- Salary
- $600k – $780k/yr
- Location
- ZA
- Type
- Full-time
- Department
- IT
- Seniority
- Mid
- Education
- Master
- Closing date
- Today
- Source
- Vincere
Description
Job Description Security Analyst Mid RSA 2026.pdf
This document is uncontrolled when not viewed on the company's ISMS SharePoint System
Page 1 of 2
Role: Mid-level Cyber Security Analyst Company: CyberFusion 3 Integrated Service (South Africa) Geographical responsibility:
Global. Based in the Cape Town (RSA) SOC, supporting clients in the UK and internationally.
Reports to: SOC Manager / Head of Security Operations UK, with regional matrix reporting to the Managing Director RSA.
Location and working arrangements
Based in the Cape Town SOC, with core hours aligned to UK business hours to maximise overlap with the UK team and client stakeholders. Participation in the 24x7 on-call rota shared between the UK and Cape Town teams; on-call is paid in line with company policy. Occasional travel to client sites or the UK office may be required.
Job Purpose The Cyber Security Analyst is a core member of a Microsoft-native SOC built on Microsoft Defender XDR and Microsoft Sentinel, providing security monitoring, investigation and response for dedicated and shared clients.
The role exists to triage and investigate alerts accurately and within SLA, carry out first-line containment and support incident response, contribute to detection tuning and improvement, and communicate clearly with clients and colleagues. The role holder works with direction from senior analysts, is expected to develop towards senior analyst level, and brings curiosity and initiative to every investigation.
Job Interactions
Internally: Senior analysts and the SOC Lead, fellow analysts across the UK and Cape Town teams, professional services and onboarding teams, and company Directors.
Externally: Client IT and security contacts through the agreed support channels, and client third parties (managed service providers, vendors) when coordinating remediation. Supports client onboarding and service reviews alongside senior analysts where required.
Job Responsibilities
Your responsibilities as a Cyber Security Analyst include but are not limited to: Monitoring, investigation and response
Monitor and triage alerts and incidents across Microsoft Defender XDR (Endpoint, Identity, Office 365, Cloud Apps), Microsoft Sentinel and Defender for Cloud within agreed SLAs, prioritising by severity and client impact. Investigate security events using Defender XDR incidents and device timelines, advanced hunting, Entra ID sign-in and audit logs, Purview Audit and Sentinel logs, documenting findings and evidence clearly in the ticketing system. Carry out first-line containment under agreed runbooks (device isolation, account disablement and session revocation, indicator blocking, mailbox remediation), escalating to senior analysts where required and supporting them through to resolution and post-incident review. Communicate with client stakeholders through the agreed support channels, providing clear status updates and remediation recommendations.
Detection improvement, threat hunting and intelligence Identify false positives and noisy rules, propose and implement tuning under senior review, and document the changes made. Write and adapt KQL queries for investigation and hunting, and contribute new analytics rules and custom detections mapped to MITRE ATT&CK with senior review. Perform threat hunts and act on threat intelligence (Microsoft Defender Threat Intelligence, threat analytics, NCSC advisories) with guidance from the senior team, converting findings into detections or hardening recommendations. Assist with data source onboarding and health checks (connector status, ingestion gaps, log quality).
Posture, automation and service delivery Review and report posture findings (Secure Score, Exposure Management, Entra ID and Intune configuration, Defender Vulnerability Management, Defender for Cloud recommendations) and contribute to client service reports.
This document is uncontrolled when not viewed on the company's ISMS SharePoint System
Page 2 of 2
Learn and contribute to automation (Sentinel automation rules, Logic Apps playbooks, Defender automated response) and help maintain workbooks and dashboards. Operate securely across multiple client tenants using the approved multi-tenant access model with least privilege, and support the onboarding of new clients.
Team, quality and development Maintain and improve runbooks and playbooks and follow the SOC's quality standards for investigations and tickets; take part in post-incident reviews and lessons learned. Support and coach Level 1 analysts and share knowledge with the team. Support the ISMS and audits, and handle client data in line with contractual, UK GDPR and POPIA obligations. Stay current on the threat landscape and the Microsoft security platform, and follow an agreed development plan towards senior analyst.
Skills and Experience
Essential A minimum of 2-3 years' experience in a SOC or security operations role, including hands-on experience with Microsoft Sentinel and Microsoft Defender XDR. Working KQL skills: writing and adapting queries for investigation, hunting and basic detection tuning. Working knowledge of the Microsoft security stack: Sentinel (incidents, analytics rules, workbooks), Defender for Endpoint, Defender for Identity, Defender for Office 365 and Defender for Cloud Apps. Microsoft Entra ID fundamentals (sign-in and audit logs, Conditional Access, MFA, risky users and sign-ins), with awareness of Intune device compliance and Purview Audit as they apply to investigations. Basic understanding of cloud security (Azure identity, logging and the shared responsibility model). Understanding of the Cyber Kill Chain, MITRE ATT&CK and common attack techniques: phishing and business email compromise, token theft, MFA fatigue, malicious OAuth apps, common malware types and lateral movement. Networking fundamentals (TCP/IP, DNS, HTTP, firewalls) and Windows and Linux knowledge sufficient to interpret logs and endpoint activity. Good written and verbal communication in English, able to write clear investigation notes and client updates. Good time management and the ability to prioritise across multiple clients; curiosity, initiative and a passion for security. Ability to work UK-aligned hours and participate in the 24x7 on-call rota.
Desirable (not essential) Experience in an MSSP or other multi-client environment. PowerShell or Python scripting, and Logic Apps or other automation experience. Experience with Defender for Cloud, Defender Vulnerability Management, Purview DLP, or Microsoft Sentinel in the Defender portal. Exposure to non-Microsoft tooling (for example Splunk, Elastic, Open Source, CrowdStrike or firewall platforms) or digital forensics basics. A BSc in Cyber Security, Computer Science or a related discipline.
Qualifications Essential Microsoft Certified: Security Operations Analyst Associate (SC-200), held or achieved within twelve months of starting.
Desirable SC-900, AZ-900, SC-300 or AZ-500; CompTIA Security+ or CySA+; CREST CPIA; GIAC GCIH or GSEC; or other recognised cyber security certifications.