L3 Security Incident Handling Analyst

2 weeks ago


Midrand, South Africa Nexio Full time

**ROLE PURPOSE**
As part of the Customer-facing Nexio SOC team, the L3 Security Incident Handling Analyst will be responsible for monitoring enterprise networks and systems, detecting events and reporting on any and all threats that are directed against those systems regardless of their classification level or type. The L3 Security Incident Handling Analyst is expected to collaborate with leadership to develop metrics based on situational awareness and threat monitoring at an enterprise level that will be reported based on the approved plan and supporting checklists. The L3 Security Incident Handling Analyst must be able to rapidly address security incidents alerted primarily by an industry recognised Security Information and Events Management [SIEM].

He/She should ideally have advanced security incident handling analysis experience in an established SOC environment where ArcSight, or Azure Sentinel, or QRadar was the SIEM platform.

**ROLE REQUIREMENTS**
- Is familiar with the tactical and long-term vision across the Cyber Security function.
- Team lead on Security Incident Analysis and Handling within the SOC function.
- Adheres to the standard operating procedure and playbooks in the SOC.
- Direct impact on the SOC performance.
- Impacts on team’s runbooks and operational processes in the SOC Service.
- Provides security incident handling and technical guidance to SOC Teams.
- Gives regular, comprehensive and constructive feedback, and coaching and mentoring to team.
- Delegates work to team members taking into account their capacity, level of skill and exposure to different types of work and complexity; provides clear instructions and direction, with reasonable deadlines.
- Provides support for complex computer network exploitation and defence techniques to include deterring, identifying and investigating computer and network intrusions
- Provides incident response and remediation support; performing comprehensive computer surveillance/monitoring, identifying vulnerabilities; developing secure network designs and protection strategies, and audits of information security infrastructure.
- Provides technical support for continuous monitoring, computer exploitation and reconnaissance; target mapping and profiling; and, network decoy and deception operations in support of computer intrusion defence operations.
- Provides technical support for forensics services to include evidence seizure, computer forensic analysis and data recovery, in support of computer crime investigation.
- Researches and maintains proficiency in open and closed source computer exploitation tools, attack techniques, procedures and trends. Performs research into emerging threat sources and develops threat profiles.
- Provides technical support for a comprehensive risk management program identifying mission critical processes and systems; current and projected threats; and system vulnerabilities.
- Lead Red Team / Blue Team exercises and identify gaps in current monitoring tools and processes.
- Develops playbooks for various incident scenarios and have a knowledge of automation processes and products.
- Mentors Junior Analysts to become more effective in their roles.
- Application of security settings and other commercial best practices such as SIEM Analysis operations.
- Incident analysis from ingested source systems combined with threat intelligence feeds into the SIEM from open source and commercial feeds.

Additional Information:

- Individuals at this level have fully developed knowledge of best practices in security incident handling in an established SOC.
- Able to build strong interpersonal relationships with the SOC team and customer stakeholders.
- Excellent verbal and written communication skills.
- Able to align multiple strategies and ideas.
- Confident in producing and presenting work.
- In-depth understanding of best security incident analysis and incident handling practices in an established SOC.

**QUALIFICATIONS & EXPERIENCE**
- Grade 12
- Bachelor’s Degree in Computer Science or a related technical discipline, or the equivalent combination of education, technical certifications
- One or more these industry Cybersecurity Certifications: CISSP-ISSEP, CISSP-ISSAP, GIAC Certified Incident Handler (GCIH), Certified Computer Security Incident Handler (CSIH), CEH, OSCP, CompTiA
- Minimum of five (5) years of work experience, and two (2) years of relevant experience in and established SOC and information security/cybersecurity
- Experience with defining SOC playbooks.
- Experience with a ticketing system such as BMC Remedy.
- Basic Linux and Windows Server experience.
- Experience working with virtual environments.
- Strong analytical and organizational skills.
- Concise writing skills, excellent MS Word skills as well as other MS Office Applications.
- Experience with securing various environments preferred.
- Experience in working across security frameworks.
- Experience in working across security technologies.
- Poss



  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Threat Analyst will be responsible for monitoring enterprise networks and systems, deterring, identifying, investigating, and mitigating, any and all threats that are directed against those systems regardless of their classification level or type. The Cybersecurity Threat...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Threat Analyst will be responsible for monitoring enterprise networks and systems, deterring, identifying, investigating, and mitigating, any and all threats that are directed against those systems regardless of their classification level or type. The Cybersecurity Threat...

  • SOC Analyst

    3 weeks ago


    Midrand, South Africa Datacentrix Full time

    Gauteng, Midrand (Market related, Negotiable)Datacentrix is looking for SOC Analysts Level 1 & Level 3 to provide initial investigation of all security incidents, and management of incident from inception to resolution and liaise with vendor and Engineers to resolve incidents where required. Must have experience in installing, configuring, and maintaining...


  • Midrand, South Africa SRIVEN IT SOLUTIONS Full time

    **Role Description and Responsibilities**: One of the largest internationally renowned Accounting and Auditing firm is **urgently** looking for **Workday Configuration Support Analyst (Senior Associate) - HCM & Compensation **to join the HR Systems Practice in Operate Digital. The Operate Digital HR Systems Practice are a team of People Technology...


  • Midrand, South Africa TRSS 24 Full time

    Employer**:Tactical Reaction Services** **CONTROL ROOM OPERATOR (SECURITY)** We are a leading company in the security industry that strive for service excellence and quality products. Professionalism, Proficiency and a Proactive attitude support our mission in being the BEST security company in SA. We require the services of a _**Control Room...


  • Midrand, South Africa Siemens Full time

    **Job Title / Role: Security Professional** **Organization: Lead Country South Africa** **Location: Midrand, South Africa** **Reporting Manager: Security Manager** The Business Siemens is a global powerhouse in diversified engineering providing products, systems and solutions across the Electrification, Automation and Digitalization value chain. The...

  • Security Officer

    7 days ago


    Midrand, South Africa Maanda Nes Investments Full time

    **Job Title: Security Guard** **_05_** **_Februa_** **_ry_** **_2_** **_023_** **JOB SPECIFICATION** **Responsibilities**: - Conduct regular foot patrols of the office premises both indoors and outdoors - Monitor security systems, including CCTV cameras, alarm systems, and access control points - Respond to alarms, incidents, and emergencies promptly and...


  • Midrand, South Africa Xcellency Human Capital (Pty) Ltd Full time

    **Responsibilities**: - Microsoft Security: - Implement and manage Microsoft security solutions, including but not limited to Microsoft Defender ATP, Azure Security Centre, and Windows Defender Firewall. - Conduct regular security assessments and audits to identify and address vulnerabilities. - Sophos Firewall Management: - Configure, deploy, and manage...


  • Midrand, South Africa MSD Full time

    Reporting to the Associate Director, Regional Security Middle East Africa (MEA), the Regional Security Senior Specialist will be responsible for supporting Global Security Group (GSG) Operations in Sub-Sahara Africa (French West Africa, English & Portuguese Africa, South Africa). He/She will be responsible for providing primary security support for all...

  • SOC Analyst

    3 weeks ago


    Midrand, South Africa Data Centrix Full time

    **Minimum Qualification**: - Matric plus Diploma/Degree in Information Security - MS Security Certification - 3 - 4 years of experience working in IT or SOC environment **Role Description**: - Providing supporting security services and actionable reporting - Analyze threats and logs, alerts and reports - Proactively look for suspicious anomalous activity...


  • Midrand, South Africa Vodafone Full time

    **Role purpose**: **Your responsibilities will include**: Provide supervisory technology security operations and support to high profile projects, Ensure security is embedded in IT System and Network Infrastructure (Mobile, IS and Enterprise) across the Vodacom Group Support Cyber Incident Response actions. Defining, implementing and efficiently maintaining...

  • Security Specialist

    7 days ago


    Midrand, South Africa Jurumani Solutions Full time

    Jurumani offers an environment where creativity and the practice of building things is believed to be fundamentally useful to both the Client and Jurumani Solutions. Providing opportunity to focus on making products and business operating capabilities work, which means we often are more concerned with how systems align, orchestrate and integrate to achieve...


  • Midrand, South Africa Enshrine Placements Full time

    **Area Security Manager - Midrand, Gauteng - Job-3692** Area Security Manager needed to develop and roll out the best security practices for the security discipline at North Stations. **Position details**: Type: Permanent Reports to: Security Business Unit Manager Reporting, total staff compliment: Job titles of direct reports: Assistant Station Head...


  • Midrand, South Africa TRSS Security Full time

    We are a leading company in the security industry that strive for service excellence and quality products Professionalism, proficiency and proactive attitude support our mission in being the BEST security company in South Africa. **QUALIFICATIONS & EXPERIENCE**: - PSIRA Grade A registration & accreditation - 5 Years minimum experience in a Security...


  • Midrand, South Africa TRSS Security Full time

    We are a leading company in the security industry that strive for service excellence and quality products Professionalism, proficiency and proactive attitude support our mission in being the BEST security company in South Africa. **QUALIFICATIONS & EXPERIENCE**: - PSIRA Grade A registration & accreditation - 5 Years minimum experience in a Security...


  • Midrand, South Africa Vodafone Full time

    **.**: **When it comes to igniting a team of trailblazers, we're number 1.** The number 1 Top Employer in South Africa. Certified by the Top Employer Institute 2024. **Role Purpose/Business Unit**: To support and Manage the end-to end service management of DCA automation and Patching tools. **Your responsibilities will include**: - Assist and vet...


  • Midrand, South Africa Nexio Full time

    **ROLE REQUIREMENT** - To increase security threat detection capability and defence effectiveness in the Security Assessment Team, and SOC Team in their engagements with customers. - Provides support for Nexio Offensive Security capabilities for the Security Assessment Team, and SOC Team for customers’ engagements. - Direct impact on business resilience...

  • System Analyst

    6 days ago


    Midrand, South Africa Deka Minas (Pty) Ltd Full time

    **JOB PURPOSE** The System Analyst ensures that GIT Service Management systems are maintained and developed to ensure GIT Service Management objectives are met. The System Analyst ensures that GIT delivers stable and high-quality software systems to its client, TIH. This is done by understanding, studying and analysing requirements for system changes and...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** To define, evolve and execute the Security solution portfolio to deliver value for our customers and revenue and profits for the business. Will be responsible for ensuring the profitability of the Security solution area, across verticals throughout Nexio. Will define the overall execution of strategy and definition of the action plan to...