Integrity360

L2 SOC Analyst - Cape Town or Johannesburg

Integrity360  •  Cape Town, ZA (Onsite)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

About Us

Integrity360 is a leading independent cybersecurity and PCI specialist operating across Europe, Africa, the Caribbean, and North America. The company has office locations in Ireland, the UK, Bulgaria, Italy, Sweden, Spain, Lithuania, Ukraine, Africa, the Caribbean, and Canada, supported by seven Security Operations Centres (SOCs) located in Dublin, Sofia, Madrid, Stockholm, Rome, Johannesburg and Cape Town.

With over 780 employees, including more than 585 dedicated cybersecurity professionals, Integrity360 delivers a full suite of professional, support, and managed security services. These span the complete cyber risk lifecycle, from identification and prevention to detection, response, and recovery. Integrity360 supports over 3000 mid-market and enterprise organisations across sectors including financial services, insurance, government, healthcare, retail, telecommunications, and utilities.

At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you're ready to take your cyber security career to the next level, we’d love to hear from you. About This Role This is a fantastic opportunity for someone looking to advance their career in cybersecurity, particularly within the Blue Team arena. You'll be at the forefront of responding to and investigating malicious activity, triaging alerts, and helping customers navigate security incidents.

About This Role

This is a fantastic opportunity for someone looking to advance their career in cybersecurity, particularly within the Blue Team arena. You'll be at the forefront of responding to and investigating malicious activity, triaging alerts, and helping customers navigate security incidents.

Responsibilities

Incident Investigation:

  • Triage security alerts to assess if additional investigation is required.
  • Conduct thorough investigations to identify the root cause of incidents, collaborating with team members or escalating when necessary.
  • Ensure that incidents are communicated clearly and timeously with clients for effective resolution.
  • Be a contributor during cybersecurity incidents from detection to resolution, adhering to established protocols.

Threat Hunting:

  • Conduct threat hunting activities across assigned client environments to identify indicators of compromise (IOCs), suspicious behaviours, and potential threats.
  • Develop and execute intelligence-led threat hunting scenarios based on the latest threat actor activity, emerging threats, industry threat intelligence, and observed attacker tactics, techniques, and procedures (TTPs).

Process Improvement:

  • Regularly review and update incident response procedures to enhance efficiency and effectiveness.
  • Establish close alignment with the Detection team to analyze alert trends to refine detection rules to minimize false positives.

Efficiency Optimization:

  • Assist the Incident Response Team Leader to streamline response workflows through automation, orchestration and/or other innovative methods.
  • Establish methodologies to ensure that the alert queue is triaged effectively, allowing for appropriate actions taken on security incidents.

Incident Management:

  • Identify and document vulnerabilities in client systems during investigations, contributing to ongoing improvements in security posture.
  • Assist with critical incident report writing.

Client Communication:

  • Maintain clear, professional communication with clients throughout the incident lifecycle, ensuring transparency and client satisfaction.
  • Promote best practices within the team to consistently achieve positive outcomes for clients and stakeholders.

Desired Skills:

  • A minimum of 2 - 4 years of experience in cybersecurity, particularly in a technical role within a SOC, CSIRT, or similar environment.
  • Experience with conducting security related log investigations with utilising various log sources/security products.
  • Solid understanding of networking, with the focus being able to understand network related attacks.
  • Familiarity with SIEM technologies such as Splunk, QRadar, Elastic Stack, or equivalent.
  • Knowledge of the attack chain and critical incidents including experience with Digital Forensics and Incident Response is beneficial.

Qualifications/Certifications:

  • A bachelor’s degree in computer science, Information Technology, or similar credentials is highly advantageous.
  • Relevant certifications such Security+, PenTest+, Blue Team Level 1 or similar credentials are highly advantageous.

#LI-GB1

Integrity360

About Integrity360

Integrity360 is EMEA’s leading cyber security and PCI specialist, with offices across the UK and Ireland, Bulgaria, Italy, Sweden, Spain, Germany, Switzerland, France, Lithuania, Ukraine, Africa, and the Caribbean. The company operates six Security Operations Centres (SOCs) in Dublin, Madrid, Sofia, Stockholm, Naples, and Cape Town.

With over 700 employees and an expert team of over 500 dedicated cyber security professionals, Integrity360 offers a full suite of professional, support, and managed security services. These services cover every aspect of cyber risk management, from identification and prevention to detection, response, and recovery. Whether working independently or alongside an organisation's internal teams, Integrity360 enhances the security posture of mid-market and enterprise clients across sectors such as financial services, insurance, government, healthcare, retail, telecoms, and utilities.

Founded in 2005, Integrity360 received significant strategic investment from London-based private equity firm August Equity in June 2021. This partnership, led by IT and cyber industry veteran Ian Brown, who serves as CEO and Chairman, has fuelled the group’s rapid expansion across the UK, Nordics, continental Europe, and Africa as part of a long-term growth strategy.

Industry
IT & Software
Company Size
201-500 employees
Headquarters
Termini, 3 Arkle Rd, Sandyford, Sandyford Business Park, IE
Year Founded
2005
Social Media