Cyber Threat Hunt Analyst

1 week ago


Cape Town, South Africa Surgo HR & Training Full time

Surgo (PTY) Ltd. has partnered with a global analytics and digital solutions company serving industries including insurance, healthcare, banking and financial services, media, retail, and others. They aim to bridge the gap between digital expectations and real outcomes for international companies with Digital Intelligence.

Our client is recruiting for a Cyber Threat Hunt Analyst to join their team based in Cape Town.

**Job purpose**:
The role will support and advise on product assessments, policy adjustments, and architectural transformation that will impact regional and global locations. The position requires someone with technical expertise and will provide influence on the design of detective, preventive, and proactive controls.

**Responsibilities**:
Identify and track threat actor groups and their TTPs while maintaining current knowledge of tools and best practices of APT groups

Perform cyber threat hunting activity using threat intelligence, analysis of anomalous log data, and related tools

Collect, enrich, and disseminate IOCs - Indicators of Compromise

Use the MITRE ATT&CK framework to analyze malicious campaigns and evaluate the effectiveness of security technologies and controls

Determine true threats, false positives, and network system misconfigurations and provide recommendations and solutions to issues detected

Monitor the organization’s attack surface against the current threat landscape

Support the Cyber Threat Intelligence team to provide threat informed defenses that will improve prioritization of preventative controls and mitigations to improve defense posture

Engage and collaborate with Red Team to analyze and evaluate the effectiveness of existing security controls

Support Cyber Threat DFIR for internal incidents by performing cyber threat hunting activities during investigations and building a common understanding of threat activities

**Qualification & Experience**:
Direct experience performing threat hunting in an active corporate environment

2+ years of experience in a technical role in the areas of Security Operation, Incident Response, Detection Engineering, Offensive Security/Red Team, or Cyber Threat Intelligence

Security certification or working towards certification (e.g., SANS, SEC+, CompTIA, Security+, OSCP, or CEH), equivalent experience will be considered

Direct experience working with large datasets, log review and bulk analysis tools

Experience consuming and analyzing Cyber Threat Intelligence for actionable takeaways

Familiarity with offensive security strategies and assessment methodologies

Knowledge of threat actors, including malware families, intrusion techniques, and associated criminal entities

Experience explaining threat hunt objectives and ability to communicate associated risks

Ability to understand requirements and needs from across the organization in order to build consensus and drive results

Ability to navigate and work effectively across a complex, geographically dispersed organization

Able to perform proactive threat hunting using multiple toolsets, suggesting, and testing hypotheses, pivoting and reporting on investigation results

Ability to work on-side

**Beneficial**:
Experience with more than one more enterprise scale EDR and SIEM tool

Experience using Internet and network scanning tools for malicious host discovery

Basic understanding of building threat hunting queries using KQL, SIGMA, or Yara

Previous experience using a Threat Intelligence platform or CTI vendor

Demonstrated ability to self-direct, with mínimal supervision to achieve assigned goals

Knowledge of basic Data Science concepts and processes

Experience with offensive security tools and technical and the methods used to compromise large networks

Previous experience performing digital forensics or incident response on major security incidents

**Salary**: Market Related

**Working Hours**: Monday to Friday - 08:00am to 17:00pm



  • Cape Town, South Africa Surgo Full time

    Surgo (PTY) Ltd. has partnered with a global analytics and digital solutions company serving industries including insurance, healthcare, banking and financial services, media, retail, and others. They aim to bridge the gap between digital expectations and real outcomes for international companies with Digital Intelligence. Our client is recruiting for...


  • Cape Town, Western Cape, South Africa Parvana Full time R900 000 - R1 200 000 per year

    About our client:Our international client has redefined the approach to addressing client security needs by reshaping support strategies, tapping into existing client technologies, optimising or complementing their current resources, all while aligning seamlessly with their financial parameters. Through the integration of cutting-edge technologies such as...


  • Cape Town, South Africa Parvana Full time

    Senior Cyber Security Analyst 2 days ago Be among the first 25 applicants About our client Our international client has redefined the approach to addressing client security needs by reshaping support strategies, tapping into existing client technologies, optimising or complementing their current resources, all while aligning seamlessly with financial...


  • Cape Town, South Africa Old Mutual Full time

    A leading financial services provider in Cape Town seeks a Senior Cyber Analyst to enhance its Cyber Defence team. The candidate will be responsible for threat detection and incident response in a digital banking environment, collaborating with internal teams and external partners. The role requires 5+ years in cybersecurity, strong AWS and Azure knowledge,...


  • Cape Town, South Africa Old Mutual Full time

    A leading financial services group in Cape Town is seeking a Cyber Analyst to join their cyber defence team. This role involves monitoring security threats, collaborating with partners, and improving incident response strategies. Candidates should have a degree in Cybersecurity, 3+ years of cybersecurity experience, and familiarity with cloud-based security...


  • Cape Town, South Africa Zappi Full time

    A leading consumer insights platform in Cape Town is seeking an IT Security (SOC) Analyst (Tier 2) to join their Security Operations team. This role involves investigating security incidents, leading threat hunts, and optimizing security tools. Candidates should have a minimum of 2 years in a SOC environment and be skilled in log analysis and scripting. The...


  • Cape Town, South Africa Old Mutual Full time

    A leading financial services provider in Cape Town seeks a Senior Cyber Analyst to enhance its Cyber Defence team. The candidate will be responsible for threat detection and incident response in a digital banking environment, collaborating with internal teams and external partners. The role requires 5+ years in cybersecurity, strong AWS and Azure knowledge,...


  • Cape Town, South Africa Integrity360 Full time

    Title: _Senior Cyber Incident Response Analyst - Location: _Cape Town or Johannesburg, South Africa - Salary: _Negotiable / DOE **About Us** Integrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12...


  • Cape Town, South Africa Integrity360 Full time

    Company Integrity360 – the largest independent cyber‑security provider in Europe with over 700 employees, 12 locations and six Security Operations Centres (SOCs) – including Dublin, Sofia, Stockholm, Madrid, Naples and Cape Town. Location Cape Town, Western Cape, South Africa Job Title Senior Cyber Incident Response Analyst About Us Integrity360’s...


  • Cape Town, South Africa BASHR Consulting Full time

    As a Cybersecurity Analyst you will be required for analysing and reporting on network traffic, implementing solutions that provide IT security, and coordinating various teams within the company. You will be responsible for monitoring and evaluating threats that could potentially breach the network. **Requirements**: - Tertiary Qualification - AWS:...