Security Analyst

Network Finance

Randburg

On-site

ZAR 420,000 - 660,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Network Finance is seeking a Security Analyst to monitor, triage, and respond to security alerts using Microsoft Sentinel, Defender for Endpoint, and Azure services. You will implement incident playbooks, perform root cause analysis, and collaborate with IT to remediate vulnerabilities.

The role requires strong Azure and Defender experience and a proactive security mindset.

Qualifications

  • 3+ years’ experience in a Security Analyst / SOC / Cybersecurity role.
  • Hands-on experience with Microsoft Sentinel (Azure Sentinel).
  • Strong experience across Microsoft Defender security suite.
  • Solid working knowledge of Microsoft Azure (IAM, networking, logging, security controls).
  • Experience with Microsoft Purview (DLP, Information Protection, Compliance Manager).

Responsibilities

  • Monitor, triage, and investigate security alerts using Microsoft Sentinel (SIEM/SOAR).
  • Respond to incidents including malware, phishing, identity compromise, and data exfiltration.
  • Develop and tune Sentinel analytics rules, workbooks, and automation (Logic Apps).
  • Perform root cause analysis and produce incident reports with remediation actions.
  • Operate and manage Microsoft Defender for Endpoint, Identity, Cloud Apps, and Office 365.
  • Investigate advanced threats using Defender XDR.
  • Improve detection accuracy by tuning alerts and reducing false positives.
  • Collaborate with IT teams to remediate vulnerabilities and security gaps.
  • Monitor and secure Microsoft Azure workloads, networks, and identities.
  • Support implementation and enforcement of Zero Trust principles.
  • Apply Azure security best practices including RBAC, Conditional Access, and MFA.
  • Review logs and security telemetry from Azure resources.
  • Manage and monitor Fortinet solutions (FortiGate firewalls, FortiAnalyzer, FortiManager).
  • Investigate network‑based threats and suspicious traffic patterns.
  • Support firewall rule reviews, segmentation, VPN security, and IPS/IDS tuning.
  • Integrate Fortinet logs and alerts into Microsoft Sentinel for unified visibility.
  • Develop and maintain incident response playbooks for phishing, malware, identity compromise, data loss, and network attacks.
  • Align playbooks with organisational policies, compliance requirements, and MITRE ATT&CK techniques.
  • Review, test, and refine playbooks based on incident outcomes and threat hunting results.
  • Maintain clear documentation to support SOC operations and compliance.
  • Operate and support the vulnerability management lifecycle (discovery, risk assessment, prioritisation, remediation tracking).
  • Use Microsoft Defender Vulnerability Management and/or third‑party scanners.
  • Collaborate with infrastructure, cloud, and application teams to remediate vulnerabilities.
  • Track remediation progress and report on risk reduction.
  • Support Microsoft Purview for data classification, sensitivity labels, DLP, and compliance reporting.
  • Monitor and respond to DLP alerts.
  • Assist with regulatory compliance initiatives (POPIA, ISO 27001, GDPR).
  • Contribute to security policies, standards, and procedures.
  • Work closely with infrastructure, cloud, and development teams to embed security.
  • Stay current with emerging threats, Microsoft security features, and industry best practices.

Skills

Microsoft Sentinel
Microsoft Defender
Azure
Purview
SOC

Job description

Key Responsibilities
Security Monitoring & Incident Response
  • Monitor, triage, and investigate security alerts using Microsoft Sentinel (SIEM/SOAR)
  • Respond to incidents including malware, phishing, identity compromise, and data exfiltration
  • Develop and tune Sentinel analytics rules, workbooks, and automation (Logic Apps)
  • Perform root cause analysis and produce incident reports with remediation actions
Microsoft Defender Security Operations
  • Operate and manage Microsoft Defender for Endpoint, Identity, Cloud Apps, and Office 365
  • Investigate advanced threats using Defender XDR
  • Improve detection accuracy by tuning alerts and reducing false positives
  • Collaborate with IT teams to remediate vulnerabilities and security gaps
Cloud & Identity Security (Azure)
  • Monitor and secure Microsoft Azure workloads, networks, and identities
  • Support implementation and enforcement of Zero Trust principles
  • Apply Azure security best practices including RBAC, Conditional Access, and MFA
  • Review logs and security telemetry from Azure resources
Network Security
  • Manage and monitor Fortinet solutions (FortiGate firewalls, FortiAnalyzer, FortiManager)
  • Investigate network‑based threats and suspicious traffic patterns
  • Support firewall rule reviews, segmentation, VPN security, and IPS/IDS tuning
  • Integrate Fortinet logs and alerts into Microsoft Sentinel for unified visibility
Security Playbooks & Automation
  • Develop and maintain incident response playbooks for phishing, malware, identity compromise, data loss, and network attacks
  • Align playbooks with organisational policies, compliance requirements, and MITRE ATT&CK techniques
  • Review, test, and refine playbooks based on incident outcomes and threat hunting results
  • Maintain clear documentation to support SOC operations and compliance
Vulnerability Management
  • Operate and support the vulnerability management lifecycle (discovery, risk assessment, prioritisation, remediation tracking)
  • Use Microsoft Defender Vulnerability Management and/or third‑party scanners
  • Collaborate with infrastructure, cloud, and application teams to remediate vulnerabilities
  • Track remediation progress and report on risk reduction
Data Protection & Compliance
  • Support Microsoft Purview for data classification, sensitivity labels, DLP, and compliance reporting
  • Monitor and respond to DLP alerts
  • Assist with regulatory compliance initiatives (POPIA, ISO 27001, GDPR)
Continuous Improvement & Collaboration
  • Contribute to security policies, standards, and procedures
  • Work closely with infrastructure, cloud, and development teams to embed security
  • Stay current with emerging threats, Microsoft security features, and industry best practices
Job Experience and Skills Required
  • 3+ years’ experience in a Security Analyst / SOC / Cybersecurity role
  • Hands‑on experience with Microsoft Sentinel (Azure Sentinel)
  • Strong experience across Microsoft Defender security suite
  • Solid working knowledge of Microsoft Azure (IAM, networking, logging, security controls)
  • Experience with Microsoft Purview (DLP, Information Protection, Compliance Manager)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

Network Recruitment • Johannesburg

Hybrid
ZAR 600,000 - 900,000
Cloud Security Analyst
Cloud Security Analyst

Boardroom Appointments • Cape Town

On-site
ZAR 600,000 - 800,000
Flexible working hours
Diverse and inclusive workplace
Security Operations Analyst
Security Operations Analyst

Shop2Shop • Stellenbosch

Hybrid
ZAR 480,000 - 720,000
Information Security Manager
Information Security Manager

ATS Client • Midrand

On-site
ZAR 900,000 - 1,500,000
Microsoft Security Specialist
Microsoft Security Specialist

Netsurit • Johannesburg

Hybrid
ZAR 800,000 - 1,100,000
Exposure to cutting-edge technologies
Culture of knowledge sharing
Technical growth opportunities
Senior Microsoft Cloud & Platform Security Lead
Senior Microsoft Cloud & Platform Security Lead

Dariel • Roodepoort

On-site
ZAR 900,000 - 1,300,000
SOC Analyst Tier 2
SOC Analyst Tier 2

Boardroom Appointments • Cape Town

On-site
Security Operations Centre (SOC) Engineer
Security Operations Centre (SOC) Engineer

Recruit-It • Wes-Kaap

On-site
ZAR 180,000 - 240,000
Security Analyst- Tier 2
Security Analyst- Tier 2

Kocho Group • South Africa

Hybrid
ZAR 400,000 - 700,000
Security Analyst
Security Analyst

XContent Business Solutions (Pty) Ltd • Stellenbosch

On-site
ZAR 400,000 - 550,000