- Location
- Cape Town · Cape Town, Western Cape, South Africa
- Workplace
- Remote, Hybrid, Onsite
- Department
- Cyber
- Experience
- 2+ years
- Source
- Greenhouse
Description
WHO WE ARE
S-RM is a global intelligence and cyber security consultancy. Since 2005, we’ve helped some of the most demanding clients in the world solve some of their toughest information security challenges.
We’ve been able to do this because of our outstanding people. We’re committed to developing sharp, curious, driven individuals who want to think critically, solve complex problems, and achieve success.
But we also know that work isn’t everything. It’s about the lives and careers it helps us build. We’re immensely proud of this culture and we invest in our people’s wellbeing, learning, and ideas every day.
We’re excited you’re thinking about joining us.
WORKING IN CYBER AT S-RM
Our Cyber Security division is the fastest-growing part of S-RM. The cyber sector is always evolving, and our Managed Services, Advisory, and Incident Response practices are in more demand than ever.
We’re building a team to meet this challenge. We’re quick to respond, innovate, and improve. We don’t get too hung up on hierarchy or bureaucracy. If your ideas are good enough, we’ll empower you to implement them. If you’re the best person to talk to a customer, you’ll get that opportunity, regardless of the title in your email signature. And when you need a hand, your team will always have your back.
We also don’t believe there’s a typical cyber security professional. We’ve built a team of intelligence analysts, technical specialists, software developers, investigators, risk managers, and more. You’ll always find a range of perspectives and expertise to help you learn and grow.
If that sounds like your kind of team, we’d like to hear from you.
THE ROLE
As a SOC Analyst you will deploy your cybersecurity expertise in a vital delivery role across our managed detection and response services.
In this role, you will use infrastructure and tools that power our Security Operations Centre (SOC) to deliver desired security outcomes for our managed services clients. The ideal candidate will have familiarity with security tools such as SIEM, SOAR, EDR, and other advanced technology. You will have a proven ability to respond effectively to security incidents. This hybrid role involves both remote work and some in-office presence for collaboration, teamwork and development.
- Monitor Security Events: Continuously monitor and analyse security alerts from EDR, SIEM and other security tools to detect suspicious activities or potential threats.
- Incident Response: Conduct investigations and respond to security incidents, executing containment, mitigation, and remediation steps as necessary.
- Threat Hunting: Proactively search for indicators of compromise (IoCs) and advanced threats within the environment, utilising both automated tools and manual analysis.
- Threat Detection: Use expertise to tune detection rules, automate workflows, and improve incident detection accuracy.
- Log Analysis: Perform in-depth log analysis from firewalls, endpoint protection platforms, and other solutions to investigate complex incidents.
- Threat Intelligence: Stay informed of emerging threats and collaborate with the threat intelligence team to enhance detection capabilities.
- Incident Reporting and Documentation: Ensure detailed documentation of incidents, responses, and resolutions to maintain a clear incident management process.
- Shift Work: Participate in a 24/7 shift rotation to ensure continuous security monitoring, including evening, night, and weekend shifts.
The role will be based in our Cape Town office and is hybrid with a minimum of two days a week in office.
WHAT WE ARE LOOKING FOR
The ideal candidate will have 2 to 3 years of experience working within a Security Operations Centre (SOC), with proven hands-on experience monitoring, investigating, and responding to security alerts and incidents.
They should be proficient in the use of XDR and SIEM platforms such as SentinelOne Singularity or Microsoft Sentinel, as well as Endpoint Detection and Response (EDR) solutions including SentinelOne, Microsoft Defender for Endpoint, or CrowdStrike.
The role requires experience in alert triage, event correlation, threat investigation, and incident escalation, supported by a solid understanding of common cyber threats, attack techniques, and security frameworks.
Candidates should also have working knowledge of Windows and Linux operating systems, Active Directory, and Microsoft 365 security monitoring, together with experience maintaining incident records, investigation notes, and operational documentation.
We are looking for the following experience and qualifications:
Minimum qualifications and experience
- Bachelor’s degree in cyber security, Information Security, Computer Science, or related discipline.
- Additional certifications such as:
- CompTIA CySA+
- SC-100/SC-200
- GIAC Certified Incident Handler (GCIH)
- Certified SOC Analyst (CSA)
- Blue Team / SOC Level 1 or 2 (CyberDefenders or THM)
Preferred qualifications and experience
- Experience with Security Orchestration, Automation and Response (SOAR) platforms.
- Exposure to cloud security monitoring, particularly Microsoft Azure and Microsoft 365.
- Previous experience supporting managed security services (MSSP/MDR) environments or multiple clients
- Experience developing detection rules, SIEM use cases, and security playbooks.
- Knowledge of threat intelligence feeds and MITRE ATT&CK framework mapping.
Successful candidates are also likely to show the following skills and competencies:
- Strong analytical and critical thinking skills
- Attention to detail and accuracy
- Effective decision-making under pressure
- Strong verbal and written communication skills
- Ability to work independently and within a team environment
- Time management and prioritisation skills
- Continuous learning mindset and adaptability
- Customer service and stakeholder engagement skills
- Professional integrity and confidentiality
- Ability to work shifts and participate in on-call rotations when required
- Strong organisational and investigative skills
- Resilience and the ability to perform in a fast-paced operational environment
The successful candidate must have permission to work in South Africa by the start of their employment.
OUR BENEFITS
We offer thoughtful, balanced rewards and support to help our people do their best work and live their lives outside it, this includes but is not exhaustive of:
- Holiday – 23 days per year increasing to 28 days (+1 day for every year you worked at S-RM, up to a maximum of 5 days) in addition to bank holidays
- Gap Cover policy – allowing you to bridge the gap between your medical bills and your medical aid cover.
- Life insurance – 4x annual salary
- Private pension – up to 7% contribution matched by the company
- Formalised Recognition programme
- Hybrid working and flexible working hours
Parental support:
- Fertility treatment leave – 5 days of leave per cycle of treatment per year
- Maternity leave – 26 weeks of full pay followed by 13 weeks of half pay (after 1 year at the company on the “qualifying week” = 15 weeks before a due date)
- Paternity leave – 6 weeks of full pay (after 1 year at the company on the “qualifying week” = 15 weeks before a due date)
Various Health and Medical Benefits including:
- Medical aid with Discovery Health for employee, partner, and children up to the cost of the Classic
Saver plan(taxable benefit) for you and your family;
- EAP (Employee Assistance Programme) for employees and immediate family, including counselling sessions
- Free access to the world-famous mindfulness app Headspace.
- Seasonal flu vaccination
- Eye tests and glasses reimbursement up to certain cost on an annual basis
To apply for this role, please submit an up-to-date CV through this link: Job Application for SOC Analyst at S-RM