Security Engineer L1 - Umhlanga
First Technology
Umhlanga, KwaZulu-Natal
Opens the original listing in a new tab. Applying is free. Never pay money to get a job — report anyone who asks.
Cyber security roles across analyst, engineer and governance positions, concentrated in banking, telecoms and the large consultancies.
Job description
Role and Responsibilities
Security Monitoring and Alert Triage:
- Monitor security event logs and alerts generated by security tools such as SIEM, IDS/IPS and firewall logs.
- Analyze alerts to determine their severity and relevance to the client’s security posture.
- Perform initial triage of security events to differentiate between false positives, true positives or any other possible security incidents.
- Communicate with IT Management or end-users where necessary to perform troubleshooting / investigation.
Incident Detection and Response:
- Investigate and analyze security incidents detected through monitoring tools.
- Follow documented procedures for incident handling and escalation, ensuring timely response and resolution within SLA.
- Coordinate with other teams within the SOC or across the organization to contain and mitigate security incidents.
Threat Intelligence Analysis:
- Stay updated with the latest cybersecurity threats, vulnerabilities, and attack techniques.
- Analyze threat intelligence data to identify potential risks to client’s organization infrastructure and systems.
- Utilize threat intelligence to enhance security monitoring and incident response capabilities.
Reporting and Documentation:
- Generate regular and monthly reports on security events, incidents, systems and trends for management and stakeholders.
- Maintain consistent ticket management and accurate documentation, for security incidents and alerts, including their timelines, actions taken, recommended remediation, and evidence for future reference and improvement.
Vulnerability Management:
- Assist in vulnerability scanning and assessment activities to identify weaknesses in the organization's systems and applications.
- Collaborate with the vulnerability management team to identify, prioritize, report and where necessary remediate, vulnerabilities within established timelines.
Anti-Virus Management:
- Monitor anti-virus and endpoint protection systems for malware detections and alerts.
- Investigate and respond to malware incidents, including malware analysis and containment measures.
- Coordinate with the IT team to ensure proper configuration and updates of anti-virus software, policies and management platforms.
Additional Duties:
- Assist in the maintenance and optimization of SOC tools and technologies.
- Participate in security awareness training and initiatives.
- Collaborate with other teams within the cybersecurity function, such as threat hunting and forensics, for proactive security measures.
- Participate in on-call rotations for after-hours incident response and support.
Note: The Level 1 SOC Analyst may also be required to perform other duties as assigned, depending on the specific needs and priorities of the organization's security operations. This could include involvement in projects related to security architecture, compliance audits, or emerging security technologies.
Soft Skills and attributes
- Security Engineer L1 must be able to demonstrate the following:
-
- Ability to be self-managed and work independently, or as part of a team
- Excellent communication skills
- Attention to detail
- Research new technologies and techniques used in the cyber security industry
- Keen analytical ability related to the diagnosis of policy violations and their impact / risk within the monitored environment
- Consistent, prompt delivery in often common or repetitive tasks
- Escalate, but maintain visibility of, suspected threats beyond current technical ability
- Fundamental understanding of technologies and concepts involved in security monitoring (Active Directory, Firewalls, Anti-Virus / EDR and basic Networking principles)
- Ability to multi-task and keep track of, and manage expectations with regards to multiple security alerts on a daily basis
- Keen interest in finding the root cause of security incidents or alerts
- Fundamental understanding of Microsoft & 3rd Party Patch Management concepts
- Ability to utilize the full capability of the SIEM platform
- Ability to be self-managed and work independently, or as part of a team
Qualifications and Education Requirements
- Matric is essential
- S+ or equivalent certification
- Bachelor’s degree in Computer Science or Information Technology Diploma (Beneficial)
Preferred Skills
- Should have proven excellence as a Service Desk Engineer or in another relevant position
Found on Indeed · Posted 5 days ago · Last checked Today
Good to know
What does this cyber security job pay?
The salary is not listed on this cyber security role. Check the source listing or ask the employer when you apply.
Do I need experience for cyber security jobs in Umhlanga?
This cyber security role may ask for some experience or a relevant qualification. Read the listing for the specifics before you apply.
How do I apply for this job?
Tap "Apply on Indeed" to open the original listing, where you can read the full description and apply directly. JobsZA never charges you to apply, and you should never pay money to get a job.
Found on Indeed · Posted 5 days ago
More cyber security and similar jobs in Umhlanga
Korakhoa Solutions · Umhlanga, KwaZulu-Natal
Confidential · Umhlanga, KwaZulu-Natal
Growth Resourcing · Umhlanga, KwaZulu-Natal
Confidential · Umhlanga, KwaZulu-Natal