Monitor, investigate, and respond to security alerts across EDR, MDR, and related security platforms.
Perform triage, analysis, and validation of security events and suspicious activities.
Support incident response efforts, including remediation coordination and follow-up.
Manage security incidents through to resolution, ensuring accurate documentation and effective stakeholder communication.
Contribute to the ongoing development and maturity of the cpompanies managed security services.
Vulnerability Management & Security Enhancement
Analyse vulnerability data and prioritise remediation activities based on risk.
Coordinate and drive remediation efforts across technical teams.
Identify recurring security weaknesses and recommend practical improvements.
Present security risks, vulnerabilities, and remediation progress to internal stakeholders.
Participate in security reviews, governance, and council meetings.
Maintain ongoing visibility of organisational security risks.
This role places a strong emphasis on identifying vulnerabilities, ensuring timely remediation, and continuously improving the organisation's overall security posture.
Microsoft 365 Security
Research, recommend, and implement Microsoft 365 security enhancements.
Review identity security, authentication controls, and access management practices.
Assist with investigations relating to Microsoft 365 security incidents and events.
Support the optimisation of tenant security configurations in line with industry best practices.
Security Tools & Automation
Assist with the implementation, optimisation, and day-to-day management of:
Managed Detection and Response (MDR) solutions
Endpoint Detection and Response (EDR) platforms
Privileged Access Management (PAM)
Security monitoring tools
Internal security automation initiatives
Collaborate closely with development and infrastructure teams to enhance security visibility and automation.
Contribute to the development of scalable security processes, workflows, and operational efficiencies.
The clients has made significant investments in security tooling, automation, internal RMM capabilities, and PAM development. This role will be instrumental in maximising the value and effectiveness of these platforms.
Cross-Functional Security Collaboration
Serve as a security resource across all technical departments.
Provide security guidance during infrastructure, networking, desktop, and software initiatives.
Assist technical teams in identifying security risks and implementing practical mitigation strategies.
Promote security awareness and best practices throughout the organisation.
Work collaboratively with desktop, network, infrastructure, and development teams to strengthen the overall security posture.
Process Development & Continuous Improvement
Help define, document, and improve security-related operational processes.
Develop dashboards, reporting, and visibility into the organisation's security posture.
Contribute to automation initiatives that enhance operational efficiency.
Assist in building scalable security frameworks as the companies security services continue to evolve.
This position includes ownership of key security processes and continuous improvement initiatives.
Technical Experience Required
Strong experience in some or all of the following areas:
Security Operations
Vulnerability Management
EDR and MDR Platforms
Microsoft 365 Security
Identity and Access Management (IAM)
Endpoint Security
Security Monitoring and Alert Investigation
Security Incident Response
Security Tool Administration
Security Reporting and Risk Analysis
Security Process Improvement
Advantageous Experience
Experience in any of the following will be highly beneficial:
Privileged Access Management (PAM)
Security Automation
Microsoft 365 Administration
Networking Fundamentals
Firewall Technologies
Remote Monitoring and Management (RMM) Platforms
SentinelOne or similar EDR solutions
Managed Service Provider (MSP) or Managed Security Service Provider (MSSP) environments
Security governance, compliance, and policy development
Requirements
Qualifications
Relevant qualification in Information Security, Cybersecurity, Computer Science, Information Technology, or a related discipline preferred.
Industry certifications such as Security+, SC-900, SC-200, CySA+, CISSP, CEH, or equivalent will be advantageous.
Experience
35+ years' experience in cybersecurity, infrastructure, systems administration, networking, or a related technical field.
Proven experience working with security tools, monitoring platforms, and security investigations.
Demonstrated experience coordinating remediation efforts across multiple technical teams.
Previous experience within an MSP, MSSP, or managed services environment is advantageous.
Create a job alert for this search
Intermediate Security Operations Engineer • Port Elizabeth, South Africa