Security Analyst II: Threat Defender & Automation

AiR

Cape Town

On-site

ZAR 400,000 - 600,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Uncapped leave
Comprehensive benefits package
Growth opportunities

Job summary

AiR in Cape Town is seeking a Security Operations/Incident Response professional to defend against evolving cyber threats using the Microsoft security stack, AI, and automation. You will monitor, detect, and respond to security alerts across M365 and Azure to protect the organization and its customers.

The ideal candidate has 3+ years in security operations, hands-on with Microsoft Sentinel, Defender, and Entra ID, and knowledge of MITRE ATT&CK.

Qualifications

  • 3+ years in Security Operations or Incident Response
  • Experience with Microsoft Sentinel and KQL
  • Hands-on with Microsoft Defender (Endpoint, Office 365) & Entra ID
  • Understanding of MITRE ATT&CK and common attack vectors
  • Excellent analytical and communication skills
  • Certifications: CompTIA CySA+ or Microsoft SC-200

Responsibilities

  • Investigate and respond to escalated security alerts across M365 and Azure
  • Develop detection rules and automation playbooks
  • Mentor junior analysts and improve security processes
  • Coordinate incident response and remediation efforts

Skills

Security Operations
Incident Response
MITRE ATT&CK
KQL
Mentoring junior analysts
Analytical skills

Education

CompTIA CySA+
Microsoft SC-200

Tools

Microsoft Sentinel
Microsoft Defender for Endpoint
Defender for Office 365
Entra ID

Job description

AiR in Cape Town is seeking a Security Operations/Incident Response professional to defend against evolving cyber threats using the Microsoft security stack, AI, and automation. You will monitor, detect, and respond to security alerts across M365 and Azure to protect the organization and its customers.

The ideal candidate has 3+ years in security operations, hands-on with Microsoft Sentinel, Defender, and Entra ID, and knowledge of MITRE ATT&CK.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst – Tier 2
Security Analyst – Tier 2

AiR • Cape Town

On-site
ZAR 400,000 - 600,000
Uncapped leave
Comprehensive benefits package
Growth opportunities
Senior Security Analyst
Senior Security Analyst

Sabenza IT & Recruitment • Cape Town

On-site
ZAR 700,000 - 1,100,000
Security Operations Engineer
Security Operations Engineer

Parvana • Cape Town

Hybrid
ZAR 600,000 - 900,000
Security Operations Engineer
Security Operations Engineer

Parvana • South Africa

Hybrid
ZAR 700,000 - 900,000
Hybrid work model
Career development
Security Analyst
Security Analyst

XContent Business Solutions (Pty) Ltd • Stellenbosch

On-site
ZAR 400,000 - 550,000
SOC Analyst: Incident Response & Threat Hunting
SOC Analyst: Incident Response & Threat Hunting

Integrity360 • Cape Town

On-site
ZAR 420,000 - 600,000
Hybrid Security Operations Analyst - Defender & Sentinel
Hybrid Security Operations Analyst - Defender & Sentinel

XContent Business Solutions (Pty) Ltd • Stellenbosch

Hybrid
ZAR 400,000 - 550,000
Hybrid Security Operations Engineer - MITRE Att&ck & Azure
Hybrid Security Operations Engineer - MITRE Att&ck & Azure

Parvana • South Africa

Hybrid
ZAR 900,000 - 1,300,000
Wellness benefits
Hybrid in-office/remote
Senior Security Analyst: Incident Response & Cloud Security
Senior Security Analyst: Incident Response & Cloud Security

Adapt IT Group • Midrand

On-site
ZAR 600,000 - 900,000
Security Analyst
Security Analyst

Adapt IT Group • Midrand

On-site
ZAR 600,000 - 900,000