L3 Security Incident Handling Analyst

3 weeks ago


Midrand, South Africa Nexio Full time

**ROLE PURPOSE**
As part of the Customer-facing Nexio SOC team, the L3 Security Incident Handling Analyst will be responsible for monitoring enterprise networks and systems, detecting events and reporting on any and all threats that are directed against those systems regardless of their classification level or type. The L3 Security Incident Handling Analyst is expected to collaborate with leadership to develop metrics based on situational awareness and threat monitoring at an enterprise level that will be reported based on the approved plan and supporting checklists. The L3 Security Incident Handling Analyst must be able to rapidly address security incidents alerted primarily by an industry recognised Security Information and Events Management [SIEM].

He/She should ideally have advanced security incident handling analysis experience in an established SOC environment where ArcSight, or Azure Sentinel, or QRadar was the SIEM platform.

**ROLE REQUIREMENTS**
- Is familiar with the tactical and long-term vision across the Cyber Security function.
- Team lead on Security Incident Analysis and Handling within the SOC function.
- Adheres to the standard operating procedure and playbooks in the SOC.
- Direct impact on the SOC performance.
- Impacts on team’s runbooks and operational processes in the SOC Service.
- Provides security incident handling and technical guidance to SOC Teams.
- Gives regular, comprehensive and constructive feedback, and coaching and mentoring to team.
- Delegates work to team members taking into account their capacity, level of skill and exposure to different types of work and complexity; provides clear instructions and direction, with reasonable deadlines.
- Provides support for complex computer network exploitation and defence techniques to include deterring, identifying and investigating computer and network intrusions
- Provides incident response and remediation support; performing comprehensive computer surveillance/monitoring, identifying vulnerabilities; developing secure network designs and protection strategies, and audits of information security infrastructure.
- Provides technical support for continuous monitoring, computer exploitation and reconnaissance; target mapping and profiling; and, network decoy and deception operations in support of computer intrusion defence operations.
- Provides technical support for forensics services to include evidence seizure, computer forensic analysis and data recovery, in support of computer crime investigation.
- Researches and maintains proficiency in open and closed source computer exploitation tools, attack techniques, procedures and trends. Performs research into emerging threat sources and develops threat profiles.
- Provides technical support for a comprehensive risk management program identifying mission critical processes and systems; current and projected threats; and system vulnerabilities.
- Lead Red Team / Blue Team exercises and identify gaps in current monitoring tools and processes.
- Develops playbooks for various incident scenarios and have a knowledge of automation processes and products.
- Mentors Junior Analysts to become more effective in their roles.
- Application of security settings and other commercial best practices such as SIEM Analysis operations.
- Incident analysis from ingested source systems combined with threat intelligence feeds into the SIEM from open source and commercial feeds.

Additional Information:

- Individuals at this level have fully developed knowledge of best practices in security incident handling in an established SOC.
- Able to build strong interpersonal relationships with the SOC team and customer stakeholders.
- Excellent verbal and written communication skills.
- Able to align multiple strategies and ideas.
- Confident in producing and presenting work.
- In-depth understanding of best security incident analysis and incident handling practices in an established SOC.

**QUALIFICATIONS & EXPERIENCE**
- Grade 12
- Bachelor’s Degree in Computer Science or a related technical discipline, or the equivalent combination of education, technical certifications
- One or more these industry Cybersecurity Certifications: CISSP-ISSEP, CISSP-ISSAP, GIAC Certified Incident Handler (GCIH), Certified Computer Security Incident Handler (CSIH), CEH, OSCP, CompTiA
- Minimum of five (5) years of work experience, and two (2) years of relevant experience in and established SOC and information security/cybersecurity
- Experience with defining SOC playbooks.
- Experience with a ticketing system such as BMC Remedy.
- Basic Linux and Windows Server experience.
- Experience working with virtual environments.
- Strong analytical and organizational skills.
- Concise writing skills, excellent MS Word skills as well as other MS Office Applications.
- Experience with securing various environments preferred.
- Experience in working across security frameworks.
- Experience in working across security technologies.
- Poss



  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the L2 Security Incident Manager will identify, analyse and react to security incidents, events and threats using a reliable set of operating processes and SIEM technologies such as Azure Sentinel, or QRadar, or ArcSight. The L2 Security Incident Manager will be responsible for monitoring...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Management Specialist is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Management Specialist is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the...

  • L1 Incident Analyst

    7 months ago


    Midrand, South Africa Liquid Tech (Pty) Ltd. Full time

    **Role Purpose** To deliver day-to-day managed security services (MSS), related to SOC deliverables. Critical in this regard is to execute according to Standard Operating Procedure (SOP) expectations and meeting all related service level agreements (SLAs). It is further expected that these services will be enhanced and matured so that customer value can be...

  • Security Data Analyst

    2 weeks ago


    Midrand, South Africa Handpicked Recruitment Full time

    **Description** **Minimum requirements**: - Matric plus Diploma/Degree in Information Security - MS Security Certification - Experience as a data analyst/threat hunting analyst - 1-2 years’ experience working in a SOC - Night shift hours - 18:00 - 06:00 - Must have own transport **Duties will include but are not limited to**: - Providing supporting...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and provide...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Threat Analyst will be responsible for monitoring enterprise networks and systems, deterring, identifying, investigating, and mitigating, any and all threats that are directed against those systems regardless of their classification level or type. The Cybersecurity Threat...

  • Incident Manager

    7 months ago


    Midrand, South Africa Nexio Full time

    Nexio is a specialist ICT solution provider that helps clients build, support, and manage their IT infrastructures. We have operations in all 9 provinces across the country, over 200 clients and over 600 employees and as a Level 1 BBBEE we put to practice our commitment to South Africa’s transformation agenda, we are at the forefront of digital...

  • Cybersecurity Analyst

    7 months ago


    Midrand, South Africa Fidelity Services Group Full time

    **Job Title**: Cybersecurity Analyst **Location**: Ulwazi Campus Midrand/Helderkruin **Reports to**: Information Security Manager** **Job Summary**: We are seeking a skilled and dedicated Cybersecurity Analyst to join our Cybersecurity team in the physical security industry. As a Cybersecurity Analyst, you will play a crucial role in ensuring the security...


  • Midrand, South Africa Skye Business Solutions Full time

    We are a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax and related services. Our global network of member firms and related entities in more than 150 countries and territories, serves four out of five Fortune Global 500® companies. **About the Division** In a world that is constantly changing,...


  • Midrand, South Africa Network Contracting Full time

    **Outputs**: **Consultancy services** - Document solutions - Liaise with Development teams on proposed solutions. **Technical Analyst** - Understanding the business requirements, and through a structured process documenting, validating, and translating it into functional specifications that are used by developers to craft a technical solution. - Create...


  • Midrand, South Africa Skye Business Solutions Full time

    Our clients are a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax and related services. Our global network of member firms and related entities in more than 150 countries and territories serves four out of five Fortune Global 500 companies. The main purpose of the job is to support the engagement Senior...

  • Security Supervisor

    4 months ago


    Midrand, South Africa DBSA Full time

    The Security Supervisor is responsible for assessing security risks and threats to the organisation and implementing operational methods and processes that mitigate physical security services; i.e. guarding, patrolling, regulating all access and egress, concierge service to the DBSA and the provision of VIP protection services as and when required. The...


  • Midrand, South Africa WSP Africa Full time

    **Company Description** We are WSP - Join us and make your career future ready! Think bigger scale. Think higher profile. Think ground-breaking. Join WSP, and you’ll be at the heart of a team of international experts all dedicated to growing and sharing their expertise, and working on projects that transform society for all of us. WSP is one of the most...


  • Midrand, South Africa SRIVEN IT SOLUTIONS Full time

    **Role Description and Responsibilities**: One of the largest internationally renowned Accounting and Auditing firm is **urgently** looking for **Workday Configuration Support Analyst (Senior Associate) - HCM & Compensation **to join the HR Systems Practice in Operate Digital. The Operate Digital HR Systems Practice are a team of People Technology...


  • Midrand, South Africa Data Centrix Full time

    **Key Skills/Competencies**: - Matric & ITIL Foundation - Qualifications pertaining to the customer service industry - Must be able to use Microsoft Office - Proficient data entry skills - Proficient in English - 2+ years experience in a service desk role - Ability to effectively handle multiple tasks in a fast-paced environment - Demonstrated verbal...


  • Midrand, South Africa Vodafone Full time

    **Role purpose**: Cyber Defence is one of MPA’s critical Cyber Security teams. The Cyber Defence team’s mission is to deliver a highly effective end-to-end 24x7 Cyber Defence service. They are responsible for proactively identifying threats and vulnerabilities; detecting and mitigating cyber events, and managing cyber security incident responses to...


  • Midrand, South Africa Siemens Full time

    **Job Title / Role: Security Professional** **Organization: Lead Country South Africa** **Location: Midrand, South Africa** **Reporting Manager: Security Manager** The Business Siemens is a global powerhouse in diversified engineering providing products, systems and solutions across the Electrification, Automation and Digitalization value chain. The...

  • Security Officer

    7 months ago


    Midrand, South Africa Maanda Nes Investments Full time

    **Job Title: Security Guard** **_05_** **_Februa_** **_ry_** **_2_** **_023_** **JOB SPECIFICATION** **Responsibilities**: - Conduct regular foot patrols of the office premises both indoors and outdoors - Monitor security systems, including CCTV cameras, alarm systems, and access control points - Respond to alarms, incidents, and emergencies promptly and...


  • Midrand, South Africa RJPersonnel Full time

    2years - Configure and support Symantec Endpoint Protection antivirus. - Knowledge of firewall rules and should be involved in the review of the firewall policies. - Identify threats and working on steps to defend against them. - General or basic knowledge of vulnerability assessments and penetration tests. - Security awareness/procedures. - Participate in...