L2 SOC Analyst – DOL2SOCA

Armstrong Appointments

Cape Town

On-site

ZAR 480,000 - 720,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Armstrong Appointments is seeking an L2 SOC Analyst to join our client, an IT Managed Service Provider, based in Cape Town or Gauteng. You will provide level 2 support, escalate as needed, and perform threat hunting and investigations on a day-to-day basis.

You will help drive compliance and SOC strategy using company tooling to enhance services for clients, with proactive security and quality outcomes. On-call duties may apply to after-hours incidents.

Qualifications

  • Experience in SOC operations with SIEM/EDR
  • MSP/MSSP experience
  • 3+ years in a SOC environment
  • Threat hunting and incident response experience
  • Familiarity with ISO, PCI DSS, CIS, or NIST controls

Responsibilities

  • Ongoing threat hunting for clients and internally for Company.
  • Automating tasks, alert and report creation on SOC activities.
  • Continuous monitoring of and action on internal and client security systems.
  • Detecting and responding to security events and protecting information assets.
  • Assisting in delivering security services and products to clients.
  • Coaching and mentoring of junior analysts.
  • Participation in on-call rota for out-of-hours incidents.
  • Communicate with customers about incident progress and outages.

Skills

Threat hunting
Incident response
On-call support
Coaching
Automation

Education

MS AZ-900
MS AZ-500
MS SC-200
MS SC-300
MS SC-400
CompTIA N+
CompTIA S+
Mimcast certified
BTL1

Tools

SIEM
EDR
Azure Sentinel
Intune
Defender

Job description

Our client, an IT Managed service provider are currently seeking the skills of a L2 SOC Analyst to be based in either Cape Town or Gauteng

The main role of the L2 SOC Analyst is to provide level 2 support and escalations capabilities to the SOC and perform day to day SOC threat hunting and investigation activities.

The L2 SOC Analyst will be responsible for assisting in driving our compliance and strategy in the SOC using the tooling within the company to develop and improve our services to our client and ensure we provide a pro-active and quality service to all SOC clients.

Main job function
  • Ongoing threat hunting for clients and internally for Company.
  • Automating tasks, alert and report creation on SOC activities.
  • Continuous monitoring of and action on internal and client security systems.
  • Detecting and responding to security events and protecting information assets.
  • Assisting in delivering security services and products to clients.
  • Assisting with improving internal SOC processes and procedures.
  • Contribute to the improvement of the information security within the company.
  • Communication with customers as required: keeping them informed of incident progress, notifying them of impending changes or agreed outages, etc.
  • Incident response and investigation, including owning incident playbooks.
  • Product investigation and testing for the SOC.
  • Upon out of hours incidents, support the wider Security Operations team by participating in an on-call rota.
  • Coaching and mentoring of junior analysts
Qualifications
  • Desirable Qualifications
  • Cybersecurity related certifications.
  • Microsoft Security stack certifications. MS AZ-900
  • MS AZ-500
  • MS SC-200
  • MS SC-300
  • MS SC-400
  • Comptia N+
  • Comptia S+
  • Other technical security and vendor qualifications a bonus
  • Mimcast certified
  • BTL1
Criteria

Experience in the following is required

  • SOC operations and tools (SIEM, EDR, etc.)
  • Vulnerability management experience
  • MSP/MSSP experience
  • Microsoft security stack (Intune, Azure, ATP, Defender)
  • 3+ years in a SOC environment
  • Threat Hunting
  • Experience in the following is desirable
  • Microsoft Azure Sentinel
  • Scripting (PowerShell, Python, regex)
  • Other security tools a bonus
  • Control frameworks (ISO, PCI DSS, CIS, and/or NIST)
  • Working with remote team
  • 5+ years in a cybersecurity environment
  • End Point Protection, Cloud Security, Security Incident and Event Management, Managed Anti-Virus Services, CASB, Data Loss Prevention
  • Threat and security research and investigation
  • Ability to provide information and audits and reporting for supported technologies.
  • Present on risk findings and vulnerabilities in a client environment
  • Conduct and develop security controls and put in measures to mitigate and prevent threats, vulnerabilities to prevent attacks on client environments
  • Ability to create root cause analysis and reporting on events
  • Facilitates the analysis of a client threat landscape during cyber-attacks activity.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

L2 SOC Analyst
L2 SOC Analyst

Pronel Consultants • Johannesburg

On-site
ZAR 550,000 - 900,000
L2 SOC Analyst
L2 SOC Analyst

Pronel Personnel • Johannesburg

On-site
ZAR 600,000 - 900,000
L2 SOC Analyst - Cape Town or Johannesburg
L2 SOC Analyst - Cape Town or Johannesburg

Integrity360 • Johannesburg

On-site
ZAR 420,000 - 620,000
L2 SOC Analyst: Threat Hunting & Incident Response
L2 SOC Analyst: Threat Hunting & Incident Response

Armstrong Appointments • Cape Town

On-site
ZAR 480,000 - 720,000
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Integrity360 • Johannesburg

On-site
ZAR 600,000 - 900,000
L3 SOC Analyst - Cape Town
L3 SOC Analyst - Cape Town

Integrity360 • Cape Town

On-site
ZAR 600,000 - 800,000
L2 SOC Analyst - Cape Town or Johannesburg
L2 SOC Analyst - Cape Town or Johannesburg

Integrity360 • Cape Town

On-site
ZAR 420,000 - 600,000
L2 SOC Analyst: Threat Hunting, IR & Automation
L2 SOC Analyst: Threat Hunting, IR & Automation

Pronel Personnel • Johannesburg

On-site
ZAR 600,000 - 900,000
L2 SOC Analyst: Threat Hunting, Incident Response & Automation
L2 SOC Analyst: Threat Hunting, Incident Response & Automation

Pronel Consultants • Johannesburg

On-site
ZAR 550,000 - 900,000
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Jobless • Johannesburg

On-site
ZAR 600,000 - 900,000