Security Engineer L1 - Umhlanga

First Technology Pty Ltd.

Umhlanga Rocks

On-site

ZAR 180,000 - 240,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

First Technology Pty Ltd. is seeking a Level 1 SOC Analyst to monitor security events, triage alerts, and coordinate incident response within agreed SLAs.

The role emphasizes collaboration across IT and security teams, vulnerability management, and ongoing threat intelligence integration. The ideal candidate will have Matric, S+ certification, and a related degree or diploma, with hands-on experience in SIEM and endpoint protection technologies.

Qualifications

  • Matric is essential.
  • S+ or equivalent certification is required.
  • Bachelor’s degree in Computer Science or Information Technology Diploma is beneficial.

Responsibilities

  • Monitor security event logs and alerts from SIEM, IDS/IPS and firewall logs.
  • Analyze alerts for severity and relevance to client’s security posture.
  • Perform initial triage to differentiate false positives or true incidents.
  • Communicate with IT management or end-users for troubleshooting/investigation.
  • Investigate incidents detected through monitoring tools.
  • Follow documented procedures for incident handling and escalation within SLA.
  • Coordinate with teams to contain and mitigate incidents.
  • Stay updated with the latest cybersecurity threats and vulnerabilities.
  • Analyze threat intelligence to identify risks to client infrastructure.
  • Generate regular reports on security events, incidents, systems and trends.
  • Maintain ticketing and documentation with timelines and evidence.
  • Assist in vulnerability scanning and remediation within timelines.
  • Monitor anti-virus and endpoint protection for malware detections.
  • Investigate malware incidents and containment measures.
  • Coordinate with IT for AV configuration and updates.
  • Participate in security awareness and on-call rotations.
  • Assist in maintenance and optimization of SOC tools.

Skills

Self-management
Independent work
Excellent communication
Attention to detail
Research new technologies
Analytical thinking
Root cause analysis
Multi-tasking
Patch management concepts
SIEM usage
Threat monitoring
Incident containment

Education

Matric
S+ or equivalent certification
Bachelor’s degree in Computer Science or IT Diploma

Tools

SIEM platform
Active Directory
Firewalls
Anti-Virus/EDR
Networking concepts

Job description

Role and Responsibilities

Security Monitoring and Alert Triage:

  • Monitor security event logs and alerts generated by security tools such as SIEM, IDS/IPS and firewall logs.
  • Analyze alerts to determine their severity and relevance to the client’s security posture.
  • Perform initial triage of security events to differentiate between false positives, true positives or any other possible security incidents.
  • Communicate with IT Management or end-users where necessary to perform troubleshooting / investigation.

Incident Detection and Response:

  • Investigate and analyze security incidents detected through monitoring tools.
  • Follow documented procedures for incident handling and escalation, ensuring timely response and resolution within SLA.
  • Coordinate with other teams within the SOC or across the organization to contain and mitigate security incidents.

Threat Intelligence Analysis:

  • Stay updated with the latest cybersecurity threats, vulnerabilities, and attack techniques.
  • Analyze threat intelligence data to identify potential risks to client’s organization infrastructure and systems.
  • Utilize threat intelligence to enhance security monitoring and incident response capabilities.

Reporting and Documentation:

  • Generate regular and monthly reports on security events, incidents, systems and trends for management and stakeholders.
  • Maintain consistent ticket management and accurate documentation, for security incidents and alerts, including their timelines, actions taken, recommended remediation, and evidence for future reference and improvement.

Vulnerability Management:

  • Assist in vulnerability scanning and assessment activities to identify weaknesses in the organization's systems and applications.
  • Collaborate with the vulnerability management team to identify, prioritize, report and where necessary remediate, vulnerabilities within established timelines.

Anti-Virus Management:

  • Monitor anti-virus and endpoint protection systems for malware detections and alerts.
  • Investigate and respond to malware incidents, including malware analysis and containment measures.
  • Coordinate with the IT team to ensure proper configuration and updates of anti-virus software, policies and management platforms.

Additional Duties:

  • Assist in the maintenance and optimization of SOC tools and technologies.
  • Participate in security awareness training and initiatives.
  • Collaborate with other teams within the cybersecurity function, such as threat hunting and forensics, for proactive security measures.
  • Participate in on-call rotations for after-hours incident response and support.

Note: The Level 1 SOC Analyst may also be required to perform other duties as assigned, depending on the specific needs and priorities of the organization's security operations. This could include involvement in projects related to security architecture, compliance audits, or emerging security technologies.

Soft Skills and attributes

  • Security Engineer L1 must be able to demonstrate the following:
    • Ability to be self-managed and work independently, or as part of a team
    • Excellent communication skills
    • Attention to detail
    • Research new technologies and techniques used in the cyber security industry
    • Keen analytical ability related to the diagnosis of policy violations and their impact / risk within the monitored environment
    • Consistent, prompt delivery in often common or repetitive tasks
    • Escalate, but maintain visibility of, suspected threats beyond current technical ability
    • Fundamental understanding of technologies and concepts involved in security monitoring (Active Directory, Firewalls, Anti-Virus / EDR and basic Networking principles)
    • Ability to multi-task and keep track of, and manage expectations with regards to multiple security alerts on a daily basis
    • Keen interest in finding the root cause of security incidents or alerts
    • Fundamental understanding of Microsoft & 3rd Party Patch Management concepts
    • Ability to utilize the full capability of the SIEM platform
Qualifications and Education Requirements
  • Matric is essential
  • S+ or equivalent certification
  • Bachelor’s degree in Computer Science or Information Technology Diploma (Beneficial)
Preferred Skills
  • Should have proven excellence as a Service Desk Engineer or in another relevant position
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

L2 SOC Analyst – DOL2SOCA
L2 SOC Analyst – DOL2SOCA

Armstrong Appointments • Cape Town

On-site
ZAR 480,000 - 720,000
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Integrity360 • Johannesburg

On-site
ZAR 600,000 - 900,000
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Jobless • Johannesburg

On-site
ZAR 600,000 - 900,000
L3 SOC Analyst - Cape Town
L3 SOC Analyst - Cape Town

Integrity360 • Cape Town

On-site
ZAR 600,000 - 800,000
L2 SOC Analyst - Cape Town or Johannesburg
L2 SOC Analyst - Cape Town or Johannesburg

Integrity360 • Johannesburg

On-site
ZAR 420,000 - 620,000
Senior Security Analyst - Hybrid
Senior Security Analyst - Hybrid

Recruit-It • Somerset West

On-site
ZAR 900,000 - 1,200,000
Senior Security Analyst
Senior Security Analyst

Recruit-It • Somerset West

On-site
ZAR 900,000 - 1,600,000
Junior Security Engineer
Junior Security Engineer

Hire Resolve • Midrand

On-site
ZAR 300,000 - 500,000
Competitive salary based on experience
SOC Analyst Tier 2
SOC Analyst Tier 2

Boardroom Appointments • Cape Town

On-site
Security Analyst
Security Analyst

Adapt IT Group • Midrand

On-site
ZAR 600,000 - 900,000