
Security Analyst – Tier 2
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in South Africa.
• Support the SecOps Tech Lead and Head of Security Operations in the enhancement of SOC and SOAR functions.
• Oversee and respond to incidents and alerts within Microsoft Sentinel.
• Perform threat hunting using KQL and ensure incidents are resolved with thorough documentation.
• Aid in daily SOC operations involving personnel, processes, and technology.
• Guarantee compliance with client SLAs and uphold high levels of client satisfaction.
• Execute SOC and SOAR operational tasks, updating or closing work tickets with adequate technical details.
• Refer suspicious or malicious events to senior team members and incident response teams.
• Create and revise operational documentation.
• Guide and support junior team members.
• Serve as an operational point of contact during critical cybersecurity incidents.
• Assist in managing major incidents for Kocho and its clients.
• Offer support and guidance for monitoring tasks.
• Facilitate communications with stakeholders.
• Assist in the implementation of security measures and threat protection.
• Develop and maintain security tools and applications, including the Microsoft Sentinel and Microsoft Defender suite.
• Support analysts and clients with rules, policies, filters, use cases, and SOC tools.
• Implement service enhancements and lessons learned from incident reviews.
• Evaluate incident closures and post-incident reports.
• Create threat-hunting queries to detect undiscovered threats within client environments.
• Contribute to team growth through knowledge sharing, briefings, guides, incident scenarios, and playbooks.
• Stay up-to-date with security concepts, tools, and best practices.
• Participate in the complete lifecycle of client solutions and service offerings.
• Communicate technical solutions effectively to both technical and business audiences.
• Generate professional documentation, performance metrics, and client reports.
• Assist in the development of service offerings, procedures, techniques, and policies.
• Support the recruitment, training, and development of the security operations team.
• Encourage high-quality outcomes across all tasks.
• Proven experience in a security operations role.
• Strong understanding of IT Security and alignment with business objectives and information security.
• Familiarity with IT infrastructure, including Windows/Linux servers and firewalls.
• Technical comprehension of security components and their implications.
• Experience with or knowledge of Microsoft security stack technologies, including Microsoft Sentinel and Microsoft Defender suite.
• Solid working knowledge of various SOC tooling, including SIEM/SOAR.
• Good grasp of network methodologies and OSI Model layers.
• Understanding of network technologies such as routers, switches, firewalls, ID/IPS, WAF, and proxies.
• Experience operating at a technical level within a Security Operations service.
• Demonstrable skills in troubleshooting and resolving technical issues.
• Strong communication and report writing abilities.
• Knowledge of backup and disaster recovery processes.
• Advanced knowledge and experience with Microsoft Sentinel, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud.
• Proficiency in KQL (Kusto Query Language).
• Background in IT administration, preferably in a SOC environment.
• Experience with incident response and management, including thorough reporting and documentation.
• Ability to analyze complex data and security logs to pinpoint cybersecurity threats.
• Capable of communicating technical information to both technical and non-technical audiences.
• Willingness to work night shifts, irregular hours, and holidays as part of a 24/7 team.
• Effectiveness in using Kimble, Teams, SharePoint, and Office 365.
• ITIL V3 certified.
• CompTIA Security or equivalent certification.
• CompTIA Network or equivalent certification.
• Certifications SC-200, SC-300, SC-400.
• Blue Team Level 1/2 certification.
• Equal opportunity employer.
• Remote working options available.
• Chance to contribute to and enhance SOC & SOAR capabilities.
• Opportunities for knowledge sharing and professional development.
• Mentoring and support from fellow colleagues.
• Flexible collaboration spaces at the head office.
• Participation in technical workshops, client briefings, and service reviews.
NuHarbor Security
Lennar
Zup Innovation
NBCUniversal
Get handpicked remote jobs straight to your inbox weekly.