L2 Security Incident Manager

4 days ago


Midrand, South Africa Nexio Full time

**ROLE PURPOSE**

As part of the Customer-facing Nexio SOC team, the L2 Security Incident Manager will identify, analyse and react to security incidents, events and threats using a reliable set of operating processes and SIEM technologies such as Azure Sentinel, or QRadar, or ArcSight.

The L2 Security Incident Manager will be responsible for monitoring enterprise networks and systems, detecting events and reporting on all threats that are directed against those systems regardless of their classification level or type. The L2 Security Incident Manageris is expected to collaborate with leadership to develop metrics based on situational awareness and threat monitoring at an enterprise level that will be reported based on the approved plan and supporting checklists. The L2 Security Incident Manager must be able to rapidly address security incidents alerted primarily by an industry recognised Security Information and Events Management [SIEM].

He/She should ideally have advanced security incident handling analysis experience in an established SOC environment where ArcSight, or Azure Sentinel, or QRadar was the SIEM platform.

**ROLE REQUIREMENT**
- Is familiar with the tactical and long-term vision across the Cyber Security function.
- Team lead on Security Incident Analysis and Handling within the SOC function.
- Adheres to the standard operating procedure and playbooks in the SOC.
- Direct impact on the SOC performance.
- Being the point of contact to drive all cyber incidents managed by the Nexio Cyber Defense Team
- Creates incident reports
- Tracks cases
- Keeps cases and incidents status up to date through regular updates
- Participates in the incident management process from investigation to resolution
- Maintain daily communication with the SOC Analyst team
- Tracks tickets, severity, and assists to drive incidents to a conclusion based on SLAs and criticality level
- Coordinate the activities of analysts and parties external to the Cyber Defense Team involved incident response
- Prepares weekly incident status report

Additional Information:

- Individuals at this level have fully developed knowledge of best practices in security incident management in an established SOC.
- Able to build strong interpersonal relationships with the SOC team and customer stakeholders.
- Excellent verbal and written communication skills.
- Able to align multiple strategies and ideas.
- Confident in producing and presenting work.
- In-depth understanding of best security incident management practices in an established SOC.

**QUALIFICATIONS & EXPERIENCE**
- Grade 12
- Bachelor’s Degree in Computer Science or a related technical discipline, or the equivalent combination of education, technical certifications
- One or more these industry Cybersecurity Certifications: CISSP-ISSEP, CISSP-ISSAP, GIAC Certified Incident Handler (GCIH), Certified Computer Security Incident Handler (CSIH), CEH, OSCP, CompTiA
- Minimum of five (5) years of work experience, and two (2) years of relevant experience in and established SOC and information security/cybersecurity
- Experience with security incident management and optimising the dashboarding, reporting and visibility of the SOC SLA performance for Customer stakeholders.
- Experience with a ticketing system such as BMC Remedy.
- Strong analytical and organizational skills.
- Concise writing skills, excellent MS Word skills as well as other MS Office Applications.
- Experience with securing various environments preferred.
- Experience in working across security frameworks.
- Experience in working across security technologies.
- Possess very good knowledge of technological advances within the information security area
- Demonstrate in depth solution and service knowledge

**LEADERSHIP COMPETENCY REQUIREMENTS**
- Responsive to reasonable customer, supplier, peer, and line management requests
- Proactive, innovative and reliable
- Put the customer first
- Do things right first time
- Positively contribute to this high-performance team
- Go the extra mile in the best interest of the company
- Develop positive and productive relationships with peers and customers
- Demonstrate emotional intelligence, and act with integrity
- Has demonstrated the ability to work well with others, high performance team work ethic
- Excellent communicator and collaborator
- Willingness to learn range of security technologies and platforms
- Positive attitude
- Delivering results and meeting customer expectations
- Following business-relevant instructions and procedures
- Learning and researching in various areas in cybersecurity

**Application Submission Details**:

- **Updated CV**:

- ** Short motivation Letter**:

- ** Supporting qualifications/certifications if any


  • L1 Incident Analyst

    2 days ago


    Midrand, South Africa Liquid Tech (Pty) Ltd. Full time

    **Role Purpose** To deliver day-to-day managed security services (MSS), related to SOC deliverables. Critical in this regard is to execute according to Standard Operating Procedure (SOP) expectations and meeting all related service level agreements (SLAs). It is further expected that these services will be enhanced and matured so that customer value can be...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the L3 Security Incident Handling Analyst will be responsible for monitoring enterprise networks and systems, detecting events and reporting on any and all threats that are directed against those systems regardless of their classification level or type. The L3 Security Incident Handling Analyst...

  • Incident Manager

    7 days ago


    Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** The Incident Manager is responsible for managing the process to restore normal service operation as quickly as possible to minimize the impact on business operations. This role involves leading the incident management team, ensuring that all IT service disruptions are resolved efficiently and effectively, and maintaining high levels of...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Management Specialist is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Management Specialist is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the...


  • Midrand, South Africa Nexio Full time

    **ROLE PURPOSE** As part of the Customer-facing Nexio SOC team, the Cybersecurity Incident Manager is a crucial role within an organization's cybersecurity team. The primary responsibility of the Cybersecurity Incident Manager is to detect, respond to, investigate, and mitigate cyber threats and incidents that occur within the organization's network and...


  • Midrand, South Africa Skye Business Solutions Full time

    Our clients are a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax and related services. Our global network of member firms and related entities in more than 150 countries and territories serves four out of five Fortune Global 500 companies. The main purpose of the job is to support the engagement Senior...


  • Midrand, South Africa Skye Business Solutions Full time

    We are a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax and related services. Our global network of member firms and related entities in more than 150 countries and territories, serves four out of five Fortune Global 500® companies. **About the Division** In a world that is constantly changing,...


  • Midrand, South Africa Phaki Personnel Full time

    **Job purpose**: To identify, develop, implement, and manage the companys security programs according to the Minimum Information Security Standards (MISS). **Minimum Qualification and Experience**: National Diploma in Security Management or an equivalent qualification from the college of Law (NQF 6) Ideal Qualification: BTech Degree in Security Risk...


  • Midrand, Gauteng, South Africa Boardroom Appointments Full time R1 200 000 - R2 400 000 per year

    Information Security ManagerResponsibilitiesStrategic Leadership & GovernanceDevelop and maintain The Companys enterprise-wide cybersecurity strategy aligned with business objectives and regulatory requirements.Establish and enforce security governance frameworks, policies, and standards.Ensure alignment with the NIST Cybersecurity Framework (Identify,...