Security Analyst- Tier 2

1 week ago


Cape Town, South Africa Kocho Full time

About Kocho

We believe specialist UK firms deserve the same level of service they would give their own clients. We know that clients want expertise, a service they can rely on and intimate support from a named individual who knows their business.

Our relentless commitment to finding the best solution, our sense of pride in helping our clients achieve their goals and our thirst for understanding how technology improves business are what make us successful. With us it’s Personal We are seeking a highly capable 3rd Line Azure engineer, you will be responsible to remotely deliver senior 3rd line support and project services to multiple international customers, in line with contractual SLAs and KPIs.

Job Purpose

This position will assist the SecOps Tech Lead and Head of Security Operations in enhancing the SOC & SOAR operations
within Kocho. The Security Analyst will collaborate closely with other teams to build services and solutions that align with
security best practices and client assurance requirements. This includes, but is not limited to, the use of Microsoft
Sentinel, Microsoft Defender for Endpoint, Microsoft Defender for Cloud, and all other MS Security Stacks.

The primary responsibility of the Security Analyst role is to carry out operational SOC and SOAR activities as directed by
the SecOps Tech Lead and Head of Security Operations. This includes monitoring and responding to incidents and alerts
closing down incidents with comprehensive documentation. Furthermore, they will contribute to the efficient day-to-day
operations of the SOC, focusing on personnel, processes, and technology. With a solid foundation in IT Administration
and understanding of common corporate technologies, they will ensure all client SLAs are met, maintaining consistently
high client satisfaction scores.

You will be required to, work with members of the Security Operations Team to ensure all SOC & SOAR operational tasks
are completed on time and work tickets updated / closed with satisfactory technical details included, and where
appropriate escalate suspicious / malicious events to senior team members and Kocho or client incident response
personnel in order to identify, contain and remediate active threats. You will also be required to develop and update
operational documentation, as necessary.

Security Analysts will be comfortable engaging at both technical and non-technical levels, contributing as required in
technical workshops and client briefings / service reviews. You will be working in an incredibly passionate environment,
with great people in which you can actively contribute to develop and deliver our SOC & SOAR capability.

Key responsibilities of the role:
Strategy and Leadership:

- This is not a leadership role though you will be expected to mentor and support Junior Colleagues.

Technical Specialism:

- Advanced knowledge and experience with Microsoft Sentinel, Microsoft Defender for Endpoint, and Microsoft

Defender for Cloud familiarity with other Microsoft Security Stacks and a broad understanding of common
corporate technologies.
- Proficient in using KQL (Kusto Query Language) for threat hunting and other security-related investigations.
- Experience in IT administration, preferably within a Security Operations Center (SOC) environment.
- Experience in incident response and handling, including detailed incident reporting and documentation.
- Ability to analyze complex data and security logs to identify cyber security threats. Ability to communicate in

both technical and non-technical terms, tailoring approach to the audience.
- Self-motivated learner of technologies and methodologies to support best practice.
- Actively contributing to knowledge sharing across the business.

Security Operations:

- Act as an operational point of contact during significant cyber security events.
- Assist in the support of major incident handling within the SOC, and where applicable for clients.
- Provide support and guidance regarding monitoring activities.
- Provide “hands on” resource, working to ensure Kocho objectives and client SLA targets are achieved.
- Provide input and support for stakeholder communication.
- Assist and support the implementation of security controls, threat protection etc. for both Kocho and it’s clients.
- Support other Security Analysts and clients on rules/policies/filters/use cases and SOC tooling.
- Assist with the implementation of improvements as part of on-going service enhancement or “lessons learned”

following incident investigation (cause and affect).
- Assist in the review of incident closures, post incident reports and act upon improvements identified.
- Undertake Threat Hunting, to include the development of queries to support improvements to the

identification of undetected threats on client estates.
- Contribute to team development through knowledge sharing, briefing and production of guides, incident

scenarios and playbooks.
- Show flexibility in developing knowledge of


  • SOC Analyst Tier 2

    7 days ago


    Cape Town, Western Cape, South Africa Boardroom Appointments Full time R250 000 - R500 000 per year

    SOC Analyst Tier 2 - Contract PositionResponsibilitiesProvide technical escalation point for Tier 1 Analysts on security incidents, alerts, and inquiries requiring input on security risk, privacy, or threats.Be available to assist Tier 1 Analysts with critical incidents and serve as a reference for alerts and inquiries.Perform analysis of log files.Conduct...


  • Cape Town, South Africa Zappi Full time

    A leading consumer insights platform in Cape Town is seeking an IT Security (SOC) Analyst (Tier 2) to join their Security Operations team. This role involves investigating security incidents, leading threat hunts, and optimizing security tools. Candidates should have a minimum of 2 years in a SOC environment and be skilled in log analysis and scripting. The...


  • Cape Town, South Africa Netsurit Full time

    Tier 2 Technical Support Engineer Location: Cape Town (Bellville) Model: Fully Onsite Job Description Netsurit's mission is to Support the dreams of the doers. For Netsurit, this means helping employees achieve their personal dreams and ambitions while they free up our customers to meet their broader business goals by taking the burden of day-to-day IT...


  • Cape Town, Western Cape, South Africa BOSS ERP Consulting Full time R60 000 - R120 000 per year

    Cybersecurity AnalystWe are seeking a Cybersecurity Analyst to support the Group Cyber Security Manager with operational security support utilising your knowledge of threats and vulnerabilities using the Microsoft Defender security suite.As a Cybersecurity Analyst we are seeking the following skills and experience:2+ years' experience in a security analyst...


  • Cape Town, South Africa Boardroom Appointments Full time

    **Key purpose**: The role will require the Information Security Analyst to work closely with clients displaying good client engagement skills with a high level of professionalism. **Duties and responsibilities**: - Complies to all mandated policies, laws and audit requirements - Managed environment is safe and secure Security patch management -...


  • Cape Town, Western Cape, South Africa Communicate Ct Full time R50 000 - R80 000 per year

    Our client is looking for a curious, energetic, and sharp-minded Cyber Security Analyst who will be part of an international team.  If you live for uncovering anomalies, chasing down threats and have a passionate about cybersecurity, then we would like to hear from you.Threat detection & monitoring: Analyse logs, hunt for threats, and keep adversaries at...


  • Cape Town, South Africa Technolutions PTY LTD Full time

    As a Tier 3 Support Engineer at Technolutions, you’ll be the go‑to escalation point for complex issues across our managed networking, cloud hosting, firewalls, and Microsoft 365 environments. You’ll design, implement, and troubleshoot advanced solutions for our SME customers, working with technologies such as Microsoft 365, Azure, virtual servers,...


  • Cape Town, South Africa Technolutions Pty Ltd Full time

    As a Tier 3 Support Engineer at Technolutions, you'll be the go-to escalation point for complex issues across our managed networking, cloud hosting, firewalls, and Microsoft environments. You’ll design, implement, and troubleshoot advanced solutions for our SME customers, working with technologies such as Microsoft, Azure, virtual servers, next-gen...


  • Cape Town, Western Cape, South Africa Lexdan Select Full time

    Lexdan Select is assisting a financial services company in their search for an Information Security Analyst, based in Cape Town city.This is a hybrid role, with 2 days in-office.Salary: R to R p.a.Duties and responsibilities:Threat and Vulnerability Monitoring: Continuously monitor our environment to detect potential threats and vulnerabilities, ensuring...

  • Security Analyst I

    2 weeks ago


    Cape Town, Western Cape, South Africa Boardroom Appointments Full time R250 000 - R500 000 per year

    Minimum Requirements:Diploma / Degree in computer science, cybersecurity, or any related field.Recognised industry certifications in cybersecurity such as PCI Professional (PCIP), Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM).+2 years of experience in cybersecurity, with solid experience across...