Security Analyst- Tier 2
Kocho
South Africa
Opens the original listing in a new tab. Applying is free. Never pay money to get a job — report anyone who asks.
Cyber security roles across analyst, engineer and governance positions, concentrated in banking, telecoms and the large consultancies.
Job description
We are Kocho
Kocho is the original Microsoft identity‑centric security partner, delivering transformational services for UK organisations. We secure every identity first - then use that foundation to strengthen security, modernise cloud and apps, and keep everything running through leading managed services, and managed security operations.
You’ll be joining a team that’s trusted by organisations to deliver at scale. As an eight‑time Microsoft Partner of the Year winner and one Microsoft’s most decorated UK partners.
Our work speaks for itself:
- We’ve helped BT Group build multi‑brand customer authentication at scale (including migration of 25 million accounts).
- We supported Dojo’s cloud‑first identity modernisation (achieving 65% reduction in first‑line support tickets and £80k+ annual savings).
- And we enabled Hallo Healthcare’s secure cloud independence (migrating 17,000 identities and 180+ applications securely to zero trust architecture with Entra).
Our head office is in the heart of London, with additional offices in Cardiff and Cape Town, providing a comfortable working environment with flexible collaboration spaces. And we’re guided by our core values: Do What’s Right, Think Greater, and Better Together.
Kocho is an equal opportunities employer. We make recruitment decisions based on qualifications, skill set and experiences We consider all suitable candidates regardless of their age, sex, gender reassignment, race, pregnancy and maternity, religion or belief, marital status, disability or sexual orientation. This is mindset aligns with our company values as we understand that we are Better Together.
Job Purpose
This position will assist the SecOps Tech Lead and Head of Security Operations in enhancing the SOC & SOAR operations within Kocho. The Security Analyst will collaborate closely with other teams to build services and solutions that align with security best practices and client assurance requirements. This includes, but is not limited to, the use of Microsoft Sentinel, Microsoft Defender for Endpoint, Microsoft Defender for Cloud, and all other MS Security Stacks.
The primary responsibility of the Security Analyst role is to carry out operational SOC and SOAR activities as directed by the SecOps Tech Lead and Head of Security Operations. This includes monitoring and responding to incidents and alerts within Microsoft Sentinel. The successful candidate will leverage their KQL knowledge for threat hunting, effectively closing down incidents with comprehensive documentation. Furthermore, they will contribute to the efficient day-to-day operations of the SOC, focusing on personnel, processes, and technology. With a solid foundation in IT Administration and understanding of common corporate technologies, they will ensure all client SLAs are met, maintaining consistently high client satisfaction scores.
You will be required to, work with members of the Security Operations Team to ensure all SOC & SOAR operational tasks are completed on time and work tickets updated / closed with satisfactory technical details included, and where appropriate escalate suspicious / malicious events to senior team members and Kocho or client incident response personnel in order to identify, contain and remediate active threats. You will also be required to develop and update operational documentation, as necessary.
Security Analysts will be comfortable engaging at both technical and non-technical levels, contributing as required in technical workshops and client briefings / service reviews. You will be working in an incredibly passionate environment, with great people in which you can actively contribute to develop and deliver our SOC & SOAR capability.
Key responsibilities of the role:
Strategy and Leadership:
• This is not a leadership role though you will be expected to mentor and support Junior Colleagues.
Technical Specialism:
• Advanced knowledge and experience with Microsoft Sentinel, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud familiarity with other Microsoft Security Stacks and a broad understanding of common corporate technologies.
• Proficient in using KQL (Kusto Query Language) for threat hunting and other security-related investigations.
• Experience in IT administration, preferably within a Security Operations Center (SOC) environment.
• Experience in incident response and handling, including detailed incident reporting and documentation.
• Ability to analyze complex data and security logs to identify cyber security threats. Ability to communicate in both technical and non-technical terms, tailoring approach to the audience.
• Self-motivated learner of technologies and methodologies to support best practice.
• Actively contributing to knowledge sharing across the business.
Security Operations:
• Act as an operational point of contact during significant cyber security events.
• Assist in the support of major incident handling within the SOC, and where applicable for clients.
• Provide support and guidance regarding monitoring activities.
• Provide “hands on” resource, working to ensure Kocho objectives and client SLA targets are achieved.
• Provide input and support for stakeholder communication.
• Assist and support the implementation of security controls, threat protection etc. for both Kocho and it’s clients.
• Assist and support the building and maintenance of security tools and applications e.g., MS Sentinel, MS Defender for Endpoint, and the other elements of the Defender suite.
• Support other Security Analysts and clients on rules/policies/filters/use cases and SOC tooling.
• Assist with the implementation of improvements as part of on-going service enhancement or “lessons learned” following incident investigation (cause and affect).
• Assist in the review of incident closures, post incident reports and act upon improvements identified.
• Undertake Threat Hunting, to include the development of queries to support improvements to the identification of undetected threats on client estates.
• Contribute to team development through knowledge sharing, briefing and production of guides, incident scenarios and playbooks.
• Show flexibility in developing knowledge of supporting areas and performing their responsibilities during times of operational need.
• Maintain currency in relation to security concepts, tools and best practices.
• Willingness to work shifts (including unsociable hours and bank holidays) as part of 24x7 team working.
Business Operations:
• Ability to work effectively with internal systems such as Kimble, Teams, SharePoint and Office 365.
• Effective personal resource and time management with a commercial approach to work.
• Working remotely, or on site.
Delivery and KPIs:
• Contribute to the full lifecycle of client solutions and service offerings, from proposition through to delivery and support and maintenance.
• Communicate technical solutions in a clear, and concise approach for a variety of audiences from both a technical and business background.
• Contribute to well written and professional documentation, performance, and client reports.
• Assist the SecOps lead and Head of Security Operations in development of new service offerings, procedures, techniques, and policies.
• Assist in the recruitment, training, and development of the security operations team.
• Promoting and practicing high quality outcomes across all aspects of work.
Skills and experience:
Essential
• Demonstrable experience of operating within a security operati
Found on LinkedIn · Posted 1 weeks ago · Last checked Today
Good to know
What does this cyber security job pay?
The salary is not listed on this cyber security role. Check the source listing or ask the employer when you apply.
Do I need experience for cyber security jobs in Other?
This cyber security role may ask for some experience or a relevant qualification. Read the listing for the specifics before you apply.
How do I apply for this job?
Tap "Apply on LinkedIn" to open the original listing, where you can read the full description and apply directly. JobsZA never charges you to apply, and you should never pay money to get a job.
Found on LinkedIn · Posted 1 weeks ago
More cyber security and similar jobs in South Africa
Confidential · South Africa
Somewhere · South Africa