L2 SOC Analyst - Cape Town or Johannesburg (On Site)

South AfricaSouth Africa·Cape TownFull-Timemid
Soc AnalystCybersecurity
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Incident Investigation: Triage security alerts to assess if additional investigation is required. Conduct thorough investigations to identify the root cause of incidents,

Requirements Summary

A bachelor’s degree in computer science, Information Technology, or similar credentials is highly advantageous. Relevant certifications such Security+, PenTest+,

Technical Tools
Soc AnalystCybersecurity

About Us

Integrity360 is a leading independent cybersecurity and PCI specialist operating across Europe, Africa, the Caribbean, and North America. The company has office locations in Ireland, the UK, Bulgaria, Italy, Sweden, Spain, Lithuania, Ukraine, Africa, the Caribbean, and Canada, supported by seven Security Operations Centres (SOCs) located in Dublin, Sofia, Madrid, Stockholm, Rome, Johannesburg and Cape Town.


With over 780 employees, including more than 585 dedicated cybersecurity professionals, Integrity360 delivers a full suite of professional, support, and managed security services. These span the complete cyber risk lifecycle, from identification and prevention to detection, response, and recovery. Integrity360 supports over 3000 mid-market and enterprise organisations across sectors including financial services, insurance, government, healthcare, retail, telecommunications, and utilities. 


At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you're ready to take your cyber security career to the next level, we’d love to hear from you. About This Role This is a fantastic opportunity for someone looking to advance their career in cybersecurity, particularly within the Blue Team arena. You'll be at the forefront of responding to and investigating malicious activity, triaging alerts, and helping customers navigate security incidents.


About This Role

This is a fantastic opportunity for someone looking to advance their career in cybersecurity, particularly within the Blue Team arena. You'll be at the forefront of responding to and investigating malicious activity, triaging alerts, and helping customers navigate security incidents. This role is predominantly on site.  


Responsibilities: 

Incident Investigation:

  • Triage security alerts to assess if additional investigation is required.
  • Conduct thorough investigations to identify the root cause of incidents, collaborating with team members or escalating when necessary.
  • Ensure that incidents are communicated clearly and timeously with clients for effective resolution.
  • Be a contributor during cybersecurity incidents from detection to resolution, adhering to established protocols.

 

Threat Hunting:

  • Conduct threat hunting activities across assigned client environments to identify indicators of compromise (IOCs), suspicious behaviours, and potential threats.
  • Develop and execute intelligence-led threat hunting scenarios based on the latest threat actor activity, emerging threats, industry threat intelligence, and observed attacker tactics, techniques, and procedures (TTPs).


Process Improvement:

  • Regularly review and update incident response procedures to enhance efficiency and effectiveness.
  • Establish close alignment with the Detection team to analyze alert trends to refine detection rules to minimize false positives.

 

Efficiency Optimization:

  • Assist the Incident Response Team Leader to streamline response workflows through automation, orchestration and/or other innovative methods.
  • Establish methodologies to ensure that the alert queue is triaged effectively, allowing for appropriate actions taken on security incidents.

 

Incident Management:

  • Identify and document vulnerabilities in client systems during investigations, contributing to ongoing improvements in security posture.
  • Assist with critical incident report writing.

 

Client Communication:

  • Maintain clear, professional communication with clients throughout the incident lifecycle, ensuring transparency and client satisfaction.
  • Promote best practices within the team to consistently achieve positive outcomes for clients and stakeholders.


Desired Skills:

  • A minimum of 2 - 4 years of experience in cybersecurity, particularly in a technical role within a SOC, CSIRT, or similar environment.
  • Experience with conducting security related log investigations with utilising various log sources/security products.
  • Solid understanding of networking, with the focus being able to understand network related attacks.
  • Familiarity with SIEM technologies such as Splunk, QRadar, Elastic Stack, or equivalent.
  • Knowledge of the attack chain and critical incidents including experience with Digital Forensics and Incident Response is beneficial.

 

Qualifications/Certifications:

  • A bachelor’s degree in computer science, Information Technology, or similar credentials is highly advantageous.
  • Relevant certifications such Security+, PenTest+, Blue Team Level 1 or similar credentials are highly advantageous.

 

#LI-GB1

Location & Eligibility

Where is the job
Cape Town, South Africa
On-site at the office

Listing Details

Posted
September 7, 2026
First seen
September 25, 2026
Last seen
September 30, 2026

Posting Health

Days active
4
Repost count
0
Trust Level
20%
Scored at
September 30, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

L2 SOC Analyst - Cape Town or Johannesburg (On Site)