L2 SOC Analyst - Cape Town or Johannesburg

Posted 15 Days Ago
Be an Early Applicant
Cape Town, Western Cape, ZAF
In-Office
Mid level
Security • Consulting • Cybersecurity
The Role
Conducts security alert triage, incident investigations, threat hunting, and root-cause analysis across client environments. The role supports incident response from detection through resolution, identifies vulnerabilities, improves detection rules and response procedures, and assists with workflow automation. Responsibilities also include critical incident reporting, client communication, and collaboration with detection and incident response teams. Candidates should have SOC or CSIRT experience, log investigation skills, networking knowledge, and familiarity with SIEM platforms such as Splunk, QRadar, or Elastic Stack.
Summary Generated by Built In

About Us

Integrity360 is a leading independent cybersecurity and PCI specialist operating across Europe, Africa, the Caribbean, and North America. The company has office locations in Ireland, the UK, Bulgaria, Italy, Sweden, Spain, Lithuania, Ukraine, Africa, the Caribbean, and Canada, supported by seven Security Operations Centres (SOCs) located in Dublin, Sofia, Madrid, Stockholm, Rome, Johannesburg and Cape Town.

With over 780 employees, including more than 585 dedicated cybersecurity professionals, Integrity360 delivers a full suite of professional, support, and managed security services. These span the complete cyber risk lifecycle, from identification and prevention to detection, response, and recovery. Integrity360 supports over 3000 mid-market and enterprise organisations across sectors including financial services, insurance, government, healthcare, retail, telecommunications, and utilities. 

At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you're ready to take your cyber security career to the next level, we’d love to hear from you. About This Role This is a fantastic opportunity for someone looking to advance their career in cybersecurity, particularly within the Blue Team arena. You'll be at the forefront of responding to and investigating malicious activity, triaging alerts, and helping customers navigate security incidents.

About This Role

This is a fantastic opportunity for someone looking to advance their career in cybersecurity, particularly within the Blue Team arena. You'll be at the forefront of responding to and investigating malicious activity, triaging alerts, and helping customers navigate security incidents.

Responsibilities: 

Incident Investigation:

  • Triage security alerts to assess if additional investigation is required.
  • Conduct thorough investigations to identify the root cause of incidents, collaborating with team members or escalating when necessary.
  • Ensure that incidents are communicated clearly and timeously with clients for effective resolution.
  • Be a contributor during cybersecurity incidents from detection to resolution, adhering to established protocols.

Threat Hunting:

  • Conduct threat hunting activities across assigned client environments to identify indicators of compromise (IOCs), suspicious behaviours, and potential threats.
  • Develop and execute intelligence-led threat hunting scenarios based on the latest threat actor activity, emerging threats, industry threat intelligence, and observed attacker tactics, techniques, and procedures (TTPs).

Process Improvement:

  • Regularly review and update incident response procedures to enhance efficiency and effectiveness.
  • Establish close alignment with the Detection team to analyze alert trends to refine detection rules to minimize false positives.

Efficiency Optimization:

  • Assist the Incident Response Team Leader to streamline response workflows through automation, orchestration and/or other innovative methods.
  • Establish methodologies to ensure that the alert queue is triaged effectively, allowing for appropriate actions taken on security incidents.

Incident Management:

  • Identify and document vulnerabilities in client systems during investigations, contributing to ongoing improvements in security posture.
  • Assist with critical incident report writing.

Client Communication:

  • Maintain clear, professional communication with clients throughout the incident lifecycle, ensuring transparency and client satisfaction.
  • Promote best practices within the team to consistently achieve positive outcomes for clients and stakeholders.

Desired Skills:

  • A minimum of 2 - 4 years of experience in cybersecurity, particularly in a technical role within a SOC, CSIRT, or similar environment.
  • Experience with conducting security related log investigations with utilising various log sources/security products.
  • Solid understanding of networking, with the focus being able to understand network related attacks.
  • Familiarity with SIEM technologies such as Splunk, QRadar, Elastic Stack, or equivalent.
  • Knowledge of the attack chain and critical incidents including experience with Digital Forensics and Incident Response is beneficial.

Qualifications/Certifications:

  • A bachelor’s degree in computer science, Information Technology, or similar credentials is highly advantageous.
  • Relevant certifications such Security+, PenTest+, Blue Team Level 1 or similar credentials are highly advantageous.

#LI-GB1

Skills Required

  • 2–4 years of cybersecurity experience in a technical SOC, CSIRT, or similar environment
  • Experience conducting security-related log investigations using various log sources and security products
  • Solid networking knowledge, particularly understanding network-related attacks
  • Familiarity with SIEM technologies such as Splunk, QRadar, Elastic Stack, or equivalent
  • Knowledge of the attack chain and critical incidents
  • Experience with digital forensics and incident response
  • Bachelor’s degree in computer science, information technology, or similar
  • Relevant certification such as Security+, PenTest+, Blue Team Level 1, or similar
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Dublin, County Dublin
358 Employees
Year Founded: 2005

What We Do

Integrity360 is one of Europe’s leading cyber security specialists operating from office locations in the UK, Ireland, Bulgaria and Sweden. The group provides a comprehensive range of professional, support and managed cyber security services that identify and assess, protect and prevent, detect and analyse and respond and recover cyber risks and threats. Working either independently or as an extension of a organisations own team Integrity360 strengthen security postures for both mid market and enterprise organisations across a wide range of sectors including financial services, insurance, government, healthcare, retail, telecoms and utilities. During June 2021 the company received a major strategic investment from leading London based private equity firm August Equity as part of a significant growth and expansion plan that will build the brand international With four Security Operation Centres, the company offers a complete end-to-end security services offering to its clients, covering their security from every angle. Its services include Managed Security, Cyber Security Testing, Incident Response, Security Integration and Cyber Risk & Assurance services. Its 300 clients can be found in all business verticals and include some of the largest and most well-known brands in the country. What sets Integrity360 apart is its excellent team of people that drive the business forward. The company was founded with a focus on technical expertise and that philosophy remains today. The skills and experience in the company are some of the greatest in the industry and clients remain with Integrity360 because they can rely on and trust them to go above and beyond to ensure their needs are met. Integrity360 is listed multiple time in the Gartner Market Guides for Managed Security Services.

Similar Jobs

TransUnion Logo TransUnion

Bilingual Consumer Admin II M

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
2 Locations
13000 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

HPE Networking Senior Presales Engineer

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
2 Locations
85422 Employees

CDW Logo CDW

Sales Support Associate

Information Technology
Hybrid
Cape Town, Western Cape, ZAF
15100 Employees

Morningstar Logo Morningstar

Infrastructure Engineer

Artificial Intelligence • Big Data • Enterprise Web • Fintech • Software • Financial Services
Remote or Hybrid
South Africa
11500 Employees

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account