Cyber Threat Hunt Analyst

7 months ago


Cape Town, South Africa Surgo Full time

Surgo (PTY) Ltd. has partnered with a global analytics and digital solutions company serving industries including insurance, healthcare, banking and financial services, media, retail, and others. They aim to bridge the gap between digital expectations and real outcomes for international companies with Digital Intelligence.

Our client is recruiting for a
**Cyber Threat Hunt Analyst** to join their team based in Cape Town.

**Job purpose**:
The role will support and advise on product assessments, policy adjustments, and architectural transformation that will impact regional and global locations. The position requires someone with technical expertise and will provide influence on the design of detective, preventive, and proactive controls.

**Responsibilities**:

- Identify and track threat actor groups and their TTPs while maintaining current knowledge of tools and best practices of APT groups
- Perform cyber threat hunting activity using threat intelligence, analysis of anomalous log data, and related tools
- Collect, enrich, and disseminate IOCs - Indicators of Compromise
- Use the MITRE ATT&CK framework to analyze malicious campaigns and evaluate the effectiveness of security technologies and controls
- Determine true threats, false positives, and network system misconfigurations and provide recommendations and solutions to issues detected
- Monitor the organization’s attack surface against the current threat landscape
- Support the Cyber Threat Intelligence team to provide threat informed defenses that will improve prioritization of preventative controls and mitigations to improve defense posture
- Engage and collaborate with Red Team to analyze and evaluate the effectiveness of existing security controls
- Support Cyber Threat DFIR for internal incidents by performing cyber threat hunting activities during investigations and building a common understanding of threat activities

**Qualification & Experience**:

- Direct experience performing threat hunting in an active corporate environment
- 2+ years of experience in a technical role in the areas of Security Operation, Incident Response, Detection Engineering, Offensive Security/Red Team, or Cyber Threat Intelligence
- Security certification or working towards certification (e.g., SANS, SEC+, CompTIA, Security+, OSCP, or CEH), equivalent experience will be considered
- Direct experience working with large datasets, log review and bulk analysis tools
- Experience consuming and analyzing Cyber Threat Intelligence for actionable takeaways
- Familiarity with offensive security strategies and assessment methodologies
- Knowledge of threat actors, including malware families, intrusion techniques, and associated criminal entities
- Experience explaining threat hunt objectives and ability to communicate associated risks
- Ability to understand requirements and needs from across the organization in order to build consensus and drive results
- Ability to navigate and work effectively across a complex, geographically dispersed organization
- Able to perform proactive threat hunting using multiple toolsets, suggesting, and testing hypotheses, pivoting and reporting on investigation results
- Ability to work on-side

**Beneficial**:

- Experience with more than one more enterprise scale EDR and SIEM tool
- Experience using Internet and network scanning tools for malicious host discovery
- Basic understanding of building threat hunting queries using KQL, SIGMA, or Yara
- Previous experience using a Threat Intelligence platform or CTI vendor
- Demonstrated ability to self-direct, with mínimal supervision to achieve assigned goals
- Knowledge of basic Data Science concepts and processes
- Experience with offensive security tools and technical and the methods used to compromise large networks
- Previous experience performing digital forensics or incident response on major security incidents

**Salary**: Market Related

**Working Hours**: Monday to Friday - 08:00am to 17:00pm



  • Cape Town, South Africa Surgo HR & Training Full time

    Surgo (PTY) Ltd. has partnered with a global analytics and digital solutions company serving industries including insurance, healthcare, banking and financial services, media, retail, and others. They aim to bridge the gap between digital expectations and real outcomes for international companies with Digital Intelligence. Our client is recruiting for a...


  • Cape Town, South Africa Nclose Full time

    **Cyber Defence Analyst** This new role is designed to assist the Defence team with Responses to incidents, researching trending malware and defensive actions needed to defend against them and to Analyse current threats detected and find trends to assist the defence team in hardening the tech to protect against these threats. - Systems Engineer with some...


  • Cape Town, South Africa BASHR Consulting Full time

    As a Cybersecurity Analyst you will be required for analysing and reporting on network traffic, implementing solutions that provide IT security, and coordinating various teams within the company. You will be responsible for monitoring and evaluating threats that could potentially breach the network. **Requirements**: - Tertiary Qualification - AWS:...


  • Cape Town, South Africa Exclusively Remote Full time

    One of our US based clients are looking for experienced Cyber Security Analyst/Specialist with a strong background in Cyber Security and prior experience working for a Managed Service Provider (MSP). Responsibilities: - **Cyber Security**: Implement and manage cyber security solutions to safeguard clients' IT environments from potential threats,...


  • Cape Town, South Africa PPECB Full time

    Job Description**Cyber Security Operational Analyst** **Overview**: **Responsibilities**: - Monitor security systems to detect and respond to security incidents, threats, and vulnerabilities in a timely manner. - Review and analyse security logs and alerts to identify potential security breaches and threats. - Conduct investigations into security incidents...

  • T2 Security Analyst

    7 months ago


    Cape Town, South Africa Job Crystal Full time

    A company providing secure cloud transformation by combining Microsoft cloud technology with cyber security, and managed services is looking for a T2 Security Analyst in Cape Town to assist the SecOps Tech Lead and Head of Security Operations in enhancing the SOC & SOAR operations within the company. The Security Analyst will collaborate closely with other...

  • Security Analyst

    7 months ago


    Cape Town, South Africa Capital Edge Recruitment Full time

    Join a team of Security Analyst (SOC Tier 2) at an international IT MSP, where you’ll play a pivotal role in enhancing their Security Operations Center (SOC) and Security Orchestration, Automation, and Response (SOAR) operations. Collaborate with talented teams to build services and solutions that align with security best practices and client assurance...

  • Senior Csoc Analyst

    24 hours ago


    Cape Town, South Africa Content + Cloud Full time

    **Location**: Cape Town, Western Cape **Job Title**: Senior CSOC Analyst **Salary Type**: Negotiable **Education Level**: Diploma **Job Level**: Senior **Required Experience**: 3 - 5 Years The Senior CSOC Analyst role is part of the Cyber Security Operations Centre (CSOC) and sits within the Security & Networks area of Content + Cloud This is a...


  • Cape Town, South Africa Woolworths Full time

    Advert reference: woolw_000639 Advert status: Online - **Position Summary** **Industry**:IT & Internet **Job category**:Others: IT and Telecommunication **Location**:Cape Town **Contract**:Permanent **Remuneration**:Market-related **Introduction** We are searching for an energetic, output-driven Senior Blue Team Ninja to support the execution of the...


  • Cape Town, South Africa Woolworths Full time

    Advert reference: woolw_000638 Advert status: Online - **Position Summary** **Industry**:IT & Internet **Job category**:Others: IT and Telecommunication **Location**:Cape Town **Contract**:Permanent **Remuneration**:Market-related **Introduction** We are searching for an energetic, output-driven Blue Team Ninja to support the execution of the cyber...


  • Cape Town, South Africa Woolworths Full time

    Advert reference: woolw_000593 Advert status: Online - **Position Summary** **Industry**:IT & Internet **Job category**:Others: IT and Telecommunication **Location**:Cape Town **Contract**:Permanent **Remuneration**:Market-related **Introduction** We are searching for an energetic, output-driven Blue Team Ninja to support the execution of the cyber...


  • Cape Town, South Africa TMF Group Full time

    **About Us** With 8,000 in-house experts in over 80 locations - you will be part of our #OneTMF family where you can learn and grow alongside of colleagues from different parts of the world. TMF Group is the only company worldwide to provide the combination of fiduciary, company secretarial, accounting and tax and HR and payroll services to businesses...


  • Cape Town, South Africa LRI Invest Full time

    Description L3 SOC/Security Analyst Cape Town Summary of the position Outline of main duties and responsibilities The SME/Expert Security Analyst L3 performs penetration tests, threat hunting, and optimising security monitoring tools. Key responsibilities include: - Review asset discovery and vulnerability assessment data to identify and prioritize...


  • Cape Town, South Africa Kocho Full time

    JOB PURPOSE This position will assist the SecOps Tech Lead and Head of Security Operations in enhancing the SOC & SOAR operations within Kocho. The Security Analyst will collaborate closely with other teams to build services and solutions that align with security best practices and client assurance requirements. This includes, but is not limited to, the use...


  • Cape Town, South Africa City of Cape Town Full time

    ELIGIBILITY CLOSING DATE 15.11.2024 REFERENCE NUMBER CS 187/24 ext SALARY R1533805.00 - R1899481.00 DEPARTMENT Information Systems and Technology DIRECTORATE CORPORATE SERVICES Manager - Cyber Security **Requirements**: - A relevant three-year tertiary qualification, preferable a Bachelor’s degree in Information Systems or Computer Science - Information...


  • Cape Town, South Africa Secondments Recruitment Full time

    **Job Advert Summary**: **Minimum Requirements**: - Bachelor's degree in Computer Science, Information Security, or a related field. - 3+ years of experience in a security operations role. - Strong knowledge of industry best practices and regulatory requirements related to cyber security. - Strong knowledge & experience with security frameworks such as...

  • Security Analyst

    2 weeks ago


    Cape Town, South Africa Qualip Solutions Full time

    Technically focused security analyst as an embedded member of the CIB Security Engineering team Provide security analysis and design input as a member of the CIB Security Engineering team with a focus on establishing the security enablers required by the CIB product engineering community as well as tactical support for teams when needed.The CIB Security...

  • Cyber Grc Consultant

    7 months ago


    Cape Town, South Africa Strategic Placements CC Full time

    **Requirements**: - Relevant qualification (CISM / GRCP / CISSP / B.Com Information Systems or similar) - Minimum 3 years’ experience as a Cyber Security practitioner with relevant knowledge in GRC - Experience in assessing and/or implementing security and risk standards (NIST, ISO 27001, PCI DSS, ITIL, COBIT) - Experience in writing risk assessment...

  • Head of Cyber Security

    9 months ago


    Cape Town, South Africa CyberPro Consulting Full time

    CyberPro Consulting merges a fervor for technology with a sincere interest in our customers' business and success. Boasting more than two decades of experience in the IT and software development industry, CyberPro Consulting serves a diverse clientele, spanning from large-scale enterprises to SME businesses. As Head of Cyber Security in our Cape Town...

  • Cyber Security Lead

    5 months ago


    Cape Town, South Africa Clicks Group Limited Full time

    **Listing reference**: 017709**Listing status**: Online- **Position summary** **Industry**:IT & Internet - **Job category**:IT and Telecommunications**Location**:Cape Town - **Contract**:Permanent**EE position**:No**Introduction**Job description** **JOB OBJECTIVES**Lead, mentor, and manage a team of cyber security specialists in performing security...