Cybersecurity Analyst

2 weeks ago


Johannesburg, Gauteng, South Africa Logicalis Group Full time
About Logicalis Group

Logicalis Group is an international solution provider delivering digital enablement services to help customers harness technology and innovative services to achieve business outcomes.

We have 4,500 employees who engage with customers across various industries and geographical regions. Our focus is on customer vertical markets, including financial services, telecommunications, media, and technology, education, healthcare, retail, government, manufacturing, and professional services.

We partner with leading technology companies such as Cisco, HPE, IBM, CA Technologies, NetApp, Microsoft, Oracle, VMware, and ServiceNow to provide our customers with the best possible solutions.

Job Description: Threat Intelligence Specialist

The Security Operations Centre will defend against security breaches and actively isolate and mitigate security risks. The Threat Intelligence Specialist forms part of the SOC team responsible for identifying, analysing, and reacting to cyber threats using reliable processes and security technologies.

The SOC team includes the SOC Manager, SIEM Platform Manager, Case Manager, Tier 1, 2, and 3 Analysts, and Security Specialists. They work closely with IT operational teams to address security incidents and events quickly.

This role involves:

  • Possessing in-depth knowledge of network, endpoint, threat intelligence, forensics, and malware reverse analysis, as well as specific applications or underlying infrastructure.
  • Acting as an incident 'hunter', not waiting for escalated incidents.
  • Closely involved in developing, tuning, and implementing threat detection analytics.
  • Escalating for Tier 1 and 2 SOC Analysts.
  • Responding to and overseeing remediation of declared security incidents.
  • Completing Root Cause Analysis Reports for P1-P4.
  • Providing guidance to Tier 1 and 2 SOC Analysts.
  • Using threat intelligence such as updated rules and Indicators of Compromise (IOCs) to pinpoint affected systems and attack extent.
  • Monitoring shift-related metrics ensuring applicable reporting is gathered and disseminated to the SOC Manager.
  • Making recommendations to the SOC Manager.
  • Overseeing analysis on running processes and configs on affected systems.
  • Undertaking in-depth threat intelligence analysis to find perpetrators, attack types, and impacted data or systems.
  • Overseeing containment and recovery.
  • Deep-dive incident analysis by correlating data from various sources.
  • Validating if critical systems or data sets are impacted.
  • Providing support for analytic methods for detecting threats.
  • Conducting advanced triage based on defined run books of alerts.
  • Undertaking threat intelligence research if necessary.
  • Validating false positives, policy violations, intrusion attempts, security threats, and potential compromises.
  • Undertaking security incident triage to provide necessary context prior to escalating to relevant specialists to perform deeper analysis when necessary.
  • Further analysing alarms by method e.g., credentials compromised and asset class.
  • Based on correlation rules and alarms within the SIEM and run books, further analysing anomaly tactics using the MITRE ATT&CK framework.
  • Analysing event and process metadata in real-time or retrospectively and identifying suspicious files/scripts seen for the first time.
  • Closing tickets in the SIEM platform – this would be automatically created into Service Now.
  • Managing security incidents using the SIEM platform and defined operational procedures.
  • Performing a further investigation of potential incidents and escalating or closing events as applicable.
  • Validating investigation results ensuring relevant details are passed on to Tier 2 SOC Level 2 for further event analysis.
  • Closing out deeper analysis and review activities.
  • Assisting senior SOC staff with operational responsibilities.


  • Johannesburg, Gauteng, South Africa African Ambition Full time

    Cybersecurity AnalystLocation: JHBBasic: R850 000 PAWe are looking for a Cybersecurity Analyst to join our team to protect our organization from cyberattacks by monitoring our systems and evaluating threats as they arise.Responsibilities Document security breaches and assess the damage they cause Work with the security team to perform tests and uncover...

  • Cybersecurity Analyst

    2 weeks ago


    Johannesburg, Gauteng, South Africa Fidelity Services Group Full time

    Job title : Cybersecurity Analyst - ICT Midrand / HelderkruinJob Location : Gauteng, JohannesburgDeadline : April 27, 2025Quick Recommended LinksJobs by Location Job by industries Job Summary: We are seeking a skilled and dedicated Cybersecurity Analyst to join our Cybersecurity team in the physical security industry. As a Cybersecurity Analyst, you will...

  • Cybersecurity Analyst

    3 weeks ago


    Johannesburg, Gauteng, South Africa African Ambition Full time

    We are looking for a Cybersecurity Analyst to join our team to protect our organization from cyberattacks by monitoring our systems and evaluating threats as they arise.ResponsibilitiesDocument security breaches and assess the damage they causeWork with the security team to perform tests and uncover network vulnerabilitiesFix detected vulnerabilities to...

  • Cybersecurity Analyst

    3 weeks ago


    Johannesburg, Gauteng, South Africa Fidelity Services Group Full time

    Job title : Cybersecurity Analyst - Midrand / HeldekruinJob Location : Gauteng, JohannesburgDeadline : April 11, 2025Quick Recommended LinksJobs by Location Job by industries Key Responsibilities: Monitor and analyze security events to identify potential threats and vulnerabilities.  Conduct regular vulnerability assessments to identify weaknesses in...


  • Johannesburg, Gauteng, South Africa Prima Secure Full time

    We are looking for a proactive and detail-oriented Junior Cybersecurity Analyst with at least 1 year of hands-on experience in cybersecurity or IT security support.The ideal candidate will assist in monitoring, analyzing, and responding to cybersecurity threats while gaining exposure to a wide range of tools and technologies in a collaborative...


  • Johannesburg, Gauteng, South Africa Prima Secure Full time

    We are looking for a proactive and detail-oriented Junior Cybersecurity Analyst with at least 1 year of hands-on experience in cybersecurity or IT security support. The ideal candidate will assist in monitoring, analyzing, and responding to cybersecurity threats while gaining exposure to a wide range of tools and technologies in a collaborative environment....

  • Cybersecurity Analyst

    4 hours ago


    Johannesburg, Gauteng, South Africa Feeblo Full time

    We are seeking a highly skilled Cybersecurity Analyst to protect our organization's digital assets from evolving threats. The ideal candidate will monitor, detect, and respond to security incidents while implementing robust defense strategies. You will play a critical role in safeguarding sensitive data, ensuring compliance, and mitigating risks across our...


  • Johannesburg, Gauteng, South Africa African Ambition Full time

    Job OverviewAfrican Ambition is seeking a highly skilled Cybersecurity Analyst to join our team and contribute to the protection of our organization from cyber threats.


  • Johannesburg, Gauteng, South Africa Prima Secure Full time

    Cybersecurity Analyst Trainee Wanted: Prima Secure seeks a junior cybersecurity analyst to assist in monitoring, analyzing, and responding to cybersecurity threats. This entry-level position offers mentorship and learning opportunities with experienced cybersecurity professionals.About the PositionYou will assist in monitoring security alerts and events...


  • Johannesburg, Gauteng, South Africa Data Centrix Full time

    At Data Centrix, we are seeking a highly skilled Cybersecurity Operations Lead to join our team. This is an exciting opportunity for a seasoned professional to lead a team of security analysts and incident responders in providing direction and mentorship.The ideal candidate will have a strong background in cybersecurity with at least 3 years of experience in...


  • Johannesburg, Gauteng, South Africa Prima Secure Full time

    We are looking for a proactive and detail-oriented Junior Cybersecurity Analyst to assist in monitoring, analyzing, and responding to cybersecurity threats. The ideal candidate will gain exposure to a wide range of tools and technologies in a collaborative environment.Job DescriptionThis role is perfect for someone who is eager to grow and make a real impact...


  • Johannesburg, Gauteng, South Africa Prima Secure Full time

    We are seeking a highly motivated and detail-oriented Junior Cybersecurity Analyst to join our team at Prima Secure. In this role, you will assist in monitoring, analyzing, and responding to cybersecurity threats while gaining exposure to a wide range of tools and technologies.Key ResponsibilitiesMonitor security alerts and events using SIEM and other...


  • Johannesburg, Gauteng, South Africa Datacentrix Full time

    At Datacentrix, we are seeking a highly skilled Cybersecurity Operations Lead to oversee the day-to-day operations and strategy of our Security Operations Center (SOC). This role is responsible for ensuring timely detection, investigation, and response to security incidents across IT and OT environments.Key Responsibilities:Lead a team of security analysts...


  • Johannesburg, Gauteng, South Africa Prima Secure Full time

    We are seeking a highly motivated and detail-oriented Junior Cybersecurity Analyst to join our team at Prima Secure. As an entry-level cybersecurity professional, you will play a key role in monitoring, analyzing, and responding to cybersecurity threats while gaining exposure to a wide range of tools and technologies in a collaborative environment.About the...


  • Johannesburg, Gauteng, South Africa ICT Engage Full time

    About ICT EngageICT Engage is a leading provider of IT services, dedicated to delivering innovative solutions that meet the ever-evolving needs of businesses.Job Description :We are seeking a highly motivated and skilled individual to fill the role of Technical Support and Security Analyst. As a key member of our team, you will be responsible for providing...


  • Johannesburg, Gauteng, South Africa Feeblo Full time

    We are seeking a highly skilled Cybersecurity Analyst to protect our organization's digital assets from evolving threats. The ideal candidate will monitor, detect, and respond to security incidents while implementing robust defense strategies.Key ResponsibilitiesInvestigate and respond to security incidents (malware, phishing, DDoS, insider threats)Conduct...


  • Johannesburg, Gauteng, South Africa The South African Breweries Full time

    Job title : Cybersecurity Operations ManagerJob Location : Gauteng, JohannesburgDeadline : April 13, 2025Quick Recommended LinksJobs by Location Job by industries Key Roles and Responsibilities: Operational Oversight Manage 24/7 cybersecurity operations, including threat detection, incident response, and vulnerability management. Our globally centralized...


  • Johannesburg, Gauteng, South Africa Deka Minas Pty Ltd Full time

    Deka Minas Pty Ltd is seeking an Enterprise Security Specialist to join our team. As a key member of our cybersecurity team, you will play a vital role in protecting our organization's assets from cyber threats.The ideal candidate will have expertise in vulnerability assessment and management, cloud security, and Continuous Threat Exposure Management (CTEM)....


  • Johannesburg, Gauteng, South Africa Prima Secure Full time

    Cybersecurity is an essential part of any organization's infrastructure, and we are seeking a skilled Junior Cybersecurity Analyst to join our team at Prima Secure. As a Junior Cybersecurity Analyst, you will play a critical role in monitoring, analyzing, and responding to cybersecurity threats.ResponsibilitiesMonitor security alerts and events using SIEM...


  • Johannesburg, Gauteng, South Africa SSR G&M Ltd Full time

    About the Role:We are looking for a highly skilled Cybersecurity Investigator to join our team at SSR G&M Ltd. As a key member of our security department, you will be responsible for analyzing various data sources to identify potential risk indicators and supporting investigators in their research.The ideal candidate will have experience in insider threat...