About the job Cyber Security SOC Analyst
Cyber Security SOC Analyst
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Cyber Security Security Operations Centre (SOC) Analysts to monitor, detect, investigate and respond to cybersecurity threats across complex enterprise IT environments.
The successful candidates will be responsible for continuously monitoring security events, analysing suspicious activities, investigating security alerts and supporting the identification and containment of potential cybersecurity incidents.
This role requires strong hands-on experience with Security Information and Event Management (SIEM) platforms, Endpoint Detection and Response (EDR) technologies, security event analysis, threat detection and incident investigation.
The ideal candidates will have proven experience working within an enterprise Security Operations Centre or equivalent cybersecurity monitoring environment, with the ability to identify genuine security threats, distinguish false positives from actionable incidents and escalate critical security events appropriately.
Candidates should demonstrate strong technical knowledge of enterprise networks, operating systems, security monitoring technologies and common cyberattack techniques.
Key Responsibilities
Security Operations Centre Monitoring
- Monitor enterprise security systems, networks, endpoints, applications and cloud environments for potential cybersecurity threats.
- Analyse security alerts generated by SIEM, EDR, XDR, IDS/IPS, firewalls and other security monitoring technologies.
- Conduct continuous security event monitoring and identify suspicious or unauthorised activities.
- Investigate potential cybersecurity incidents and determine their severity, scope and business impact.
- Distinguish genuine security threats from false positives.
- Perform initial incident triage, classification and prioritisation.
- Escalate critical security incidents to incident response teams or senior cybersecurity specialists.
- Maintain accurate security monitoring records and incident investigation notes.
- Support continuous improvement of SOC monitoring processes and procedures.
- Work collaboratively with cybersecurity, infrastructure, networking and application teams.
Security Event Analysis and Investigation
- Investigate suspicious authentication attempts, unauthorised access and unusual network activity.
- Analyse system logs, endpoint telemetry, network traffic and cloud security events.
- Correlate security information from multiple monitoring platforms to identify potential threats.
- Investigate malware alerts, phishing incidents, suspicious processes and compromised accounts.
- Identify indicators of compromise and indicators of attack.
- Analyse suspicious activity involving privilege escalation, lateral movement and persistence techniques.
- Conduct preliminary investigations into potential data breaches and security policy violations.
- Document investigation findings and recommend appropriate remediation actions.
- Support incident responders with technical evidence and investigation findings.
Threat Detection and Security Analysis
- Monitor emerging cybersecurity threats, vulnerabilities and attacker techniques.
- Analyse threat intelligence and apply relevant indicators to security monitoring activities.
- Use the MITRE ATT&CK framework to understand and classify suspicious activity.
- Identify unusual patterns and anomalies within enterprise security logs.
- Support the development and refinement of SIEM detection rules and correlation searches.
- Identify gaps in security monitoring coverage and recommend improvements.
- Participate in threat hunting and proactive security investigations.
- Assist with identifying potential security control weaknesses.
- Support detection validation and continuous security monitoring improvements.
Incident Response and Escalation
- Perform initial response activities for suspected cybersecurity incidents.
- Follow established incident response playbooks and escalation procedures.
- Assess security incident severity and potential organisational impact.
- Support containment activities in collaboration with authorised technical teams.
- Escalate complex incidents requiring advanced investigation or forensic analysis.
- Maintain incident timelines and investigation records.
- Support incident response teams during major cybersecurity events.
- Participate in post-incident reviews and lessons-learned activities.
- Recommend improvements to incident detection and escalation procedures.
SIEM, EDR and Security Technology Operations
- Operate and monitor enterprise SIEM platforms.
- Investigate endpoint security alerts using EDR and XDR technologies.
- Analyse firewall, proxy, DNS, authentication and network security logs.
- Monitor security events across Windows, Linux and cloud environments.
- Support SIEM use-case development and alert tuning.
- Assist with security log source integration and monitoring coverage.
- Identify and report monitoring tool failures or gaps in security telemetry.
- Maintain SOC dashboards, investigation records and operational reports.
- Support security automation and incident response workflow improvements.
SOC Reporting and Documentation
- Maintain accurate records of security alerts, investigations and escalated incidents.
- Prepare security incident summaries and technical investigation reports.
- Produce SOC operational reports and security monitoring statistics.
- Document recurring threats, suspicious activities and security trends.
- Maintain SOC procedures, investigation guides and operational documentation.
- Support cybersecurity audits and security compliance activities.
- Provide recommendations to improve threat detection and SOC effectiveness.
- Participate in SOC knowledge-sharing and technical development initiatives.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Information Security, Network Engineering or a related discipline.
- Typically 3–5 years of relevant hands-on experience in cybersecurity monitoring, SOC operations, security event analysis or incident investigation.
- Proven practical experience working within an enterprise Security Operations Centre or equivalent security monitoring environment.
- Strong hands-on experience with at least one enterprise SIEM platform.
- Practical experience investigating security alerts and analysing security events.
- Familiarity with EDR, XDR, firewall and network security monitoring technologies.
- Strong understanding of cybersecurity threats, attack techniques and indicators of compromise.
- Experience conducting security incident triage, classification and escalation.
- Knowledge of Windows and Linux operating systems.
- Understanding of Microsoft Active Directory, authentication systems and identity-related security threats.
- Good understanding of TCP/IP networking, DNS, HTTP/HTTPS and common network protocols.
- Familiarity with the MITRE ATT&CK framework.
- Experience analysing security logs and correlating information from multiple sources.
- Understanding of incident response procedures and cybersecurity investigation principles.
- Familiarity with cloud security monitoring environments would be advantageous.
- Strong analytical, technical troubleshooting and documentation skills.
Technical Skills and Competencies
Security Operations Centre Operations
- SOC monitoring and operations
- Security alert investigation
- Security event triage
- Incident severity classification
- Threat detection
- Incident escalation
- Security monitoring procedures
- SOC dashboards and reporting
- Security incident documentation
- SOC operational metrics
- Security monitoring improvement
- Incident response support
Security Information and Event Management
Practical experience with one or more of the following platforms:
- Microsoft Sentinel
- Splunk Enterprise Security
- IBM QRadar
- Elastic Security
- ArcSight
- LogRhythm
- Google Security Operations
- Other enterprise SIEM platforms
Relevant competencies include:
- SIEM alert monitoring
- Security log analysis
- Event correlation
- Detection rule investigation
- SIEM query development
- Log source validation
- Alert tuning
- Security dashboard monitoring
- Threat intelligence correlation
Endpoint Detection and Response
Experience with relevant technologies such as:
- Microsoft Defender for Endpoint
- Microsoft Defender XDR
- CrowdStrike Falcon
- SentinelOne
- Palo Alto Cortex XDR
- Trend Micro endpoint security
- Other enterprise EDR and XDR platforms
Relevant competencies include:
- Endpoint alert investigation
- Suspicious process analysis
- Malware alert investigation
- Endpoint telemetry analysis
- Endpoint compromise identification
- Incident containment support
Network Security Monitoring
- TCP/IP networking
- DNS
- HTTP/HTTPS
- Firewalls
- IDS/IPS
- VPN security
- Proxy logs
- Network traffic analysis
- Network security event investigation
- Suspicious connection analysis
- Network-based indicators of compromise
- Wireshark
- Zeek or equivalent network monitoring technologies
Threat Detection and Investigation
- Indicators of Compromise (IOCs)
- Indicators of Attack (IOAs)
- Threat intelligence analysis
- MITRE ATT&CK mapping
- Malware alert investigation
- Phishing investigation
- Credential compromise detection
- Privilege escalation detection
- Lateral movement identification
- Suspicious authentication analysis
- Security event correlation
- Threat hunting fundamentals
Enterprise Infrastructure Security
- Windows Server
- Linux
- Microsoft Active Directory
- Microsoft Entra ID
- Enterprise networking
- Endpoint security
- Authentication and authorisation
- Identity and access management
- Server and workstation security
- Enterprise security architecture fundamentals
Cloud Security Monitoring
Familiarity with relevant cloud technologies would be advantageous:
- Microsoft Azure
- Microsoft 365 security
- Microsoft Entra ID
- AWS security monitoring
- AWS CloudTrail
- Azure Activity Logs
- Cloud identity security
- Cloud workload monitoring
- Cloud security event investigation
- Hybrid security monitoring
Scripting and Security Automation
Experience with one or more of the following would be beneficial:
- Kusto Query Language (KQL)
- Splunk Search Processing Language (SPL)
- PowerShell
- Python
- Bash
- Security log queries
- Security automation
- SOAR platforms
- Automated incident enrichment
- SOC workflow optimisation
Cybersecurity Frameworks and Standards
- MITRE ATT&CK
- NIST Cybersecurity Framework
- NIST SP 800-61 – Incident Response
- ISO/IEC 27001
- ISO/IEC 27035 – Information Security Incident Management
- CIS Critical Security Controls
- Cyber Kill Chain
- Security monitoring and incident response best practices
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- CompTIA Security+
- CompTIA CySA+
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- GIAC Security Essentials (GSEC)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified Ethical Hacker (CEH)
- Splunk Core Certified Power User
- Splunk Enterprise Security Certified Admin
- IBM QRadar certifications
- Certified Information Systems Security Professional (CISSP)
- Relevant SIEM, EDR, SOC or cybersecurity monitoring certifications
Key Personal Attributes
- Strong analytical and investigative abilities.
- Excellent attention to detail and technical accuracy.
- Ability to identify suspicious activity within large volumes of security events.
- Strong technical troubleshooting and problem-solving skills.
- Ability to work effectively under pressure during cybersecurity incidents.
- Sound judgement when prioritising and escalating security alerts.
- Excellent communication and stakeholder engagement skills.
- Strong technical reporting and documentation abilities.
- Ability to collaborate effectively with cybersecurity and infrastructure teams.
- Proactive approach to threat detection and security monitoring.
- High levels of confidentiality, accountability and professional integrity.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their practical SOC operations, SIEM monitoring, security event investigation and cybersecurity incident analysis experience, together with copies of relevant academic qualifications and professional certifications.
Candidates should specifically highlight:
- SOC environments in which they have worked.
- Their level of responsibility, such as Tier 1, Tier 2 or Tier 3 SOC Analyst.
- SIEM platforms they have used professionally.
- EDR, XDR and network security monitoring technologies they have worked with.
- Experience investigating and escalating cybersecurity incidents.
- Types of security alerts and threats they have personally investigated.
- Experience with threat intelligence, MITRE ATT&CK and security event correlation.
- Detection rules, SIEM queries or monitoring improvements they have developed.
- Cloud security monitoring and incident investigation experience.
- SOC reporting, incident documentation and security investigation responsibilities.
- Relevant cybersecurity, SIEM and SOC certifications.
Important: This is a specialist Cyber Security SOC Analyst opportunity requiring demonstrable hands-on experience in security monitoring, SIEM analysis and cybersecurity incident investigation. General IT support, network administration or theoretical cybersecurity knowledge without practical SOC or equivalent security operations experience will not be sufficient.
Please note: Specific project requirements, remuneration, employment arrangements, shift patterns, on-call expectations and working conditions will be confirmed during the recruitment process. The required SOC analyst seniority level will also be confirmed with the client.