Security Operations Analyst

Shop2Shop

Stellenbosch

Hybrid

ZAR 480,000 - 720,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Shop2Shop is seeking an experienced Security Operations Analyst in Stellenbosch to monitor identity, endpoint, cloud and network security, investigate threats and improve controls. You will tune Defender-based detections, coordinate remediation with engineers and service providers, and contribute to SIEM capabilities and threat intelligence.

You will apply your expertise to track vulnerabilities, maintain incident records, and support governance with evidence collection and audits.

Qualifications

  • Practical knowledge of security monitoring, alert triage, investigation and incident-response processes.
  • Experience with Microsoft Defender or comparable endpoint, identity, email and cloud-security platforms.
  • Understanding of vulnerability management, remediation prioritisation and security exposure reporting.
  • Ability to analyse security telemetry, identify suspicious activity and document investigation findings.
  • Working knowledge of SIEM concepts and query languages such as KQL.
  • Familiarity with MITRE ATT&CK, CIS Controls, ISO 27001.
  • Methodical incident handling and evidence management.

Responsibilities

  • Monitor security alerts across identity, endpoint, cloud, email and network environments.
  • Triage alerts and investigate indicators of compromise or suspicious activity.
  • Maintain and tune detections to improve alert quality and reduce unnecessary noise.
  • Develop monitoring and detection capabilities using Microsoft Defender and future SIEM platforms.
  • Coordinate vulnerability scanning and assess findings based on risk and business impact.
  • Track remediation activities with internal engineers and service providers.
  • Monitor Secure Score, exposure indicators and security control coverage.
  • Conduct threat-hunting activities and develop detection rules.
  • Coordinate phishing simulations and security awareness activities.
  • Maintain security operations procedures, investigation playbooks and response runbooks.

Skills

Security monitoring
Incident response
Threat detection
Vulnerability management
SIEM
Microsoft Defender
KQL

Education

Bachelor's degree in Cybersecurity/IT/CS

Tools

Microsoft Defender
Microsoft Sentinel
KQL

Job description

The Security Operations Analyst is a hands-on security role responsible for monitoring, investigating and continuously improving Shop2Shop’s security posture across its identity, endpoint, cloud and network environments.

You will focus on security monitoring, vulnerability management, incident response, threat detection and the ongoing tuning of controls across the Microsoft Defender stack and future SIEM capabilities. You will work with internal engineering teams and service providers to identify risks, coordinate remediation and improve how the organisation detects and responds to security events.

You’ll thrive in this role if…

  • You're naturally curious and think like an attacker; you'll chase a faint signal until you know exactly what happened
  • You can tell noise from a real threat, and you tune for signal rather than burying the team in alerts
  • You stay calm and structured under pressure; during an incident you work the timeline, not the panic
  • You're disciplined about evidence; clear records, clean root-cause analysis, actions tracked to closure
  • You partner with engineers to respond rather than to point fingers; you're in the incident with them
  • You keep learning because the threat landscape does, and new techniques and detections interest you
  • You see compliance as real risk reduction, not a box to tick
What You Will Do
Security Monitoring and Detection
  • Monitor security alerts across identity, endpoint, cloud, email and network environments.
  • Triage alerts and investigate indicators of compromise or suspicious activity.
  • Maintain and tune detections to improve alert quality and reduce unnecessary noise.
  • Develop monitoring and detection capabilities using Microsoft Defender and future SIEM platforms.
Security Incident Response
  • Investigate security incidents and coordinate containment, remediation and recovery activities.
  • Work with the Microsoft 365 and Modern Desktop Engineers during technical response actions.
  • Maintain incident records, timelines, evidence and investigation notes.
  • Conduct post-incident reviews and track agreed corrective actions.
Vulnerability and Exposure Management
  • Coordinate vulnerability scanning and assess findings based on risk and business impact. Produce prioritised remediation plans for endpoint, identity, cloud and network vulnerabilities.
  • Track remediation activities with internal engineers and service providers.
  • Monitor Secure Score, exposure indicators and security control coverage.
Security Control Management
  • Manage and tune controls across the Microsoft Defender security stack.
  • Monitor identity threats, risky sign-ins, email threats and endpoint protection compliance.
  • Review firewall reports and work with the managed service provider on policy improvements.
  • Monitor Microsoft Purview DLP and data-labelling controls and coordinate required responses.
Threat Hunting and Security Intelligence
  • Conduct threat-hunting activities using available security telemetry.
  • Develop queries and detection rules to identify suspicious patterns and behaviours.
  • Track relevant threat intelligence, indicators of compromise and emerging attack methods.
  • Map detections and identified control gaps to recognised frameworks such as MITRE ATT&CK.
Security Governance and Awareness
  • Coordinate phishing simulations and security awareness activities with Learning and Development.
  • Maintain security operations procedures, investigation playbooks and response runbooks.
  • Support audit evidence collection, log-retention requirements and control assessments.
  • Coordinate security testing and track the remediation of findings within the IT Operations scope.
What You’ll Need to Succeed
  • Practical knowledge of security monitoring, alert triage, investigation and incident-response processes.
  • Experience with Microsoft Defender or comparable endpoint, identity, email and cloud-security platforms.
  • Understanding of vulnerability management, remediation prioritisation and security exposure reporting.
  • Ability to analyse security telemetry, identify suspicious activity and document investigation findings.
  • Working knowledge of SIEM concepts, detection rules and query languages such as KQL.
  • Familiarity with security frameworks and techniques, including MITRE ATT&CK and CIS Controls.
  • A methodical approach to incident handling, evidence collection and follow-through on corrective actions.
  • The ability to communicate security findings clearly to technical teams, service providers and business stakeholders.
Skills and Knowledge
  • Security monitoring, alert triage, investigation and incident-response practices.
  • Microsoft Defender security technologies across endpoint, identity, email, cloud applications and Microsoft 365.
  • SIEM concepts and security telemetry analysis, with knowledge of Microsoft Sentinel and KQL being beneficial.
  • Vulnerability and exposure management, including risk-based prioritisation, remediation tracking and Secure Score.
  • Threat hunting, detection engineering and the use of threat intelligence and indicators of compromise.
  • Security frameworks and control standards, including MITRE ATT&CK, CIS Controls and ISO 27001.
  • Identity, endpoint, email, cloud and network-security principles, including firewall-policy review.
  • Data protection and security-governance concepts, including DLP monitoring, audit-log retention and evidence handling.
Qualifications and Experience
  • A relevant diploma or degree in Cybersecurity, Information Technology, Computer Science or a related field, or equivalent practical experience.
  • Approximately 5–7 years’ experience in security operations, infrastructure security or a related technical security role.
  • Hands-on experience with security monitoring, alert triage, investigation and incident-response activities.
  • Experience working with Microsoft Defender or comparable endpoint, identity, email and cloud-security technologies.
  • Practical exposure to vulnerability management, remediation tracking and security-posture reporting.
  • Familiarity with SIEM platforms, security-log analysis and query languages such as KQL would be beneficial.
  • Working knowledge of security frameworks and standards such as MITRE ATT&CK, CIS Controls or ISO 27001.
  • Microsoft Security Operations Analyst Associate certification is required or strongly preferred; CompTIA Security+, CySA+ or equivalent security certifications would be beneficial.
Other Requirements
  • Hybrid working model with regular in-office presence in Stellenbosch, based on team rhythms, collaboration needs and business requirements.
  • Ability to attend key planning sessions, stakeholder workshops and in-person team collaboration when required.
  • Reliable internet connectivity and a suitable remote-working setup for work-from-home days.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

XContent Business Solutions (Pty) Ltd • Stellenbosch

On-site
ZAR 400,000 - 550,000
Hybrid Security Operations Analyst - Defender & Sentinel
Hybrid Security Operations Analyst - Defender & Sentinel

XContent Business Solutions (Pty) Ltd • Stellenbosch

Hybrid
ZAR 400,000 - 550,000
Security Operations Engineer
Security Operations Engineer

Parvana • Cape Town

Hybrid
ZAR 600,000 - 900,000
Hybrid in-office / remote
Cyber Security Analyst
Cyber Security Analyst

Network Recruitment • Johannesburg

Hybrid
ZAR 600,000 - 900,000
Senior Associate Information Security Analyst
Senior Associate Information Security Analyst

Recruit-It • Gauteng

On-site
ZAR 900,000 - 1,300,000
Security Analyst
Security Analyst

Network Finance • Randburg

On-site
ZAR 420,000 - 660,000
Senior Information Security Operations Analyst
Senior Information Security Operations Analyst

Travelbyinvestec • South Africa

On-site
ZAR 900,000 - 1,250,000
L3 SOC Analyst - Cape Town
L3 SOC Analyst - Cape Town

Integrity360 • Cape Town

On-site
ZAR 600,000 - 800,000
Principal Cyber Security Specialist - Blue Team
Principal Cyber Security Specialist - Blue Team

Cyberlogic • Wes-Kaap

Hybrid
ZAR 900,000 - 1,800,000
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Jobless • Johannesburg

On-site
ZAR 600,000 - 900,000