Security Analyst – Tier 2

🔥 0 minutes ago

🇿🇦 South Africa – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔐 Security Analyst

👻 Ghost score 12%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Kocho

Kocho

201 - 500 employees

Founded 2001

🔒 Cybersecurity

🤝 B2B

Cybersecurity • B2B

Kocho is an award-winning UK-based Microsoft partner providing identity, security, and cloud managed and professional IT services to businesses. The company delivers identity management, managed security operations, threat detection and response, endpoint and network security, Azure and Microsoft 365 optimisation, and professional services including penetration testing, vulnerability management, and virtual CISO. Kocho helps organisations protect identities, secure data, and modernise cloud infrastructure while reducing costs and maintaining compliance.

📋 Description

• Assist the SecOps Tech Lead and Head of Security Operations in enhancing SOC and SOAR operations • Monitor and respond to incidents and alerts within Microsoft Sentinel • Conduct threat hunting using KQL and close incidents with comprehensive documentation • Support day-to-day SOC operations across personnel, processes, and technology • Ensure client SLAs are met and maintain high client satisfaction • Complete SOC and SOAR operational tasks and update or close work tickets with satisfactory technical details • Escalate suspicious or malicious events to senior team members and incident response personnel • Develop and update operational documentation • Mentor and support junior colleagues • Act as an operational point of contact during significant cybersecurity events • Assist with major incident handling for Kocho and clients • Provide support and guidance for monitoring activities • Support stakeholder communications • Assist with implementing security controls and threat protection • Build and maintain security tools and applications, including Microsoft Sentinel and Microsoft Defender suite • Support analysts and clients with rules, policies, filters, use cases, and SOC tooling • Implement service improvements and lessons learned following incident investigations • Review incident closures and post-incident reports • Develop threat-hunting queries to identify undetected threats on client estates • Contribute to team development through knowledge sharing, briefings, guides, incident scenarios, and playbooks • Maintain current knowledge of security concepts, tools, and best practices • Contribute to the full lifecycle of client solutions and service offerings • Communicate technical solutions to technical and business audiences • Produce professional documentation, performance reports, and client reports • Assist in developing service offerings, procedures, techniques, and policies • Assist in recruitment, training, and development of the security operations team • Promote high-quality outcomes across all work

🎯 Requirements

• Demonstrable experience operating within a security operations function • Strong IT Security knowledge and understanding of business objectives and information security • Experience with or understanding of IT infrastructure, including Windows/Linux servers and firewalls • Technical understanding of security components and their impact • Experience with or understanding of Microsoft security stack technologies, including Microsoft Sentinel and Microsoft Defender suite • Good working knowledge of multiple SOC tooling, including SIEM/SOAR • Good understanding of network methodologies and OSI Model layers • Good understanding of network technologies, including routers, switches, firewalls, ID/IPS, WAF, and proxies • Experience working at technical levels within a Security Operations service • Demonstrable ability to troubleshoot and fault-find technical issues • Good communication and report writing skills • Knowledge of backup and disaster recovery methodologies • Advanced knowledge and experience with Microsoft Sentinel, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud • Proficiency in KQL (Kusto Query Language) • Experience in IT administration, preferably within a SOC environment • Experience in incident response and handling, including detailed reporting and documentation • Ability to analyze complex data and security logs to identify cybersecurity threats • Ability to communicate in technical and non-technical terms • Willingness to work night shifts, unsociable hours, and bank holidays as part of a 24x7 team • Ability to work effectively with Kimble, Teams, SharePoint, and Office 365 • ITIL V3 • CompTIA Security or equivalent • CompTIA Network or equivalent • SC-200, SC-300, SC-400 • Blue Team Level 1/2

🏖️ Benefits

• Equal opportunities employer • Remote working arrangement • Opportunity to contribute to and develop SOC & SOAR capability • Knowledge sharing and professional development opportunities • Mentoring and support from colleagues • Flexible collaboration spaces at the head office • Participation in technical workshops, client briefings, and service reviews

Apply Now

Similar Jobs

🕒 June 25

Prime System Solutions

51 - 200

💼 Consulting

📣 Marketing

☁️ SaaS

Security Analyst designing and managing secure LAN/WAN architectures for enterprise clients. Involves threat detection, compliance, and cloud security tasks at a global scale.