Specialist: Cybersecurity Incident Handling Analyst
3 weeks ago
**ROLE PURPOSE**
As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and information systems. The Cybersecurity Incident Manager role requires strong technical skills, deep knowledge of cybersecurity principles and technologies, and the ability to work in a fast-paced, high-pressure environment. The Cybersecurity Incident Manager plays a crucial role in coordinating and providing technical support to resolve cyber defense incidents across the enterprise. The Cybersecurity Incident Manager is responsible for analyzing incident data, identifying vulnerabilities, and recommending remediation actions. The Cybersecurity Incident Manager performs log file analysis, triages incidents, conducts trend analysis, and handles real-time incident response tasks. The Cybersecurity Incident Manager tracks and documents incidents, publishes reports and collaborates with Corporate Riks and intelligence analysts. Additionally, the Cybersecurity Incident Manager stays updated on the latest cyber threats and coordinates incident response functions
He/She should ideally have competency in security incident handling analysis experience in an established SOC environment and contribute to risk management.
**ROLE REQUIREMENT**
- Adheres to the standard operating procedure and playbooks in the SOC.
- Impacts on Customer satisfaction and confidence in the SOC Service and service level performance.
- Validate and declare security incidents based on incident handling methodologies.
- Confirm severity levels (S0 to S4) using SLA severity classification.
- Provide guidance and support to SOC Analysts during incident response.
- Determine the impact on critical systems or data sets and advise on remediation steps.
- Manage security events, incidents, and service requests via the ticketing systems.
- Incident Coordination and Support:
- Provide expert technical support to Analysts and Operational personnel to resolve incidents.
- Coordinate incident response activities and ensure timely resolution.
- Incident Analysis and Remediation:
- Correlate incident data to identify vulnerabilities and recommend remediation.
- Analyze log files from various sources to detect network security threats.
- Perform incident triage, determine scope and impact, identify vulnerabilities, and suggest remediation actions.
- Collect intrusion artifacts and leverage data for mitigating potential incidents.
- Incident Reporting and Communication:
- Perform trend analysis and report on cyber defense incidents.
- Track and document incidents from detection to resolution and closure.
- Write and publish incident findings, guidance, and reports for relevant stakeholders.
- Produce after-action reviews and facilitate lessons learned sessions.
- Real-Time Incident Handling:
- Conduct real-time incident handling tasks, including forensic collections, threat analysis, and system remediation.
- Collect artifacts and inspect for possible mitigation on enterprise systems.
- Collaboration and Liaison:
- Serve as a technical expert and liaison to Incident Analysts and Operational personnel.
- Coordinate with intelligence analysts to correlate threat assessment data.
- Monitor external data sources to stay updated on cyber defense threat conditions.
Additional Information:
- Individuals at this level are competent in best practices in security incident handling in an established SOC.
- Able to build strong interpersonal relationships with the SOC team and customer stakeholders.
- Competent communication skills and communication of complex information to non-technical stakeholders.
- Competent in producing and presenting work.
- Good understanding of security incident analysis and incident handling practices, proficient knowledge of networking protocols, operating systems, and security architecture in an established SOC.
**TECHNICAL / PROFESSIONAL COMPETENCIES**
- Adhere to operational processes in the NIST CSF, CIS CSC, NIST SP 800-53, and MITRE ATT&CK framework
- Prior experience to advise, plan, deploy, configure, manage, and monitoring large-scale and complex cyber defence and IT risk management and information or cybersecurity solutions.
**QUALIFICATIONS & EXPERIENCE**
- Grade 12
- One or more of these industry Cybersecurity Certifications: such as CISSP, GCIH, GCIA, or relevant vendor-specific certifications
- Minimum of four (4) years of work experience, and three (3) years of relevant experience in an established SOC and information security/cybersecurity
- Analytical, problem-solving, and critical-thinking skills.
- Strong knowledge of cybersecurity principles, incident response methodologies, and defense-in-depth practices.
- Proficiency in analyzing log files, conducting trend a
-
Specialist: Cybersecurity Incident Manager
7 days ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and...
-
Specialist: Cybersecurity Analyst
1 week ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and provide...
-
Senior Specialist: Cybersecurity Analyst
7 days ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Senior Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and...
-
L3 Security Incident Handling Analyst
1 day ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the L3 Security Incident Handling Analyst will identify, analyse and react to security incidents, events and threats using a reliable set of operating processes and SIEM technologies such as Azure Sentinel, or QRadar, or ArcSight. The SIEM Platform Lead will support the architecture, deployment,...
-
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Threat Analyst will be responsible for monitoring enterprise networks and systems, deterring, identifying, investigating, and mitigating, any and all threats that are directed against those systems regardless of their classification level or type. The Cybersecurity Threat...
-
Cybersecurity Analyst- Midrand
2 weeks ago
Midrand, South Africa Fidelity Services Group Full time**Job Title**:Cybersecurity Analyst** **Location**: Ulwazi Campus Midrand/Helderkruin **Reports to**: Information Security Manager** **Job Summary**: We are seeking a skilled and dedicated Cybersecurity Analyst to join our Cybersecurity team in the physical security industry. As a Cybersecurity Analyst, you will play a crucial role in ensuring the...
-
Cybersecurity Analyst
6 days ago
Midrand, South Africa Fidelity Services Group Full time**Job Title**: Cybersecurity Analyst **Location**: Ulwazi Campus Midrand/Helderkruin **Reports to**: Information Security Manager** **Job Summary**: We are seeking a skilled and dedicated Cybersecurity Analyst to join our Cybersecurity team in the physical security industry. As a Cybersecurity Analyst, you will play a crucial role in ensuring the security...
-
Cybersecurity Specialist
20 hours ago
Midrand, Gauteng, South Africa Merafong ICT Full timeAbout the RoleWe are seeking a highly skilled Cybersecurity Specialist to join our team at Merafong ICT. As a key member of our cybersecurity team, you will be responsible for identifying and analyzing sophisticated threats and vulnerabilities using advanced tools and techniques.Key Responsibilities:Advanced Threat Detection: Identify and analyze...
-
L2 Security Incident Manager
1 day ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the L2 Security Incident Manager will identify, analyse and react to security incidents, events and threats using a reliable set of operating processes and SIEM technologies such as Azure Sentinel, or QRadar, or ArcSight. The SIEM Platform Lead will support the architecture, deployment,...
-
Cybersecurity Specialist
3 days ago
Midrand, Gauteng, South Africa Careers at DLK Group Full timeMidrand, South Africa | Posted on 19/12/2024The Cybersecurity Specialist is responsible for safeguarding the organization's digital assets, networks, systems, and data. The role ensures robust security measures are in place to protect against threats, vulnerabilities, and unauthorized access while ensuring compliance with governance and regulatory...
-
Midrand, South Africa Nexio Full time**ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Senior Specialist: Cybersecurity Infrastructure Support will identify, analyze and react to security incidents, events, and threats using a reliable set of operating processes and SIEM technologies such as Azure Sentinel, or QRadar, or ArcSight. The Senior Specialist: Cybersecurity...
-
Specialist IT Cybersecurity
3 days ago
Midrand, South Africa Nexio Full time**ROLE PURPOSE** **PRIMARY DUTIES AND RESPONSBILITIES- JOB SPECIFIC REQUIREMENTS** Vulnerability Management**: - Oversee regular vulnerability assessments and penetration tests. - Identify, analyse, and prioritise vulnerabilities in the IT environment. - Develop and implement remediation plans to address identified vulnerabilities. **Patch...
-
Cybersecurity Expert
3 days ago
Midrand, Gauteng, South Africa Careers at DLK Group Full timeAt Careers at DLK Group, we are seeking a Cybersecurity Expert to safeguard our digital assets and protect against threats. The role ensures robust security measures are in place to shield our networks, systems, and data from unauthorized access while maintaining compliance with governance and regulatory frameworks.Key ResponsibilitiesNetwork Security:Design...
-
Information Security Specialist
3 days ago
Midrand, Gauteng, South Africa Careers at DLK Group Full timeCareers at DLK Group is seeking an Information Security Specialist to join our team. As an Information Security Specialist, you will be responsible for protecting our organization's digital assets and networks from threats and unauthorized access.Key ResponsibilitiesNetwork Security:Implement and maintain a robust security posture across our network...
-
Cyber Incident Response Manager
2 days ago
Midrand, South Africa Avatar Recruitment Full timeOur clients are a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax and related services. Our global network of member firms and related entities in more than 150 countries and territories serves four out of five Fortune Global 500 companies. The main purpose of the job is to support the engagement Senior...
-
Cyber Security Service Manager
2 weeks ago
Midrand, South Africa iOCO Full timeJOBNUMBER **iOCO03488** - CONTRACT TYPE **Permanent** - CONTRACT TYPE: **OnSite** **The Role**: We are seeking a results-driven S**ervice Manager**with a passion for delivering top-tier cybersecurity solutions that protect businesses from evolving threats. Skilled in service delivery, incident response, and stakeholder management, ensuring seamless...
-
Threat Intelligence Lead
20 hours ago
Midrand, Gauteng, South Africa Merafong ICT Full timeAbout the TeamOur team at Merafong ICT is made up of experienced professionals who are passionate about cybersecurity. We are dedicated to helping our clients protect their networks and systems from cyber threats. As a Threat Intelligence Lead with Merafong ICT, you will have the opportunity to work on a wide range of challenging projects and develop your...
-
Vulnerability Management Specialist
1 day ago
Midrand, South Africa Nexio Full time**ROLE PUROPOSE** As part of the Customer-facing Nexio Cyber Security team, the Vulnerability Management Specialist will be responsible for the vulnerability management governance, and vulnerability remediation oversight in a Customers’ environment. He/She should ideally have advanced Vulnerability Management Specialist experience in an established Cyber...
-
Senior Network Security Professional
20 hours ago
Midrand, Gauteng, South Africa Merafong ICT Full timeAbout Our CompanyMerafong ICT is a leading provider of cybersecurity solutions. We are committed to helping our clients protect their networks and systems from cyber threats. As a Senior Network Security Professional with Merafong ICT, you will have the opportunity to work on a wide range of challenging projects and develop your skills and expertise in the...
-
Service Manager
4 weeks ago
Midrand, Gauteng, South Africa IOCO Full timeWe are seeking a results-driven Service Manager with a passion for delivering top-tier cybersecurity solutions that protect businesses from evolving threats. Skilled in service delivery, incident response, and stakeholder management, ensuring seamless operations and compliance with industry standards. Adept at optimizing SOC, risk management, and cloud...