Threat Response Analyst

4 days ago


Johannesburg, Gauteng, South Africa Mimecast Full time

L1 - Threat Response Analyst

As a Threat Response Analyst you will be joining the Mimecast Messaging Security organization and be responsible for supporting a service for on-demand threat resolution. The service is designed to provide customers with prompt feedback and intelligence on email-borne threats, remediate these threats from their email environment to reduce dwell time, and put the appropriate detections in place to prevent further incidents from occurring. The role may require working afternoon/evening shifts and being part of a rotation for holiday support.

Messaging Security ensures that our security-focused solutions are performing accurately and efficiently. We verify that Mimecast can detect the latest email-borne threats amidst a rapidly evolving threat landscape. Through threat research and customer feedback we identify where Mimecast can be improved and update detection at our spam, URL, and attachment security layers. We strive for proactive, rather than reactive, approaches to threat detection.

The team is also responsible for assuring that Mimecast maintains an exceptional sending reputation by looking for compromised email addresses and senders following poor mailing practice.

Messaging Security works closely with research and development, as well as customer support. We are a global team that spans three continents.

What You'll Do:

  • Analyze phishing/malicious email campaigns to identify IOC's
  • Categorize email threats and determining the best means of updating detection
  • Provide email security advice, expertise, and remediation to our customers
  • Understand security policies within the Mimecast Administration Console and providing configuration suggestions to customers
  • Research and investigate the latest security threats and their potential impact to Mimecast customers
  • Work with security vendors around threat detection techniques and remediation
  • Identifying opportunities for improved processes and systems

What You'll Bring:

  • Working knowledge of messaging (email traffic management) and routing
  • Experience and understanding of email security technologies
  • Strong understanding of Domain Name System (DNS)
  • Strong understanding of SMTP, SSL/TLS, POP3, IMAP, TCP/IP
  • Ability to translate complex technical capabilities into management-friendly responses
  • Curiosity about the infrastructure of phishing/malicious email campaigns
  • 1+ years' experience working with the Mimecast platform
  • 2+ years' experience working in a Security Operation Center (SOC)
  • Experience working with email/malware detection and blocking techniques
  • Experience working with threat intelligence platforms
  • Experience working within SaaS environments

What We Bring

Join our Threat Response | Ops Team to accelerate your career journey, working with cutting-edge technologies and contributing to projects that have real customer impact. You will be immersed in a dynamic environment that recognizes and celebrates your achievements.

Mimecast is on a path of steady and healthy growth as a company, investing in people like you who bring the skills and expertise to raise our technical expertise, operational maturity, and customer success to the next level. Your contributions are important Every voice and action matters.

Mimecast offers formal and on-the-job learning opportunities, maintains a comprehensive benefits package that helps our employees and their family members to sustain a healthy lifestyle, and importantly – opportunities to work with cross-functional teams to build your knowledge

Our Hybrid Model: We provide you with the flexibility to live balanced, healthy lives through our hybrid working model that champions both collaborative teamwork and individual flexibility. Employees are expected to come to the office at least two days per week, because working together in person:

  • Fosters a culture of collaboration, communication, performance, and learning.
  • Drives innovation and creativity within and between teams
  • Introduces employees to priorities outside of their immediate realm.

  • Ensures important interpersonal relationships and connections with one another and our community

The base salary range for this position is , ,00 ZAR Annual plus benefits. This range represents the minimum and maximum new hire compensation for this role. The position may also be eligible for incentive plans and additional benefits, in accordance with company policy and local regulations. Our salary ranges are determined by role, level, and location with individual compensation also dependent on factors such as qualifications, experience, and skills. Final offers will reflect these considerations and may vary accordingly.

LI-YK1

Belonging at Mimecast

Cybersecurity is a community effort. That's why we're committed to building an inclusive, diverse community that celebrates and welcomes everyone – unless they're a cybercriminal, of course.

We're proud to be an Equal Opportunity and Affirmative Action Employer, and we'd encourage you to join us whatever your background. We particularly welcome applicants from traditionally underrepresented groups.

We consider everyone equally: your race, age, religion, sexual orientation, gender identity, ability, marital status, nationality, or any other protected characteristic won't affect your application.

Due to certain obligations to our customers, an offer of employment will be subject to your successful completion of applicable background checks, conducted in accordance with local law.



  • Johannesburg, Gauteng, South Africa Standard Bank Full time R120 000 - R180 000 per year

    Job OverviewBusiness Segment: Group FunctionsLocation: ZA, undefined, Johannesburg, Simmonds StreetJob Type: Full-timeJob Ref ID: A-0003Date Posted: 11/14/2025Job DescriptionAs a Specialist Incident Response Analyst, you will play a central role in detecting, investigating, and responding to cyber incidents in a non-tiered SOC environment. You will own...


  • Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R900 000 - R1 200 000 per year

    Minimum requirements:IT Risk/security certification such as CISM, CISSP or CISA Required Relevant Azure/AWS Cloud Certification Required.A degree in information Technology.Experience within FSI developing threat models, risk profiles, cyber security risk and incident management, and insight into crime in the financial sector. Experience in Malware...


  • Johannesburg, Gauteng, South Africa Mimecast Full time

    Messaging Security Analyst II – Threat ProtectionAbout the Job/OverviewAs a Messaging Security Analyst II, you will build upon your foundational expertise in email security to take on more complex threat investigations and contribute to the refinement of Mimecast's detection and response capabilities. You will act as a key escalation point for analysts,...


  • Johannesburg, Gauteng, South Africa Standard Bank Full time

    Job OverviewBusiness Segment: Group FunctionsLocation: ZA, undefined, Johannesburg, 30 Baker StreetJob Type: Full-timeJob Ref ID: A-0001Date Posted: 12/11/2025Job DescriptionTo provide Cyber-InfoSec expertise, professional knowledge, and technical skills to prevent cyber-attacks, significant reputational, financial, or other losses. To implement SBGs Cyber...

  • Security Analyst

    2 weeks ago


    Johannesburg, Gauteng, South Africa NTT DATA Full time R250 000 - R500 000 per year

    We are seeking a proactive and detail-oriented Security Analyst with 2 to 3 years of experience, focused on network and firewall security. The ideal candidate will have hands-on expertise in Palo Alto firewalls, Cisco networking, and general network security practices.ResponsibilitiesMonitor and manage firewall systems, with a focus on Palo Alto...


  • Johannesburg, Gauteng, South Africa InfyStrat Full time R250 000 - R500 000 per year

    InfyStrat is seeking a motivated Cyber Security Analyst to join our team and contribute to our mission of safeguarding our digital assets and infrastructure. In this role, you will monitor, detect, and respond to security threats, vulnerabilities, and incidents across our systems. You'll perform risk assessments, analyze security breaches, and provide...

  • SOC Analyst

    6 days ago


    Johannesburg, Gauteng, South Africa Old Mutual Limited Full time R533 333 - R1 666 666 per year

    Let's Write Africa's Story TogetherOld Mutual is a firm believer in the African opportunity and our diverse talent reflects this. Job DescriptionDegree in Information Technology, Information Systems, Cybersecurity, or a related field.Relevant security certifications will be considered an advantage.Minimum of 3 years' experience within a SOC...

  • SOC Analyst

    4 days ago


    Johannesburg, Gauteng, South Africa Old Mutual South Africa Full time

    Let's Write Africa's Story TogetherOld Mutual is a firm believer in the African opportunity and our diverse talent reflects this.Job DescriptionDegree in Information Technology, Information Systems, Cybersecurity, or a related field.Relevant security certifications will be considered an advantage.Minimum of 3 years' experience within a SOC environment.Proven...


  • Johannesburg, Gauteng, South Africa Optimal Growth Technologies Full time R60 000 - R120 000 per year

    Network Security Analyst (Remote South Africa) Level: IntermediateAbout the RoleWere looking for a highly skilled Network Security Analyst to join our forward-thinking, security-driven team. In this role, you'll be the guardian of our digital infrastructure ensuring that firewalls, network rules, and security configurations are robust, compliant, and ready...


  • Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R250 000 - R500 000 per year

    Key purpose:As a junior analyst, you'll be responsible for the analysis of information security vulnerabilities in web applications and other online services. Your main focus will be on performing penetration testing and vulnerability assessment for our clients' websites. You'll also research potential threats to these sites by analysing publicly available...