Cybersecurity Incident Management Specialist

7 months ago


Midrand, South Africa Nexio Full time

**ROLE PURPOSE**
As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Management Specialist is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Management Specialist is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and information systems. The Cybersecurity Incident Management Specialist role requires strong technical skills, deep knowledge of cybersecurity principles and technologies, and the ability to work in a fast-paced, high-pressure environment. The Cybersecurity Incident Management Specialist plays a crucial role in coordinating and providing technical support to resolve cyber defense incidents across the enterprise. The Cybersecurity Incident Management Specialist is responsible for analyzing incident data, identifying vulnerabilities, and recommending remediation actions. The Cybersecurity Incident Management Specialist performs log file analysis, triages incidents, conducts trend analysis, and handles real-time incident response tasks. The Cybersecurity Incident Management Specialist tracks and documents incidents, publishes reports and collaborates with Corporate Riks and intelligence analysts. Additionally, the Cybersecurity Incident Management Specialist stays updated on the latest cyber threats and coordinates incident response functions.

He/She should ideally have competency in security incident handling analysis experience in an established SOC environment and contribute to risk management.

**ROLE REQUIREMENT**
- Adheres to the standard operating procedure and playbooks in the SOC.
- Impacts on Customer satisfaction and confidence in the SOC Service and service level performance.
- Validate and declare security incidents based on incident handling methodologies.
- Confirm severity levels (S0 to S4) using SLA severity classification.
- Provide guidance and support to SOC Analysts during incident response.
- Determine the impact on critical systems or data sets and advise on remediation steps.
- Manage security events, incidents, and service requests via the ticketing systems.
- Incident Coordination and Support:

- Provide expert technical support to Analysts and Operational personnel to resolve incidents.
- Incident Analysis and Remediation:

- Correlate incident data to identify vulnerabilities and recommend remediation.
- Analyze log files from various sources to detect network security threats.
- Perform incident triage, determine scope and impact, identify vulnerabilities, and suggest remediation actions.
- Collect intrusion artifacts and leverage data for mitigating potential incidents.
- Incident Reporting and Communication:

- Perform trend analysis and report on cyber defense incidents.
- Track and document incidents from detection to resolution and closure.
- Write and publish incident findings, guidance, and reports for relevant stakeholders.
- Real-Time Incident Handling:

- Conduct real-time incident handling tasks, including forensic collections, threat analysis, and system remediation.
- Collect artifacts and inspect for possible mitigation on enterprise systems.
- Collaboration and Liaison:

- Serve as a technical expert and liaison to Incident Analysts and Operational personnel.
- Coordinate with intelligence analysts to correlate threat assessment data.
Additional Information:
- Good understanding of security incident analysis and incident handling practices, proficient knowledge of networking protocols, operating systems, and security architecture in an established SOC.
- Individuals at this level are competent in best practices in security incident handling in an established SOC.
- Able to build strong interpersonal relationships with the SOC team and customer stakeholders.
- Competent communication skills and communication of complex information to non-technical stakeholders.
- Competent in producing and presenting work.

**TECHNICAL / PROFESSIONAL COMPETENCIES**
- Adhere to operational processes in the NIST CSF, CIS CSC, NIST SP 800-53, and MITRE ATT&CK framework
- Prior experience to advise, plan, deploy, configure, manage, and monitoring large-scale and complex cyber defence and IT risk management and information or cybersecurity solutions.

**QUALIFICATIONS & EXPERIENCE**
- Grade 12
- One or more of these industry Cybersecurity Certifications: such as CISSP, GCIH, GCIA, or relevant vendor-specific certifications
- Minimum of four (4) years of work experience, and three (3) years of relevant experience in an established SOC and information security/cybersecurity
- Analytical, problem-solving, and critical-thinking skills.
- Strong knowledge of cybersecurity principles, incident response methodologies, and defense-in-depth practices.
- Proficiency in analyzing log files, conducting trend analysis, and correlating incident data.
- Experience with incident triage, vulnerability identification, and remediati



  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and provide...


  • Midrand, Gauteng, South Africa Datacentrix Full time

    About the RoleDatacentrix is seeking an experienced Cybersecurity Professional to provide initial investigation of all security incidents, management of incident from inception to resolution, and liaison with vendors and engineers to resolve incidents where required.


  • Midrand, Gauteng, South Africa Nexio Full time

    Job DescriptionWe are seeking a highly skilled Cybersecurity Threat Response Specialist to join our team at Nexio.About the RoleThis is a crucial position within our cybersecurity team, requiring strong technical skills and deep knowledge of cybersecurity principles and technologies. As a Cybersecurity Threat Response Specialist, you will play a vital role...


  • Midrand, Gauteng, South Africa Nexio Full time

    Job Summary:We are seeking a highly skilled Cybersecurity Threat Response Specialist to join our team at Nexio. This role plays a critical part in protecting our organization's network and information systems from cyber threats.Key Responsibilities:Develop and implement effective incident response plans to mitigate the impact of security breaches.Analyze...

  • Incident Manager

    6 months ago


    Midrand, South Africa Nexio Full time

    Nexio is a specialist ICT solution provider that helps clients build, support, and manage their IT infrastructures. We have operations in all 9 provinces across the country, over 200 clients and over 600 employees and as a Level 1 BBBEE we put to practice our commitment to South Africa’s transformation agenda, we are at the forefront of digital...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Threat Analyst will be responsible for monitoring enterprise networks and systems, deterring, identifying, investigating, and mitigating, any and all threats that are directed against those systems regardless of their classification level or type. The Cybersecurity Threat...

  • L1 Incident Analyst

    6 months ago


    Midrand, South Africa Liquid Tech (Pty) Ltd. Full time

    **Role Purpose** To deliver day-to-day managed security services (MSS), related to SOC deliverables. Critical in this regard is to execute according to Standard Operating Procedure (SOP) expectations and meeting all related service level agreements (SLAs). It is further expected that these services will be enhanced and matured so that customer value can be...

  • Cybersecurity Analyst

    7 months ago


    Midrand, South Africa Fidelity Services Group Full time

    **Job Title**: Cybersecurity Analyst **Location**: Ulwazi Campus Midrand/Helderkruin **Reports to**: Information Security Manager** **Job Summary**: We are seeking a skilled and dedicated Cybersecurity Analyst to join our Cybersecurity team in the physical security industry. As a Cybersecurity Analyst, you will play a crucial role in ensuring the security...

  • Cybersecurity Analyst

    2 months ago


    Midrand, Gauteng, South Africa Datacentrix Full time

    Datacentrix is seeking a skilled Cybersecurity Analyst to join their team. The ideal candidate will have expertise in installing, configuring, and maintaining Qradar SIEM and related products. Key responsibilities include providing initial investigation of all security incidents, managing incidents from inception to resolution, and liaising with vendors and...

  • Product Manager

    2 months ago


    Midrand, South Africa DataTech Recruitment Full time

    **Barracuda Product Manager - Driving Growth Through Distribution** This role is about leading the charge for Barracuda's cybersecurity products within a distribution network. You'll be the go-to expert for everything Barracuda, working closely with both internal teams and Barracuda themselves to achieve mutual success. You must have a minimum 5 years of...


  • Midrand, South Africa A 1L Realization (Pty) Ltd Full time

    Job Description As a Senior Specialist in Cyber Security, you will play a key role in safeguarding our organization's digital assets. Your expertise will be vital in ensuring the confidentiality, integrity, and availability of our information systems. This role requires a deep understanding of security operations, solutions, and architectural principles...


  • Midrand, South Africa Jobted ZA C2 Full time

    Job DescriptionAs a Senior Specialist in Cyber Security, you will play a key role in safeguarding our organization's digital assets. Your expertise will be vital in ensuring the confidentiality, integrity, and availability of our information systems. This role requires a deep understanding of security operations, solutions, and architectural principles...


  • Midrand, South Africa A 1L Realization (Pty) Ltd Full time

    Job Description As a Senior Specialist in Cyber Security, you will play a key role in safeguarding our organization's digital assets. Your expertise will be vital in ensuring the confidentiality, integrity, and availability of our information systems. This role requires a deep understanding of security operations, solutions, and architectural principles...


  • Midrand, South Africa A 1L Realization (Pty) Ltd Full time

    Job DescriptionAs a Senior Specialist in Cyber Security, you will play a key role in safeguarding our organization's digital assets. Your expertise will be vital in ensuring the confidentiality, integrity, and availability of our information systems. This role requires a deep understanding of security operations, solutions, and architectural principles...


  • Midrand, Gauteng, South Africa A 1L Realization (Pty) Ltd Full time

    Job OverviewA 1L Realization (Pty) Ltd seeks a seasoned Cybersecurity Risk Management Expert to safeguard our digital assets. This pivotal role demands expertise in security operations, solutions, and architectural principles within the cybersecurity domain.


  • Midrand, South Africa Liquid Tech (Pty) Ltd. Full time

    **Role Purpose** This role is responsible for overseeing and managing incidents that disrupt Technology services and to ensure incidents are resolved quickly, with the appropriate teams and resources engaged promptly and efficiently to minimise the impact on business operations. As an Incident Manager, you will be responsible for the end-to-end management...


  • Midrand, South Africa Liquid Tech (Pty) Ltd. Full time

    The role and responsibility consist of evaluating Microsoft and Cloud products, developing related new solutions and services, plan for the deployment of these solutions and services, implementation and configuration of these solutions and services, testing these solutions and services, establishing relevant documentation to be handed over to customers,...

  • Cyber Security Lead

    2 weeks ago


    Midrand, Gauteng, South Africa A 1L Realization (Pty) Ltd Full time

    Job OverviewA 1L Realization (Pty) Ltd is seeking a skilled Cyber Security Lead to join our team. In this role, you will be responsible for safeguarding our digital assets and ensuring the confidentiality, integrity, and availability of our information systems.Key ResponsibilitiesSafeguarding Digital Assets: Develop and implement effective security solutions...


  • Midrand, South Africa Datacentrix Full time

    Responsibilities : Understand ordering and tracking of parts Understand Engineer scheduling processes Knowledge and/or undertraining of parts shipping procedures and systems A key responsibility of this role is ensuring that an ongoing contribution toward positive customer satisfaction is achieved. A Service Desk Agent is responsible for the...