Csoc Analyst

2 weeks ago


Cape Town, South Africa Content+Cloud Full time

This is a hands-on role and requires a broad technical knowledge, skills and abilities. Although the focus is on Cyber Security, knowledge and/or experience of modern IT systems and infrastructure is advantageous to assist with the development and continuous improvement of the security platforms within Content + Cloud and its customer’s environments.

**Requirements**:

- Work within a multi-disciplined CSOC team identifying, owning, progressing and resolving security incidents.
- Provide technical support for the identification and response to events or incidents of a suspicious or malicious nature, and apparent security breaches.
- Work with internal and external stakeholders to resolve computer security incidents and vulnerability compliance.
- Drive customer satisfaction and continuously seek to improve operational performance
- Maintain a continuous understanding of the threat landscape with in-depth knowledge around threat actors, TTPs and vulnerabilities

**Health and Safety**

To comply with Health and Safety legislation, following Content + Cloud processes to ensure your own safety and the safety of others.

**Essential**
- Excellent soft skills in the form of team working, problem solving and communication.
- A keen self-starter who can evidence excellent customer service and can collaborate effectively.
- Demonstrable experience working with SIEM technology, preferably within a CSOC / SOC environment
- Demonstrable technical knowledge, skills and/or experience in intrusion analysis, and network and security investigation using a variety of security tools (EDR, DLP, AV, Snort, Wireshark, TCPdump etc.).
- Working knowledge and experience of core security and infrastructure technologies (e.g. firewall logs, network security tools, malware detonation devices, proxies, IPS/IDS)
- Strong knowledge of understanding of multiple operating systems.

**Desired**
- Having achieved at least a BSc or MSc in Cyber Security incorporating Ethical Hacking, Digital Forensics or Information Security; or
- One or more of the following industry certifications: CEH, GCIA, GCIH, GSEC, Security+, GCTI
- Experience in secured cloud architectures (Azure, AWS) and engineering solutions
- Formal experience in Digital Forensics or experience using EnCase, FTK Imager or similar
- An awareness of cyber security related standards and regulations, for example, NIST, CIS, ISO 27001 and PCI DSS

All recruitment and selection for Content+Cloud is guided by the principles of our Employment Equity Plan