mimecast Full timeCareer OverviewMimecast offers a range of career opportunities for ambitious individuals who are passionate about sales and cybersecurity. As a Cybersecurity Sales Specialist - Incydr, you'll have the chance to develop your skills and expertise while making a significant impact in the industry.Our team is dedicated to delivering exceptional customer...
-
Cybersecurity Specialist
6 days ago
Johannesburg, Gauteng, South Africa SSR Personnel Full timeJob DescriptionWe are seeking a skilled Cybersecurity Specialist to join our team at SSR Personnel. As a Cybersecurity Specialist, you will play a vital role in analyzing data sources to identify potential risk indicators and supporting investigations into security threats.The successful candidate will be responsible for gathering intelligence, preparing...
-
Head of Cybersecurity and Innovation
5 days ago
Johannesburg, Gauteng, South Africa Network Recruitment Full timeAbout the RoleWe are seeking a highly skilled Head of Cybersecurity and Innovation to join our team. As a key member of the leadership team, you will be responsible for overseeing the implementation and maintenance of IT systems, infrastructure, and applications to ensure optimal performance and security. You will also lead efforts in ensuring data security,...
-
Cybersecurity Governance Specialist
15 hours ago
Johannesburg, Gauteng, South Africa Kalagadi Full timeJob Description:We are seeking an experienced Cybersecurity Governance Specialist to join our team at Kalagadi.Role Overview:The successful candidate will be responsible for developing and implementing information security standards, guidelines, and procedures. They will also conduct threat and risk analysis, analyse the business impact of new and existing...
-
IT Operations Specialist
1 week ago
Johannesburg, Gauteng, South Africa Rory Mackie & Associates Full timeRole Overview:Our client, a well-established Hedge Fund Manager, with a long history of delivering excellent returns, is seeking a proactive IT Operations Specialist to join their IT team. This person will be responsible for monitoring and improving their Microsoft 365 tenant, providing technical user support, and driving cybersecurity initiatives. In this...