Cyber Security Analyst

Network Recruitment

Johannesburg

Hybrid

ZAR 600,000 - 900,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Network Recruitment is seeking a proactive Cyber Security Analyst L2/L3 to join a growing security team. This hybrid, office-based role focuses on protecting Microsoft-centric cloud and on-prem environments.

You’ll monitor, detect, and respond to threats across Microsoft security stack, implement Zero Trust principles, and collaborate with IT to remediate vulnerabilities.

Qualifications

  • Hands-on experience with Microsoft Sentinel and Defender suite.
  • Solid understanding of Microsoft Azure IAM, networking and security controls.
  • Knowledge of SIEM/SOAR concepts and MITRE ATT&CK framework.

Responsibilities

  • Monitor, triage, and investigate alerts using Microsoft Sentinel.
  • Respond to incidents including malware, phishing, identity compromise, and data exfiltration.
  • Develop and optimise detection rules, dashboards, and automation workflows.
  • Manage and operate Microsoft Defender (Endpoint, Identity, Cloud Apps, Office 365).
  • Investigate threats using Defender XDR and tune alerts to reduce false positives.
  • Secure Azure workloads, networks, and identities; monitor logs and telemetry.
  • Manage Fortinet solutions; review firewall rules and VPN security; integrate logs with Sentinel.

Skills

Microsoft Sentinel
Microsoft Defender
Azure security
MITRE ATT&CK
IAM & cloud security

Tools

FortiGate
FortiAnalyzer
FortiManager
Purview
Defender XDR

Job description

We’re looking for a proactive and detail-oriented Cyber Security Analyst L2/L3 to join a growing security team (office based with flexibility). This role is ideal for someone passionate about defending modern cloud environments and working hands-on with the Microsoft security stack.

You’ll play a key role in monitoring, detecting, and responding to threats across a Microsoft-centric ecosystem, helping to strengthen overall security posture while ensuring compliance across cloud and on-prem environments.

Key Responsibilities
Security Monitoring & Incident Response
  • Monitor, triage, and investigate alerts using Microsoft Sentinel (SIEM/SOAR)
  • Respond to incidents including malware, phishing, identity compromise, and data exfiltrations
  • Conduct root cause analysis and produce detailed incident report
  • Develop and optimise detection rules, dashboards, and automation workflows
Microsoft Defender Security Operations
  • Manage and operate Microsoft Defender (Endpoint, Identity, Cloud Apps, Office 365)
  • Investigate threats using Defender XDR
  • Tune alerts to improve detection accuracy and reduce false positives
  • Work with IT teams to remediate vulnerabilities
Cloud & Identity Security (Azure)
  • Secure Azure workloads, networks, and identities
  • Support Zero Trust implementation
  • Apply best practices (RBAC, Conditional Access, MFA)
  • Monitor logs and security telemetry across Azure services
Network Security
  • Manage and monitor Fortinet solutions (FortiGate, FortiAnalyzer, FortiManager)
  • Investigate suspicious network activity and threats
  • Support firewall rule reviews, segmentation, VPN security, and IDS/IPS tuning
  • Integrate network logs into Microsoft Sentinel
Security Playbooks & Automation
  • Develop and maintain incident response playbooks
  • Align processes with MITRE ATT&CK and organisational policies
  • Test and refine playbooks through simulations and real incidents
Vulnerability Management
  • Support full vulnerability lifecycle: discovery, assessment, prioritisation, remediation
  • Work with Microsoft Defender Vulnerability Management and other tools
  • Track remediation progress and report on risk reduction
Data Protection & Compliance
  • Support Microsoft Purview (DLP, data classification, compliance reporting)
  • Monitor and respond to DLP alerts
  • Assist with compliance initiatives (POPIA, ISO 27001, GDPR where applicable)
  • Contribute to security policies and best practices
  • Collaborate with infrastructure, cloud, and development teams
  • Stay up to date with emerging threats and technologies
Required Skills & Experience

Technical Skills

  • Hands-on experience with Microsoft Sentinel
  • Strong experience with Microsoft Defender suite
  • Solid understanding of Microsoft Azure (IAM, networking, security controls)
  • Experience with Microsoft Purview
  • Knowledge of SIEM/SOAR concepts and MITRE ATT&CK framework
  • Strong understanding of identity and access management and cloud security
Experience
  • 3+ years in a Security Analyst / SOC / Cyber security role
  • Experience securing Microsoft 365 and Azure environments
  • Proven incident response and threat investigation experience
Certifications (Advantageous)
  • CompTIA Security+, CISSP, or similar
  • Microsoft SC-200, AZ-500, SC-400
Why Join?
  • Work with modern Microsoft security technologies
  • Exposure to enterprise-scale cloud and hybrid environments
  • Collaborative and forward-thinking team
  • Opportunity to grow within a maturing security function
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Network Finance • Randburg

On-site
ZAR 420,000 - 660,000
Cloud Security Analyst
Cloud Security Analyst

Boardroom Appointments • Cape Town

On-site
ZAR 600,000 - 800,000
Flexible working hours
Diverse and inclusive workplace
Cloud Security Engineer
Cloud Security Engineer

Inkhanyeti Solutions • Johannesburg

On-site
ZAR 600,000 - 900,000
Microsoft Security Specialist
Microsoft Security Specialist

Netsurit • Johannesburg

Hybrid
ZAR 800,000 - 1,100,000
Exposure to cutting-edge technologies
Culture of knowledge sharing
Technical growth opportunities
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Jobless • Johannesburg

On-site
ZAR 600,000 - 900,000
L3 SOC Analyst - Cape Town
L3 SOC Analyst - Cape Town

Integrity360 • Cape Town

On-site
ZAR 600,000 - 800,000
Cloud Security Engineer (L2)
Cloud Security Engineer (L2)

Avatar Recruitment • Cape Town

On-site
ZAR 540,000 - 900,000
Hybrid Security Operations Analyst - Defender & Sentinel
Hybrid Security Operations Analyst - Defender & Sentinel

XContent Business Solutions (Pty) Ltd • Stellenbosch

Hybrid
ZAR 400,000 - 550,000
Security Analyst
Security Analyst

XContent Business Solutions (Pty) Ltd • Stellenbosch

On-site
ZAR 400,000 - 550,000
Security Analyst- Tier 2
Security Analyst- Tier 2

Kocho Group • South Africa

Hybrid
ZAR 400,000 - 700,000