L2 SOC Analyst - Cape Town or Johannesburg
Cape Town, Western Cape, South Africa
What you’ll work on
Full postingEnsure that incidents are communicated clearly and timeously with clients for effective resolution.
Maintain clear, professional communication with clients throughout the incident lifecycle, ensuring transparency and client satisfaction.
From the employer’s posting
Conduct thorough investigations to identify the root cause of incidents, collaborating with team members or escalating when necessary. Ensure that incidents are communicated clearly and timeously with clients for effective resolution. Be a contributor during cybersecurity incidents from detection to resolution, adhering to established protocols.
Client Communication: Maintain clear, professional communication with clients throughout the incident lifecycle, ensuring transparency and client satisfaction. Promote best practices within the team to consistently achieve positive outcomes for clients and stakeholders.
See how this role fits your experience
Add your resume to compare the role’s scope, tools and requirements with your experience.
Pay, work setup, and employment type unconfirmed
Not confirmed in this saved copy: pay, work setup, employment type. Check the full posting
Find answers in the posting
AIAlready applied? Track this application
About applying
Apply opens the employer’s site in a new tab. Add your outcome here after you submit.
Source details & eligibility
Before you apply
Source excerptsSelected passages from the saved posting. Check the full description for conditions and exceptions.
- Pay
No pay amount identified in the saved description.
- Location & working pattern
Cape Town, Western Cape, South Africa
Working pattern and location restrictions need checking in the full posting.
- Work authorization
No clear work-authorization passage found. Eligibility is unconfirmed.
Posting history
- Status in our records
- Active
- First seen by us
- Sep 8, 2026
- Recorded sightings
- 1
These dates show when we found the listing. Check the employer’s website to confirm it is still accepting applications.
Report an errorEducation & alternatives
Qualifications/Certifications: - A bachelor’s degree in computer science, Information Technology, or similar credentials is highly advantageous. - Relevant certifications such Security+, PenTest+, Blue Team Level 1 or similar credentials are highly advantageous.
Job description
About Us
Integrity360 is a leading independent cybersecurity and PCI specialist operating across Europe, Africa, the Caribbean, and North America. The company has office locations in Ireland, the UK, Bulgaria, Italy, Sweden, Spain, Lithuania, Ukraine, Africa, the Caribbean, and Canada, supported by seven Security Operations Centres (SOCs) located in Dublin, Sofia, Madrid, Stockholm, Rome, Johannesburg and Cape Town.
With over 780 employees, including more than 585 dedicated cybersecurity professionals, Integrity360 delivers a full suite of professional, support, and managed security services. These span the complete cyber risk lifecycle, from identification and prevention to detection, response, and recovery. Integrity360 supports over 3000 mid-market and enterprise organisations across sectors including financial services, insurance, government, healthcare, retail, telecommunications, and utilities.
At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you're ready to take your cyber security career to the next level, we’d love to hear from you. About This Role This is a fantastic opportunity for someone looking to advance their career in cybersecurity, particularly within the Blue Team arena. You'll be at the forefront of responding to and investigating malicious activity, triaging alerts, and helping customers navigate security incidents.
About This Role
This is a fantastic opportunity for someone looking to advance their career in cybersecurity, particularly within the Blue Team arena. You'll be at the forefront of responding to and investigating malicious activity, triaging alerts, and helping customers navigate security incidents.
Responsibilities:
Incident Investigation:
- Triage security alerts to assess if additional investigation is required.
- Conduct thorough investigations to identify the root cause of incidents, collaborating with team members or escalating when necessary.
- Ensure that incidents are communicated clearly and timeously with clients for effective resolution.
- Be a contributor during cybersecurity incidents from detection to resolution, adhering to established protocols.
Threat Hunting:
- Conduct threat hunting activities across assigned client environments to identify indicators of compromise (IOCs), suspicious behaviours, and potential threats.
- Develop and execute intelligence-led threat hunting scenarios based on the latest threat actor activity, emerging threats, industry threat intelligence, and observed attacker tactics, techniques, and procedures (TTPs).
Process Improvement:
- Regularly review and update incident response procedures to enhance efficiency and effectiveness.
- Establish close alignment with the Detection team to analyze alert trends to refine detection rules to minimize false positives.
Efficiency Optimization:
- Assist the Incident Response Team Leader to streamline response workflows through automation, orchestration and/or other innovative methods.
- Establish methodologies to ensure that the alert queue is triaged effectively, allowing for appropriate actions taken on security incidents.
Incident Management:
- Identify and document vulnerabilities in client systems during investigations, contributing to ongoing improvements in security posture.
- Assist with critical incident report writing.
Client Communication:
- Maintain clear, professional communication with clients throughout the incident lifecycle, ensuring transparency and client satisfaction.
- Promote best practices within the team to consistently achieve positive outcomes for clients and stakeholders.
Desired Skills:
- A minimum of 2 - 4 years of experience in cybersecurity, particularly in a technical role within a SOC, CSIRT, or similar environment.
- Experience with conducting security related log investigations with utilising various log sources/security products.
- Solid understanding of networking, with the focus being able to understand network related attacks.
- Familiarity with SIEM technologies such as Splunk, QRadar, Elastic Stack, or equivalent.
- Knowledge of the attack chain and critical incidents including experience with Digital Forensics and Incident Response is beneficial.
Qualifications/Certifications:
- A bachelor’s degree in computer science, Information Technology, or similar credentials is highly advantageous.
- Relevant certifications such Security+, PenTest+, Blue Team Level 1 or similar credentials are highly advantageous.
#LI-GB1