About the position
ENVIRONMENT:
An innovative, End-to-end Cybersecurity firm based in Cape Town is seeking a strong technical L2 SOC Analyst / Cybersecurity Analyst to join its Cybersecurity team and support multiple client environments within its MSP/MSSP operation. This role will go beyond basic SOC alert monitoring. The successful candidate will independently investigate security alerts and incidents, analyse security telemetry, perform threat hunting, contribute to SIEM and detection improvements, and support a range of cybersecurity projects across the client base. You must be comfortable working across multiple technologies, clients and competing priorities and should be capable of working independently with limited supervision. Applicants will require Certifications such as Microsoft SC-200/Microsoft AZ-500/Microsoft SC-100/CompTIA Security+ with 2–4 years' practical cybersecurity / SOC experience & proficiency with Microsoft Sentinel, KQL, SIEM, EDR/XDR & a solid understanding of MITRE ATT&CK.
DUTIES:
- Investigate and analyse security alerts and incidents across multiple client environments.
- Perform L2 SOC investigations and determine the nature, severity and potential impact of security events.
- Work with Microsoft Sentinel and KQL for incident investigation, log analysis, threat hunting and detection development.
- Review, tune and improve SIEM detection rules and identify detection gaps.
- Contribute to MITRE ATT&CK mapping and detection coverage assessments.
- Conduct proactive threat hunting and contribute to monthly threat-hunting reporting.
- Analyse EDR/XDR alerts and endpoint security events.
- Investigate Microsoft 365, Entra ID, endpoint, email and network security events.
- Assist with vulnerability management, security hardening and remediation activities.
- Support SIEM onboarding, optimisation and cybersecurity projects.
- Produce technical and client-facing security reports and recommendations.
- Work across multiple clients and technologies while prioritising incidents and tasks according to risk and business impact.
- Maintain accurate technical documentation and investigation records.
Candidate Profile
The ideal candidate should be able to operate beyond:
Alert ? Basic Investigation ? Escalation
and instead demonstrate:
Alert ? Investigation ? Correlation ? Analysis ? Risk Assessment ? Response ? Documentation ? Improvement
They should be able to independently determine:
- What happened?
- Why did it happen?
- What is affected?
- What is the security risk?
- What should be done?
- Does the detection need to be improved?
REQUIREMENTS:
Qualifications -
- Relevant certifications are a MUST but hands-on technical experience will carry greater weight. Examples include:
- Microsoft SC-200
- Microsoft AZ-500
- Microsoft SC-100
- CompTIA Security+
- CompTIA Network+
- Fortinet certifications
- Relevant SIEM, SOC, threat-hunting or incident-response certifications
Experience/Skills -
- 2–4 Years' practical cybersecurity / SOC experience.
- Experience working in an MSP, MSSP or multi-client environment.
- Strong hands-on experience with Microsoft Sentinel.
- Practical KQL experience.
- SIEM alert investigation and incident response experience.
- EDR/XDR experience.
- Strong understanding of security monitoring and log analysis.
- Understanding of MITRE ATT&CK.
- Good understanding of networking, Windows and Microsoft security technologies.
- Strong analytical, problem-solving and documentation skills.
Advantageous –
- Microsoft Defender XDR / Defender for Endpoint.
- Sentinel detection engineering and Content Hub.
- Threat hunting.
- Detection rule development and optimisation.
- Power BI / Cybersecurity dashboards.
- Microsoft Entra ID security.
- Vulnerability Management / Tenable.
- Fortinet / FortiGate.
- Cisco security technologies.
- SentinelOne / Sophos.
- Security assessments and hardening.
- Experience with additional SIEM platforms.
ATTRIBUTES:
- Self-motivated and able to work independently.
- Strong analytical and investigative mindset.
- Comfortable troubleshooting unfamiliar security issues.
- Strong prioritisation and decision-making skills.
- Able to manage multiple clients and competing priorities.
- Strong written and verbal communication.
- Able to explain technical security issues clearly.
- Detail-oriented and methodical.
- Willing to continuously develop technical skills.
- Comfortable working under pressure.
- Takes ownership rather than relying on constant escalation.
Desired Skills: