Senior Security Analyst
Interfront SOC Ltd.
2026/08/27 Somerset West
Job Reference Number: Recruit254
Department: ICT & DevOps
Business Unit:
Industry: Information Technology
Job Type: Permanent
Positions Available: 1
Salary: Market Related The Analyst is responsible for safeguarding the organisation's information assets, systems, applications, and infrastructure through proactive security monitoring, risk management, security engineering, incident response, vulnerability management, and security governance. The role combines operational cybersecurity, security architecture and security engineering responsibilities.
Job Description
Security Operations and Monitoring
- Monitor security events across infrastructure, cloud platforms, endpoints, networks and applications.
- Investigate security alerts and incidents.
- Perform threat hunting and root cause analysis.
- Maintain and enhance SIEM and security monitoring capabilities.
- Coordinate incident response activities and post-incident reviews.
- Develop and maintain security playbooks and response procedures.
Vulnerability Management
- Manage vulnerability scanning programmes.
- Analyse vulnerability assessment results.
- Coordinate remediation efforts with ICT teams.
- Validate remediation activities.
- Produce regular vulnerability and risk reports.
- Establish risk-based prioritisation of vulnerabilities.
Security Engineering
- Design and implement security controls across Microsoft 365, Azure, Active Directory / Entra ID, Linux and Windows servers, network infrastructure and DevOps platforms.
- Implement and maintain multi-factor authentication, Privileged Access Management, Endpoint Detection and Response, Data Loss Prevention and security automation solutions.
- Evaluate and implement new security technologies.
Cloud Security
- Secure Azure cloud environments.
- Review cloud configurations and architecture.
- Conduct cloud security assessments.
- Implement Microsoft security best practices.
- Support Zero Trust initiatives.
Governance, Risk and Compliance
- Maintain cybersecurity risk registers.
- Conduct risk assessments.
- Support internal and external audits.
- Assist with policy and standard development.
- Support compliance requirements including POPIA, CIS Controls, and regulatory and client requirements.
Security Architecture
- Review and approve security designs.
- Assess new solutions and projects for security risks.
- Define security standards and baselines with Team Lead and Line Manager.
- Develop secure architecture patterns with Team Lead.
Security Awareness
- Promote security awareness initiatives.
- Conduct security training.
- Guide technical and business teams.
- Support organisational cyber resilience programmes.
DevSecOps
- Support secure software development practices.
- Review security testing and code scanning.
- Assist development teams with remediation activities.
Closing date: 11th of September 2026
Vacancy type: Permanent
Hybrid working conditions
Vacancy is open to people with disabilities.
Job Requirements
Qualifications
Minimum
- Matric with 10 years' work experience/or a bachelor’s degree or National Diploma in Information Security, Computer Science, Information Technology, Engineering or analytical related field.
Preferred Certifications
- CISSP
- CISM
- CompTIA Security+
- Microsoft Security certifications
- Microsoft Azure Security Engineer Associate (AZ-500)
Experience
Required
- Seven or more years of ICT experience.
- Five or more years of cybersecurity experience.
- Experience managing enterprise security technologies.
- Experience in incident response and threat investigation.
- Experience with vulnerability management programmes.
- Experience securing cloud platforms.
- Experience working within regulated environments.
Preferred
- Experience with the Microsoft security stack.
- Experience with DevSecOps practices.
- Experience with SIEM and SOAR platforms.
- Experience with Zero Trust architecture.
Technical Skills
Security Technologies
Microsoft Defender suite, Zabbix, Vulnerability management tools, Privileged Access Management solutions, Email security platforms, Data Loss Prevention solutions, Identity Access Management, Endpoint Management, Certificate Authority.
Infrastructure
Azure, Microsoft 365, Active Directory, Entra ID, Windows Server, Linux, VMware.
Networking
TCP/IP, Firewalls, IDS/IPS, VPN technologies, Network segmentation, ZTNA technologies (Netskope).
Automation and Scripting
PowerShell, Python, Bash, REST APIs, Security automation.
Behavioural Competencies
- Analytical thinking
- Problem solving
- Risk-based decision-making
- Attention to detail
- Accountability
- Communication skills
- Stakeholder management
- Teamwork and collaboration
- Customer focus
- Continuous learning
- Integrity and professionalism
Key Performance Indicators
- Reduction in critical vulnerabilities.
- Incident response service-level adherence.
- Security control effectiveness.
- Completion of risk assessments.
- Audit finding remediation rate.
- Security awareness participation rates.
- Compliance maturity improvements.
- Security monitoring coverage.