39 Security Monitoring jobs in South Africa
Security Monitoring and Triage Specialist â
Posted 1 day ago
Job Viewed
Job Description
- Educational qualifications
- 3 Year IT related Degree
- Relevant experience
- 5-10 years of experience working within security operations centre with focus on threat hunting and validation.
- The candidate must be well-versed in KQL and monitoring SIEM platforms.
- Required certifications
- SC-401
- CompTIA CySA+
- Key responsibilities
- Responsible for detecting, analysing and prioritising security incidents in real-time.
- Strong competence in using SIEM platforms and identifying false positives while escalating high priority threats.
Security monitoring and triage specialist â
Posted today
Job Viewed
Job Description
Incident Response Analyst
Posted today
Job Viewed
Job Description
S-RM Cape Town, Western Cape, South Africa
OverviewJoin to apply for the Incident Response Analyst role at S-RM .
Our Incident Response Senior Analysts are a critical part of our Cyber Security division's success. You will work across the full lifecycle of security incidents to help our clients respond and recover, including:
- Help manage incident response cases from first contact through to closure: you will be the primary point of contact for all internal and external stakeholders, accountable for delivery in time and on budget. You will coordinate non-technical workstreams and collaborate with technical leads where necessary.
- Overseeing host- and network-based incident response investigations: including triage, system recovery, technical evidence collection, and forensics, log, malware and root cause analyses.
- Developing plans, policies, and training: including incident management plans, table-top exercises, and response policies and procedures.
- Developing and sharing domain expertise: we will support you in growing your cyber expertise, including sharing it with the wider team through internal initiatives and programs.
- Contributing to business development: you will cultivate and manage close relationships with legal, insurance and other channel partners.
- Participating in an on-call rotation to provide 24X7X365 client incident coverage.
We nurture a culture of equality, diversity and inclusion and we are dedicated to developing a workforce that displays a variety of talents, experiences and perspectives.
What we offer / Responsibilities and opportunities- Variety of casework: no day will be the same. Our team responds to a huge variety of incidents for both public and corporate clients.
- Range of opportunities: you will have opportunities to broaden your security awareness into testing and advisory projects, in addition to deepening your incident response expertise.
- Flexible working practices: responding to incidents can be intense and high-pressure. We are mindful of our team's work/life balance and offer flexible working options to support your wellbeing.
- Experience in helping manage a range of cyber incidents in high-pressure situations;
- Excellent project management skills with a proven ability to manage multiple stakeholders;
- Experience presenting verbal updates or written reports to internal/external stakeholders with non-technical backgrounds is essential;
- Tertiary education (HBO/WO) or relevant industry experience
Relevant industry certifications are not required for this role. However, holding any of the following is beneficial: GCFE, GCFA, EnCE, CFSR, CISSP, GREM, CCNA, MCFE, OSCP, Network+ and Security+
Seniority level- Mid-Senior level
- Full-time
- Management and Manufacturing
- Security and Investigations
Referrals increase your chances of interviewing at S-RM by 2x
Get notified about new Incident Analyst jobs in Cape Town, Western Cape, South Africa.
#J-18808-LjbffrRemote Incident Response Tech Lead
Posted 7 days ago
Job Viewed
Job Description
We're also rapidly growing and are looking for top-tier candidates who share our four core values:
- We are team players, collectively working towards a common goal
- We work each day with a growth mindset focused on the success of our coworkers, clients, and the company
- We do the right thing with an honest and transparent approach that always puts our clients first
- We take ownership of our work, always seeing it through to completion
- We execute quickly and precisely, both internally and externally
As an Incident Response Tech Lead, you will provide excellence in high-touch technical management for incident response projects. This includes frequent technical and non-technical written, verbal and video call (Zoom / Teams) updates with all stakeholders on a project, both within FusionTek and externally. Throughout the day you'll be translating technology to clients who aren't always technical, so communication skills are paramount in this role. A broad technical foundation is also required, as you will make decisions on the client's recovery strategy and will serve as escalation point and subject matter expert to FusionTek team members and the client.
We are currently staffing the following shifts:
8:00 AM - 5:00 PM, Sunday to Thursday or Tuesday to Saturday - South Africa Standard Time (SAST)
2:00 PM - Midnight (Friday to Monday) - South Africa Standard Time (SAST)
Here's what you'll be doing:
- You'll primarily be focused on technical management of incident response recovery efforts from start to finish. This can include initial project mobilization, assignment and management of technical workstreams, and frequent client and vendor communication. There are daily (sometimes more frequently) updated calls and associated reporting
- Incident response projects can often begin over a weekend or outside of traditional business hours, and weekends are crucial recovery opportunities to lessen the impact the client feels as their businesses are often completely down
- You'll work through our ticketing system to document, track, and escalate project tasks and tickets, and you'll also work on our documentation platform to keep everything up to date along the way
- You'll serve as an escalation point on technical questions from other engineers and the client
- You'll be working with a team of intelligent people to deliver world-class service to our clients
- Excellent comprehension and communication in the English language
- Previous experience leading a technical team
- Knowledge of Office 365 / Azure cloud services
- Knowledge of Active Directory
- Knowledge of complex networking troubleshooting (VLANs/routing/subnetting/packet captures)
- Broad understanding of how operating systems work
- Knowledge of advanced OS troubleshooting (boot issues/corruption of profiles/OS files)
- Comfortable working in different OSs, both in CLI and GUI
- SQL DB knowledge is a plus
- Knowledge of advanced firewall configuration skills (creating and troubleshooting complex firewall policies/routes)
- Experience troubleshooting ingress/egress issues
- Comfortable working in diverse firewall UIs (SonicWall, Meraki, FortiGate, Cisco, WatchGuard, etc.)
- Strong comprehension of system architecture (i.e. - how servers' function, what their roles are, etc.)
- Understanding of the elements of network and system performance
- Time management skills are crucial to your success in this role
- Superb verbal and written communications skills are a must
- Demonstrated skillset through industry certifications or an agreed upon plan to obtain them
- Previous recovery / remediation experience a plus
- Experience working in a ticketing system is preferred, with Autotask experience a plus
At FusionTek, we truly believe that our people are our most valuable asset, which is why we're excited to provide:
- Salary range - R800,000 to R950,000
- Quarterly bonus eligibility based on specific KPIs
- Educational reimbursement for certification tests and company supplied training resources
Remote Incident Response Tech Lead
Posted 21 days ago
Job Viewed
Job Description
FusionTek is a Managed Security Service Provider (MSSP) with offices in multiple US locations and team members globally. We’re a tight-knit team of friendly, intelligent people focused on IT infrastructure management for small- to mid-sized businesses since 2007.
We’re also rapidly growing and are looking for top-tier candidates who share our four core values:
- We are team players, collectively working towards a common goal.
- We work each day with a growth mindset focused on the success of our coworkers, clients, and the company.
- We do the right thing with an honest and transparent approach that always puts our clients first.
- We take ownership of our work, always seeing it through to completion.
- We execute quickly and precisely, both internally and externally.
If this opportunity excites you, we invite you to continue reading! Join our team as an Incident Response Technical Lead. We’re seeking a proactive problem-solver with a client-focused attitude who thrives on tackling technical challenges.
As an Incident Response Tech Lead, you will provide excellence in high-touch technical management for incident response projects. This includes frequent technical and non-technical written, verbal and video call (Zoom / Teams) updates with all stakeholders on a project, both within FusionTek and externally. Throughout the day you’ll be translating technology to clients who aren’t always technical, so communication skills are paramount in this role. A broad technical foundation is also required, as you will make decisions on the client’s recovery strategy and will serve as escalation point and subject matter expert to FusionTek team members and the client.
We are currently staffing the following shifts:
8:00 AM – 5:00 PM, Sunday to Thursday or Tuesday to Saturday - South Africa Standard Time (SAST)
2:00 PM – Midnight (Friday to Monday) - South Africa Standard Time (SAST)
Here’s what you’ll be doing:
- You’ll primarily be focused on technical management of incident response recovery efforts from start to finish. This can include initial project mobilization, assignment and management of technical workstreams, and frequent client and vendor communication. There are daily (sometimes more frequently) updated calls and associated reporting.
- Incident response projects can often begin over a weekend or outside of traditional business hours, and weekends are crucial recovery opportunities to lessen the impact the client feels as their businesses are often completely down.
- You’ll work through our ticketing system to document, track, and escalate project tasks and tickets, and you’ll also work on our documentation platform to keep everything up to date along the way.
- You'll serve as an escalation point on technical questions from other engineers and the client.
- You’ll be working with a team of intelligent people to deliver world-class service to our clients
- Excellent comprehension and communication in the English language
- Previous experience leading a technical team
- Knowledge of Office 365 / Azure cloud services
- Knowledge of Active Directory
- Knowledge of complex networking troubleshooting (VLANs/routing/subnetting/packet captures)
- Broad understanding of how operating systems work
- Knowledge of advanced OS troubleshooting (boot issues/corruption of profiles/OS files)
- Comfortable working in different OSs, both in CLI and GUI
- SQL DB knowledge is a plus
- Knowledge of advanced firewall configuration skills (creating and troubleshooting complex firewall policies/routes)
- Experience troubleshooting ingress/egress issues
- Comfortable working in diverse firewall UIs (SonicWall, Meraki, FortiGate, Cisco, WatchGuard, etc.)
- Strong comprehension of system architecture (i.e. - how servers’ function, what their roles are, etc.)
- Understanding of the elements of network and system performance
- Time management skills are crucial to your success in this role
- Superb verbal and written communications skills are a must
- Demonstrated skillset through industry certifications or an agreed upon plan to obtain them
- Previous recovery / remediation experience a plus
- Experience working in a ticketing system is preferred, with Autotask experience a plus
At FusionTek, we truly believe that our people are our most valuable asset, which is why we’re excited to provide:
- Salary range – R800,000 to R950,000
- Quarterly bonus eligibility based on specific KPIs.
- Educational reimbursement for certification tests and company supplied training resources
Associate (Technical Lead), Incident Response, South Africa Cyber security Cape Town
Posted 27 days ago
Job Viewed
Job Description
S-RM is seeking an Incident Response Associate (Technical Lead) to join our Cyber Security team in South Africa.
Cybersecurity
Cape Town
Who we areS-RM is a global intelligence and cyber security consultancy. Since 2005, we’ve helped some of the most demanding clients in the world solve some of their toughest information security challenges.
We’ve been able to do this because of our outstanding people. We’re committed to developing sharp, curious, driven individuals who want to think critically, solve complex problems, and achieve success.
But we also know that work isn’t everything. It’s about the lives and careers it helps us build. We’re immensely proud of this culture and we invest in our people’s wellbeing, learning, and ideas every day.
We’re excited you’re thinking about joining us.
Our Cyber Security division is the fastest-growing part of S-RM. The cyber sector is always evolving, and our Advisory, Ethical Hacking, and Incident Response practices are in more demand than ever.
We’re building a team to meet this challenge. We’re quick to respond, innovate, and improve. We don’t get too hung up on hierarchy or bureaucracy. If your ideas are good enough, we’ll empower you to implement them. If you’re the best person to talk to a customer, you’ll get that opportunity, regardless of the title in your email signature. And when you need a hand, your team will always have your back.
We also don’t believe there’s a typical cyber security professional. We’ve built a team of intelligence analysts, technical specialists, software developers, investigators, risk managers, and more. You’ll always find a range of perspectives and expertise to help you learn and grow.
If that sounds like your kind of team, we’d like to hear from you.
The roleOur Incident Response Associates are a critical part of our Cyber Security division’s success.
As a Response Associate (Technical Lead), you will deploy your incident response expertise in a senior delivery role across our incident response services.
You will work across the full lifecycle of security incidents to help our clients respond and recover, including:
- Leading technical incident response from first contact through to closure: you will be the primary technical resource on response cases, deploying your own expertise and offering guidance to colleagues on your project team.
- Overseeing host- and network-based incident response investigations: including triage, system recovery, technical evidence collection, and forensics, log, malware and root cause analyses.
- Developing and sharing domain expertise: we will support you in growing your cyber expertise, including sharing it with the wider team through internal initiatives and programs.
- Participating in an on-call rotation to provide 24X7X365 client incident coverage.
Other features of the role include:
- Variety of casework: no day will be the same. Our team responds to a huge variety of incidents for both public and corporate clients.
- Range of opportunities: you will have opportunities to broaden your security awareness into testing and advisory projects, in addition to deepening your incident response expertise.
- Flexible working practices: responding to incidents can be intense, high-pressure work. We are mindful of our team’s work/life balance and offer flexible working options to support your wellbeing.
Candidates with the following qualifications and experience are likely to succeed as Incident Response Associates at S-RM.
That said, if you don’t think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box—we’re looking for candidates that are particularly strong in a few areas and have some interest and capabilities in others.
We nurture a culture of equality, diversity and inclusion and we are dedicated to developing a workforce that displays a variety of talents, experiences and perspectives.
- Experience: 5+ years’ experience in a technical cyber security role. Direct experience working in an incident response team is beneficial but not essential.
- Approach: an investigative mindset. You should be comfortable solving problems with limited information and guidance.
- Threat intelligence: some demonstrable knowledge of cyber threat actors, and their tactics, techniques, and procedures.
- Skillset: you should be comfortable using scripting to solve cyber security problems and ideally be able to demonstrate an interest in doing so, e.g. through your own research projects or prior experience.
- Communication: you should be able to communicate your technical findings for a non-technical audience in a professional setting.
- Qualifications: relevant industry certifications are not required for this role. However, holding any of the following is beneficial: GCFE, GCFA, EnCE, CFSR, CISSP, GREM, CCNA, MCFE, OSCP, Network+ and Security+
The successful candidate must have permission to work in South Africa by the start of their employment.
We offer thoughtful, balanced rewards and support to help our people do their best work and live their lives outside it, this includes but is not exhaustive of:
- 23 days holiday per year in addition to public holidays (+1 day for every year of service up to a maximum of 30 days in total);
- Hybrid working and flexible working hours;
- Matching pension contribution up to 7% (up to a maximum of 14% combined), and financial education;
- Life Insurance 4X annual salary.
Parental Support:
- Fertility treatment leave – 5 days of leave per cycle of treatment per year;
- Maternity leave – 26 weeks of full pay followed by 13 weeks of half pay;
- Paternity leave – 6 weeks of full pay.
Various Health and Medical Benefits including:
- Medical Aid (taxable benefit) for you and your immediate family;
- EAP program for you and your immediate family;
- Free access to the world-famous mindfulness app.
Associate (technical lead), incident response, south africa cyber security cape town
Posted today
Job Viewed
Job Description
Be The First To Know
About the latest Security monitoring Jobs in South Africa !
Associate (technical lead), incident response, south africa cyber security cape town
Posted today
Job Viewed
Job Description
Security Analyst
Posted 1 day ago
Job Viewed
Job Description
- Matric Certificate with Maths
- B Com in Accountancy or equivalent
- JDE Common Foundation
- JDE Technical Foundation
- AllOut Security Certification
- CNC Certification (advantageous)
- AS/400 CL Programming
- PRINCE2 / Project Management Certification
- Business or Systems Analysis Certification
- ITIL or COBIT Framework knowledge.
- Ten (10) + years in IT, with at least 5 years in JD Edwards E1 and World (Functional and Technical)
- Experience with AllOut Security administration
- ERP System experience: JD Edwards (mandatory), SAP or Navision (advantageous)
- Deep knowledge of Active Directory, QlikView, and vulnerability management
- Experience managing security frameworks on AS/400 systems;
- CNC and JDE deployment management
- Business analysis, project implementation, and end-user training
- Knowledge of compliance standards (SOX, King IV);
- Process mapping and documentation (Visio, Lucidchart, etc.)
- Report development and analytics (QlikView, SQL, etc.).
- Design and maintain system security protocols (JDE E1 and World)
- Administer and configure AllOut Security, ensuring segregation of duties and audit readiness
- Monitor and maintain integrations and support for various systems connected to JD Edwards
- Perform system analysis, vulnerability assessments, and conduct internal audits in alignment with King III/IV and SOX
- Lead and support audits, risk assessments, and disaster recovery processes
- Manage user roles, responsibilities, and access rights across systems
- Support CNC, AS/400 system management, and I-series server operations
- Write, update, and maintain technical documentation and user procedures
- Lead incident responses, forensic analysis, and investigations of breaches
- Train and support end-users and teams across departments;
- Provide help desk support and develop end-user documentation
- Drive and support security awareness campaigns
- Proactively identify areas of process and security improvement
- Attend to audit queries as and when required
- Perform ad hoc duties as and when required within reasonable job scope.
Cyber Security Analyst
Posted today
Job Viewed
Job Description
InfyStrat is seeking a motivated Cyber Security Analyst to join our team and contribute to our mission of safeguarding our digital assets and infrastructure. In this role, you will monitor, detect, and respond to security threats, vulnerabilities, and incidents across our systems. You'll perform risk assessments, analyze security breaches, and provide remediation recommendations while collaborating with various teams to enhance our security posture. This is a fantastic opportunity to grow your skills in a fast-paced environment while playing a critical role in protecting our organization from cyber threats.
Key Responsibilities:- Monitor security alerts and events from various sources, including SIEM tools, to identify and respond to security threats.
- Conduct thorough investigations of security incidents, documenting findings and coordinating response actions.
- Assist in the development and implementation of security policies, procedures, and guidelines to protect sensitive information.
- Perform vulnerability assessments and penetration testing to identify security weaknesses.
- Analyze trends and patterns in security incidents and provide recommendations for improving defense mechanisms.
- Stay updated on the latest cybersecurity threats, vulnerabilities, and best practices.
- Work with IT and development teams to ensure secure configurations and practices across all systems.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 2+ years of experience in cybersecurity, information security, or a related role.
- Strong understanding of security principles, concepts, and technologies.
- Experience with security monitoring tools, SIEM platforms, and incident response procedures.
- Familiarity with network security, firewalls, intrusion detection/prevention systems, and secure coding practices.
- Knowledge of security frameworks and regulatory standards (e.g., NIST, ISO 27001, GDPR).
- Strong analytical and problem-solving skills, with attention to detail.
- Excellent communication skills to effectively collaborate with cross-functional teams.
- CERT, CISSP, CISM, or equivalent security certifications are a plus.