L2 Security Incident Manager

2 days ago


Midrand, South Africa Nexio Full time

**ROLE PURPOSE**
As part of the Customer-facing Nexio SOC team, the L2 Security Incident Manager will identify, analyse and react to security incidents, events and threats using a reliable set of operating processes and SIEM technologies such as Azure Sentinel, or QRadar, or ArcSight. The SIEM Platform Lead will support the architecture, deployment, management and maintenance of these SIEM platforms.

The L2 Security Incident Manager will be responsible for monitoring enterprise networks and systems, detecting events and reporting on any and all threats that are directed against those systems regardless of their classification level or type. The L2 Security Incident Manageris is expected to collaborate with leadership to develop metrics based on situational awareness and threat monitoring at an enterprise level that will be reported based on the approved plan and supporting checklists. The L2 Security Incident Managermust be able to rapidly address security incidents alerted primarily by an industry recognised Security Information and Events Management [SIEM].

He/She should ideally have advanced security incident handling analysis experience in an established SOC environment where ArcSight, or Azure Sentinel, or QRadar was the SIEM platform.

**ROLE REQUIREMENT**
- Is familiar with the tactical and long-term vision across the Cyber Security function.
- Team lead on Security Incident Analysis and Handling within the SOC function.
- Adheres to the standard operating procedure and playbooks in the SOC.
- Direct impact on the SOC performance.
- Being the point of contact to drive all cyber incidents managed by the Nexio Cyber Defense Team
- Creates incident reports
- Tracks cases
- Keeps cases and incidents status up to date through regular updates
- Participates in the incident management process from investigation to resolution
- Maintain daily communication with the SOC Analyst team
- Tracks tickets, severity, and assists to drive incidents to a conclusion based on SLAs and criticality level
- Coordinate the activities of analysts and parties external to the Cyber Defense Team involved incident response
- Prepares weekly incident status report

Additional Information:

- Individuals at this level have fully developed knowledge of best practices in security incident management in an established SOC.
- Able to build strong interpersonal relationships with the SOC team and customer stakeholders.
- Excellent verbal and written communication skills.
- Able to align multiple strategies and ideas.
- Confident in producing and presenting work.
- In-depth understanding of best security incident management practices in an established SOC.

**QUALIFICATIONS & EXPERIENCE**
- Grade 12
- Bachelor’s Degree in Computer Science or a related technical discipline, or the equivalent combination of education, technical certifications
- One or more these industry Cybersecurity Certifications: CISSP-ISSEP, CISSP-ISSAP, GIAC Certified Incident Handler (GCIH), Certified Computer Security Incident Handler (CSIH), CEH, OSCP, CompTiA
- Minimum of five (5) years of work experience, and two (2) years of relevant experience in and established SOC and information security/cybersecurity
- Experience with security incident management and optimising the dashboarding, reporting and visibility of the SOC SLA performance for Customer stakeholders.
- Experience with a ticketing system such as BMC Remedy.
- Strong analytical and organizational skills.
- Concise writing skills, excellent MS Word skills as well as other MS Office Applications.
- Experience with securing various environments preferred.
- Experience in working across security frameworks.
- Experience in working across security technologies.
- Possess very good knowledge of technological advances within the information security area
- Demonstrate in depth solution and service knowledge

**LEADERSHIP COMPETENCY REQUIREMENTS
- Responsive to reasonable customer, supplier, peer, and line management requests
- Proactive, innovative and reliable
- Put the customer first
- Do things right first time
- Positively contribute to this high-performance team
- Go the extra mile in the best interest of the company
- Develop positive and productive relationships with peers and customers
- Demonstrate emotional intelligence, and act with integrity
- Has demonstrated the ability to work well with others, high performance team work ethic
- Excellent communicator and collaborator
- Willingness to learn range of security technologies and platforms
- Positive attitude
- Delivering results and meeting customer expectations
- Following business-relevant instructions and procedures
- Learning and researching in various areas in cybersecurity

**Application Submission Details**:

- **Updated CV**:

- ** Short motivation Letter**:

- ** Supporting qualifications/certifications if any


  • Senior Engineer

    3 weeks ago


    Midrand, South Africa IOCO Full time

    We are seeking a highly skilled Senior Engineer (SASE – L2) with deep expertise in Secure Access Service Edge (SASE), networking, and security solutions.  As a Senior Engineer (SASE – L2)  you'll be responsible for designing, deploying, managing, and optimizing SASE solutions for clients to ensure secure, scalable, and reliable...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the L3 Security Incident Handling Analyst will identify, analyse and react to security incidents, events and threats using a reliable set of operating processes and SIEM technologies such as Azure Sentinel, or QRadar, or ArcSight. The SIEM Platform Lead will support the architecture, deployment,...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and...

  • SOC Analyst

    3 weeks ago


    Midrand, South Africa Data Centrix Full time

    **Minimum Qualification**: - Matric plus Diploma/Degree in Information Security - MS Security Certification - 3 - 4 years of experience working in IT or SOC environment **Role Description**: - Providing supporting security services and actionable reporting - Analyze threats and logs, alerts and reports - Proactively look for suspicious anomalous activity...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and...


  • Midrand, Gauteng, South Africa Merafong ICT Full time

    Incident Response ExpertWe are seeking an experienced Incident Response Expert to join our team. In this role, you will conduct in-depth analysis of escalated security incidents, utilizing various tools and methodologies to uncover the root causes and potential impacts.As a member of the Merafong ICT team, you will work collaboratively with IT and other...


  • Midrand, South Africa Vodafone Full time

    **Role purpose**: Cyber Defence is one of MPA’s critical Cyber Security teams. The Cyber Defence team’s mission is to deliver a highly effective end-to-end 24x7 Cyber Defence service. They are responsible for proactively identifying threats and vulnerabilities; detecting and mitigating cyber events, and managing cyber security incident responses to...


  • Midrand, South Africa Avatar Recruitment Full time

    Our clients are a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax and related services. Our global network of member firms and related entities in more than 150 countries and territories serves four out of five Fortune Global 500 companies. The main purpose of the job is to support the engagement Senior...


  • Midrand, South Africa Ability Recruitment Full time

    **Gauteng** **,** **Midrand** **Annually** **(Market related)** **(Negotiable)** **The main purpose of this position is to provide a comprehensive physical security management service for the site. By way of managing of subcontractors and managing areas of security risk, in accordance with established Service Level Agreements (SLAs).** **Must be...


  • Midrand, South Africa SACAA Full time

    **INTRODUCTION** The South African Civil Aviation Authority (SACAA) has an exciting opportunity in our Corporate Security section. We are looking for a talented individual with the relevant skills and experience who will identify, develop, implement and manage the SACAA’s security strategies and programs. **SECURITY MANAGEMENT** - Conduct security...


  • Midrand, South Africa Maanda Nes Investments Full time

    **Job Summary**: **Key Responsibilities**: - **Project Planning and Initiation**: - Develop comprehensive project plans, including timelines, resource allocation, and risk assessments. - Define project scope, goals, and deliverables. - Identify and engage key stakeholders. - Develop project budgets and track expenses. - **Project Execution**: - Oversee...

  • Security Supervisor

    7 days ago


    Midrand, South Africa DBSA Full time

    The Security Supervisor is responsible for assessing security risks and threats to the organisation and implementing operational methods and processes that mitigate physical security services; i.e. guarding, patrolling, regulating all access and egress, concierge service to the DBSA and the provision of VIP protection services as and when required. The...


  • Midrand, Gauteng, South Africa IOCO Full time

    We are seeking a results-driven Service Manager with a passion for delivering top-tier cybersecurity solutions that protect businesses from evolving threats. Skilled in service delivery, incident response, and stakeholder management, ensuring seamless operations and compliance with industry standards. Adept at optimizing SOC, risk management, and cloud...


  • Midrand, Gauteng, South Africa IOCO Full time

    We are seeking a results-driven Service Manager with a passion for delivering top-tier cybersecurity solutions that protect businesses from evolving threats. Skilled in service delivery, incident response, and stakeholder management, ensuring seamless operations and compliance with industry standards. Adept at optimizing SOC, risk management, and cloud...


  • Midrand, South Africa The Aurum Institute Full time

    **Coordinator**:Security Management** The Security Management Coordinator will be based at the Aurum Midrand Facility and their primary role is to monitor surveillance cameras (fleet and facilities) and implement policies and procedures to protect life and property. The Security Management Coordinator’s tasks include the day-to-day management of: -...


  • Midrand, South Africa iOCO Full time

    JOBNUMBER **iOCO03488** - CONTRACT TYPE **Permanent** - CONTRACT TYPE: **OnSite** **The Role**: We are seeking a results-driven S**ervice Manager**with a passion for delivering top-tier cybersecurity solutions that protect businesses from evolving threats. Skilled in service delivery, incident response, and stakeholder management, ensuring seamless...


  • Midrand, South Africa Liquid Tech (Pty) Ltd. Full time

    **Role Purpose** To deliver day-to-day managed security services (MSS), related to SOC deliverables. Critical in this regard is to execute according to Standard Operating Procedure (SOP) expectations and meeting all related service level agreements (SLAs).It is further expected that these services will be enhanced and matured so that customer value can be...

  • Senior Engineer

    3 weeks ago


    Midrand, Gauteng, South Africa IOCO Full time

    We are seeking a highly skilled Senior Engineer (SASE – L2) with deep expertise in Secure Access Service Edge (SASE), networking, and security solutions.  As a Senior Engineer (SASE – L2)  you'll be responsible for designing, deploying, managing, and optimizing SASE solutions for clients to ensure secure, scalable, and reliable connectivity for users,...

  • Senior Engineer

    1 week ago


    Midrand, Gauteng, South Africa IOCO Full time

    We are seeking a highly skilled Senior Engineer (SASE – L2) with deep expertise in Secure Access Service Edge (SASE), networking, and security solutions.  As a Senior Engineer (SASE – L2)  you'll be responsible for designing, deploying, managing, and optimizing SASE solutions for clients to ensure secure, scalable, and reliable connectivity for users,...


  • Midrand, Gauteng, South Africa Merafong ICT Full time

    Merafong ICT seeks an Information Security Analyst to join its team. As a critical member of the organization, you will play a key role in ensuring the security and integrity of our systems and data.Key Responsibilities:Conduct incident response and management activities to identify, contain, and remediate security incidents.Develop and maintain threat...