The posting
Key Responsibilities
- Continuously monitor, analyse, triage and close security events, alerts and requests received from the managed SOC, security systems and users.
- Support the Incident Manager and relevant stakeholders in investigating, containing, remediating and recovering from security incidents to minimise business impact.
- Enhance SOC detection and response playbooks, develop new incident-response procedures, and maintain clear processes for escalation, communication, evidence collection and documentation.
- Use analytical and data-visualisation tools to automate analysis, derive insights from large datasets, correlate information across SIEM and other data sources, and investigate anomalous activity against established baselines to determine root cause.
- Apply AI-driven and machine-learning capabilities, where appropriate, to support real-time security investigations, threat triage, containment and remediation, escalating issues when required.
- Apply ethical-hacking knowledge to identify potential threats and vulnerabilities and recommend appropriate remediation measures.
- Perform digital-forensics analysis of security events and alerts while following established evidence-handling and chain-of-custody practices.
- Apply reverse-engineering techniques, where required, to understand software behaviour and support malware analysis.
- Develop security-monitoring reports, metrics and dashboards for asset owners and management.
- Stay current with emerging cyber threats, vulnerabilities, attack techniques and industry developments, and translate relevant intelligence into detection and response improvements.
- Participate in cybersecurity exercises, including cyber-range simulations and business continuity exercises.
Looking for:
- At least 3+ years of hands-on information-security experience in a SOC analyst, incident-response analyst, incident-handler or comparable role.
- Strong hands-on cybersecurity experience with enterprise SIEM platforms, such as Google Security Operations SIEM, together with a sound understanding of the cyber kill chain, tactics, techniques and procedures (TTPs), threat intelligence and malware triage
- Ability to analyse large datasets and packet-level data, operate network and endpoint security technologies, including NIDS/NIPS, firewalls, HIPS, proxies, anti-malware tools, vulnerability scanners and interpret the security events they generate.
- Strong understanding of common attacks targeting systems, networks and applications.
- Strong knowledge of internet infrastructure, networking and network security, including DNS, DHCP, firewalls, WAF, IDS/IPS, VPN, advanced persistent threats and TCP/IP protocols.
- Relevant industry certifications, such as Certified SOC Analyst (CSA), CISSP, CEH, GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH), or equivalent, are preferred.
- Strong analytical and problem-solving skills, with a self-motivated, detailoriented and collaborative approach.
- Malware triage and analysis capability is an advantage.
- Willingness to learn and contribute effectively in a collaborative team environment.
- Ability to remain composed, prioritise effectively and work under pressure during cyber security incident investigation and response.
- Good interpersonal, written and verbal communication skills.



