About the job
We are recruiting a Senior Security Analyst [SOC] for a permanent opportunity.
Our ideal candidate must be willing to work standard 8 hours a day 5 days a week, Standby will be required overtime will be expected as well.
Qualification Required
    Grade 12
    Industry recognized (vendor neutral) security certification (e.g. CISSP, CEH, Security+, GIAC, etc.)
Preferred Qualification
    Hold an industry recognized (vendor neutral) security certification (e.g. CISSP, CEH, Security+, etc.)
    Degree (or equivalent) in Information Technology/Security, Engineering or related field of study preferred (alternatively an equivalent combination of education and experience).
    3 to 5 years in a hands-on security role, with a strong background in security tools including but not limited to firewalls, IDS/IPS, proxy servers and endpoint protection
    Holds a recognized SIEM Tool Certification
Experience Required
    2+ Years of experience with Information Security with experience in a SOC environment, with demonstrable expertise in SIEM (Log Point, Q Radar, Splunk McAfee or Arc Sight
    5+ Years of experience in an operations focused information security role
Duties/Responsibilities
    Monitor, Manage and configure of Security Tools
    Monitor User, Network, Threat and other events from security tools to identify abnormal activity indicating security incidents
    Review and correlate incident information to determine and assess their urgency and impact
    Perform Threat Intel Research and understand current Cybersecurity Threats, Tactics and techniques
    Establish a detailed understanding of client's infrastructure
    Establish a detailed understanding of clients incidence response processes
    Research and understand and stay abreast with the Mitre Attack Framework
    Create and update Security incidents in ITSM platform with detailed information of logs relevant to the incident
    and track incidents and requests based on analysis results and incident response updates
    Escalate validated and confirmed Incidents to TIER 2 and designated incident response teams
    Work Closely with other security teams and designated incident response teams
    Create client request for information elements and reports
    Identify gaps and/or omissions in security detection and posture.
    Provide input into Run-book and playbook development
    Assist in automation of response and remediation processes.
    Support and assist senior analysts
Work Environment
    Security Operations Centre
Physical Demands
    Office Based in the Security Operations Centre
    Ad-Hoc Remote support
Travel
    Potential travel after hours/weekends for breach incidents
Desired Skills
    Systems Analysis
    Complex Problem Solving
    Programming
    C#
    Java
    SQL
    HTML