Specialist: Cybersecurity Analyst
2 weeks ago
**ROLE PURPOSE**
As part of the Customer-facing Nexio SOC team, the Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and provide guidance to SOC Analysts. By leveraging threat intelligence and conducting in-depth analysis, Cybersecurity Analyst identifies the scope of attacks, impacted systems, and potential perpetrators. The Cybersecurity Analyst ensures metrics are monitored, offers recommendations, and advises on containment and recovery steps. The Cybersecurity Analyst documents incidents, updates relevant documentation and supports the development of analytic methods for threat detection.
He/She should ideally have competency in security incident handling analysis experience in an established SOC environment and contribute to risk management, participate in Blue Team exercises, and develop playbooks for incident scenarios. The Cybersecurity Analyst monitors network traffic, investigates incidents, and collaborates with the SOC team to respond to threats or intrusions.
**ROLE REQUIREMENT**
- Adheres to the standard operating procedure and playbooks in the SOC.
- Impacts on Customer satisfaction and confidence in the SOC Service and service level performance.
- Validate and declare security incidents based on incident handling methodologies.
- Confirm severity levels (S0 to S4) using SLA severity classification.
- Provide guidance and support to SOC Analysts during incident response.
- Utilize threat intelligence, updated rules, and IOCs to identify affected systems and the extent of attacks.
- Conduct in-depth threat intelligence analysis to uncover attack types, data/systems impacted, and potential perpetrators.
- Make recommendations to incident managers regarding additional analysis and required remediation.
- Determine the impact on critical systems or data sets and advise on remediation steps.
- Validate false positives, policy violations, intrusion attempts, security threats, and potential compromises.
- Suggest containment and recovery steps based on analysis findings.
- Formally document learnings and update relevant documentation such as tickets and run books.
- Provide support for analytic methods to detect threats and conduct further triage based on defined run books.
- Consolidate data through alert triage, providing necessary context before escalating to Operations and Security Engineering Teams for deeper analysis.
- Manage security events, incidents, and service requests via the ticketing systems.
- Identify alarms by intent and method, including reconnaissance, system compromises, and ingested log sources:
- Firewalls and network devices
- Infrastructure server and end-user systems
- Threat intelligence platforms
- Web proxies
- Cloud and hybrid-IT provisioning, access, and infrastructure systems (Amazon Web Services)
- Antivirus systems
- Intrusion detection and prevention systems
- Similar in Scope source systems
- Validate and update initial tickets in the SIEM platform and Service Desk.
- Monitor event queues, investigate potential incidents, and escalate or close events as necessary.
- Validate investigation results and pass relevant details to the SOC Team Lead.
- Assess security controls based on cybersecurity principles and frameworks (e.g., CIS CSC, NIST SP 800-53).
- Analyze network traffic, characterize threats, and coordinate with cyber defense staff for validation.
- Document and escalate incidents, perform trend analysis, and report findings.
- Review security architecture, identify gaps, and recommend risk mitigation strategies.
- Provide timely detection, identification, and alerting of possible attacks, intrusions, and anomalous activities.
- Utilize cyber defense tools for monitoring and analyzing system activity, identifying and analyzing malicious behavior.
- Conduct analysis of network traffic, including network mapping, OS fingerprinting, and identification of compromised credentials.
- Assist in the development of signatures for cyber defense tools.
- Notify stakeholders of suspected cyber incidents, articulate event details, and follow the organization's incident response plan.
- Analyze and report on organizational and system security posture trends.
- Assess access controls and monitor external data sources for emerging threats.
Additional Information:
- Individuals at this level are competent in best practices in security incident handling in an established SOC.
- Able to build strong interpersonal relationships with the SOC team and customer stakeholders.
- Competent communication skills and communication of complex information to non-technical stakeholders.
- Competent in producing and presenting work.
- Good understanding of security incident analysis and incident handling practices, proficient knowledge of networking protoco
-
Senior Specialist: Cybersecurity Analyst
1 week ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Senior Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and...
-
Cybersecurity Operations Specialist
2 days ago
Midrand, Gauteng, South Africa Merafong ICT Full timeCybersecurity Operations SpecialistThe ideal candidate for this role will have 3-5 years of experience in a SOC environment and prior work in IT or cybersecurity. You will be responsible for overseeing security systems and alerts to detect unusual activity, reviewing and investigating alerts generated by security tools, and implementing strategies to contain...
-
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and...
-
Cybersecurity Specialist
3 days ago
Midrand, Gauteng, South Africa Merafong ICT Full timeAbout the RoleWe are seeking a highly skilled Cybersecurity Specialist to join our team at Merafong ICT. As a key member of our cybersecurity team, you will be responsible for identifying and analyzing sophisticated threats and vulnerabilities using advanced tools and techniques.Key Responsibilities:Advanced Threat Detection: Identify and analyze...
-
Cybersecurity Analyst- Midrand
2 weeks ago
Midrand, South Africa Fidelity Services Group Full time**Job Title**:Cybersecurity Analyst** **Location**: Ulwazi Campus Midrand/Helderkruin **Reports to**: Information Security Manager** **Job Summary**: We are seeking a skilled and dedicated Cybersecurity Analyst to join our Cybersecurity team in the physical security industry. As a Cybersecurity Analyst, you will play a crucial role in ensuring the...
-
Cybersecurity Analyst
1 week ago
Midrand, South Africa Fidelity Services Group Full time**Job Title**: Cybersecurity Analyst **Location**: Ulwazi Campus Midrand/Helderkruin **Reports to**: Information Security Manager** **Job Summary**: We are seeking a skilled and dedicated Cybersecurity Analyst to join our Cybersecurity team in the physical security industry. As a Cybersecurity Analyst, you will play a crucial role in ensuring the security...
-
Senior Specialist: Cybersecurity Threat Analyst
2 weeks ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Threat Analyst will be responsible for monitoring enterprise networks and systems, deterring, identifying, investigating, and mitigating, any and all threats that are directed against those systems regardless of their classification level or type. The Cybersecurity Threat...
-
Specialist: Cybersecurity Incident Manager
1 week ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and...
-
Senior Cybersecurity Specialist
14 hours ago
Midrand, Gauteng, South Africa Profile Personnel Full timeProfile Personnel is a dynamic company that requires a Senior Cybersecurity Specialist to join our team. The successful candidate will have a proven track record in designing and implementing robust cybersecurity solutions.This is an exciting opportunity to work with a talented team of IT professionals who share your passion for cybersecurity. You will have...
-
Cybersecurity Specialist
5 days ago
Midrand, Gauteng, South Africa Careers at DLK Group Full timeMidrand, South Africa | Posted on 19/12/2024The Cybersecurity Specialist is responsible for safeguarding the organization's digital assets, networks, systems, and data. The role ensures robust security measures are in place to protect against threats, vulnerabilities, and unauthorized access while ensuring compliance with governance and regulatory...
-
Chief Cybersecurity Officer
9 hours ago
Midrand, Gauteng, South Africa iOCO Full timeCybersecurity Leadership OpportunityWe are seeking a seasoned leader to manage our cybersecurity services, ensuring seamless operations and compliance with industry standards.Responsibilities:Oversee the performance and operations of the SOC, ensuring SLA and KPI adherence.Supervise security analysts, shift leads, and third-party service providers.Maintain a...
-
Senior Specialist: Cybersecurity Infrastructure
2 weeks ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Senior Specialist: Cybersecurity Infrastructure Support will identify, analyze and react to security incidents, events, and threats using a reliable set of operating processes and SIEM technologies such as Azure Sentinel, or QRadar, or ArcSight. The Senior Specialist: Cybersecurity...
-
Specialist IT Cybersecurity
6 days ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** **PRIMARY DUTIES AND RESPONSBILITIES- JOB SPECIFIC REQUIREMENTS** Vulnerability Management**: - Oversee regular vulnerability assessments and penetration tests. - Identify, analyse, and prioritise vulnerabilities in the IT environment. - Develop and implement remediation plans to address identified vulnerabilities. **Patch...
-
Threat Intelligence Analyst
2 days ago
Midrand, Gauteng, South Africa Merafong ICT Full timeThreat Intelligence AnalystThe Threat Intelligence Analyst will be responsible for utilizing threat intelligence feeds to stay updated on the latest threats and vulnerabilities. This includes integrating relevant information into incident response strategies and collaborating with IT teams to ensure a unified approach to cybersecurity.This position requires...
-
Information Security Analyst
2 days ago
Midrand, Gauteng, South Africa Merafong ICT Full timeMerafong ICT seeks an Information Security Analyst to join its team. As a critical member of the organization, you will play a key role in ensuring the security and integrity of our systems and data.Key Responsibilities:Conduct incident response and management activities to identify, contain, and remediate security incidents.Develop and maintain threat...
-
Information Security Specialist
5 days ago
Midrand, Gauteng, South Africa Careers at DLK Group Full timeCareers at DLK Group is seeking an Information Security Specialist to join our team. As an Information Security Specialist, you will be responsible for protecting our organization's digital assets and networks from threats and unauthorized access.Key ResponsibilitiesNetwork Security:Implement and maintain a robust security posture across our network...
-
Security Operations Center Analyst Level 2
3 days ago
Midrand, Gauteng, South Africa Merafong ICT Full timeSecurity Operations Center Analyst Level 2Job ResponsibilitiesIncident Response and ManagementIncident Triage: Assessing incoming security alerts and determining the appropriate response based on the severity and nature of the threat. This includes prioritizing incidents that require immediate attention.Investigation: Conducting in-depth analysis of...
-
Pricing Specialist for Managed Services
6 days ago
Midrand, Gauteng, South Africa Nexio Full timeAbout NexioNexio is a specialist ICT solution provider that helps clients build, support, and manage their IT infra-structures. We have operations in all 9 provinces across the country, over 200 clients, and over 600 employees. As a Level 1 BBBEE, we put our commitment to South Africa's transformation agenda into practice, driving digital transformation and...
-
L3 Security Incident Handling Analyst
4 days ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the L3 Security Incident Handling Analyst will identify, analyse and react to security incidents, events and threats using a reliable set of operating processes and SIEM technologies such as Azure Sentinel, or QRadar, or ArcSight. The SIEM Platform Lead will support the architecture, deployment,...
-
Data Analyst
4 weeks ago
Midrand, Gauteng, South Africa Network Recruitment Full timeJob & Company Description:An industry requiring specialist skills, deserves specialist recruitment.I am a Specialist Risk Analytics & Data recruiter working with very prestigious corporate concerns in Gauteng. Assisting you in exploring new commercial opportunities within the market is my main priority. This will allow me to enhance your current skills...