Key Responsibilities
Security Monitoring & Incident Response
- Monitor, triage, and investigate security alerts using Microsoft Sentinel (SIEM/SOAR)
- Respond to incidents including malware, phishing, identity compromise, and data exfiltration
- Develop and tune Sentinel analytics rules, workbooks, and automation (Logic Apps)
- Perform root cause analysis and produce incident reports with remediation actions
Microsoft Defender Security Operations
- Operate and manage Microsoft Defender for Endpoint, Identity, Cloud Apps, and Office 365
- Investigate advanced threats using Defender XDR
- Improve detection accuracy by tuning alerts and reducing false positives
- Collaborate with IT teams to remediate vulnerabilities and security gaps
Cloud & Identity Security (Azure)
- Monitor and secure Microsoft Azure workloads, networks, and identities
- Support implementation and enforcement of Zero Trust principles
- Apply Azure security best practices including RBAC, Conditional Access, and MFA
- Review logs and security telemetry from Azure resources
Network Security
- Manage and monitor Fortinet solutions (FortiGate firewalls, FortiAnalyzer, FortiManager)
- Investigate network‑based threats and suspicious traffic patterns
- Support firewall rule reviews, segmentation, VPN security, and IPS/IDS tuning
- Integrate Fortinet logs and alerts into Microsoft Sentinel for unified visibility
Security Playbooks & Automation
- Develop and maintain incident response playbooks for phishing, malware, identity compromise, data loss, and network attacks
- Align playbooks with organisational policies, compliance requirements, and MITRE ATT&CK techniques
- Review, test, and refine playbooks based on incident outcomes and threat hunting results
- Maintain clear documentation to support SOC operations and compliance
Vulnerability Management
- Operate and support the vulnerability management lifecycle (discovery, risk assessment, prioritisation, remediation tracking)
- Use Microsoft Defender Vulnerability Management and/or third‑party scanners
- Collaborate with infrastructure, cloud, and application teams to remediate vulnerabilities
- Track remediation progress and report on risk reduction
Data Protection & Compliance
- Support Microsoft Purview for data classification, sensitivity labels, DLP, and compliance reporting
- Monitor and respond to DLP alerts
- Assist with regulatory compliance initiatives (POPIA, ISO 27001, GDPR)
Continuous Improvement & Collaboration
- Contribute to security policies, standards, and procedures
- Work closely with infrastructure, cloud, and development teams to embed security
- Stay current with emerging threats, Microsoft security features, and industry best practices
Job Experience and Skills Required
- 3+ years’ experience in a Security Analyst / SOC / Cybersecurity role
- Hands‑on experience with Microsoft Sentinel (Azure Sentinel)
- Strong experience across Microsoft Defender security suite
- Solid working knowledge of Microsoft Azure (IAM, networking, logging, security controls)
- Experience with Microsoft Purview (DLP, Information Protection, Compliance Manager)