Back to jobs
New

SOC Analyst

Cape Town

WHO WE ARE  

S-RM is a global intelligence and cyber security consultancy.  Since 2005, we’ve helped some of the most demanding clients in the world solve some of their toughest information security challenges.  

We’ve been able to do this because of our outstanding people.  We’re committed to developing sharp, curious, driven individuals who want to think critically, solve complex problems, and achieve success.  

But we also know that work isn’t everything. It’s about the lives and careers it helps us build.  We’re immensely proud of this culture and we invest in our people’s wellbeing, learning, and ideas every day. 

We’re excited you’re thinking about joining us. 

 

WORKING IN CYBER AT S-RM  

Our Cyber Security division is the fastest-growing part of S-RM. The cyber sector is always evolving, and our Managed Services,  Advisory, and Incident Response practices are in more demand than ever.   

We’re building a team to meet this challenge.  We’re quick to respond, innovate, and improve.  We don’t get too hung up on hierarchy or bureaucracy.  If your ideas are good enough, we’ll empower you to implement them.  If you’re the best person to talk to a customer, you’ll get that opportunity, regardless of the title in your email signature. And when you need a hand, your team will always have your back.  

We also don’t believe there’s a typical cyber security professional.  We’ve built a team of intelligence analysts, technical specialists, software developers, investigators, risk managers, and more.  You’ll always find a range of perspectives and expertise to help you learn and grow.   

If that sounds like your kind of team, we’d like to hear from you. 

 

THE ROLE 

As a SOC Analyst you will deploy your cybersecurity expertise in a vital delivery role across our managed detection and response services.    

In this role, you will use infrastructure and tools that power our Security Operations Centre (SOC) to deliver desired security outcomes for our managed services clients. The ideal candidate will have familiarity with security tools such as SIEM, SOAR, EDR, and other advanced technology.   You will have a proven ability to respond effectively to security incidents. This hybrid role involves both remote work and some in-office presence for collaboration, teamwork and development.  

  • Monitor Security Events: Continuously monitor and analyse security alerts from EDR, SIEM and other security tools to detect suspicious activities or potential threats.  
  • Incident Response: Conduct investigations and respond to security incidents, executing containment, mitigation, and remediation steps as necessary.  
  • Threat Hunting: Proactively search for indicators of compromise (IoCs) and advanced threats within the environment, utilising both automated tools and manual analysis.  
  • Threat Detection: Use expertise to tune detection rules, automate workflows, and improve incident detection accuracy.  
  • Log Analysis: Perform in-depth log analysis from firewalls, endpoint protection platforms, and other solutions to investigate complex incidents.  
  • Threat Intelligence: Stay informed of emerging threats and collaborate with the threat intelligence team to enhance detection capabilities.  
  • Incident Reporting and Documentation: Ensure detailed documentation of incidents, responses, and resolutions to maintain a clear incident management process.  
  • Shift Work: Participate in a 24/7 shift rotation to ensure continuous security monitoring, including evening, night, and weekend shifts. 

 

The role will be based in our Cape Town office and is hybrid with a minimum of two days a week in office. 

 

WHAT WE ARE LOOKING FOR  

The ideal candidate will have 2 to 3 years of experience working within a Security Operations Centre (SOC), with proven hands-on experience monitoring, investigating, and responding to security alerts and incidents.  

They should be proficient in the use of XDR and SIEM platforms such as SentinelOne Singularity or Microsoft Sentinel, as well as Endpoint Detection and Response (EDR) solutions including SentinelOne, Microsoft Defender for Endpoint, or CrowdStrike.  

The role requires experience in alert triage, event correlation, threat investigation, and incident escalation, supported by a solid understanding of common cyber threats, attack techniques, and security frameworks.  

Candidates should also have working knowledge of Windows and Linux operating systems, Active Directory, and Microsoft 365 security monitoring, together with experience maintaining incident records, investigation notes, and operational documentation. 

We are looking for the following experience and qualifications: 

Minimum qualifications and experience 

  • Bachelor’s degree in cyber security, Information Security, Computer Science, or related discipline. 
  • Additional certifications such as: 
  • CompTIA CySA+ 
  • SC-100/SC-200 
  • GIAC Certified Incident Handler (GCIH) 
  • Certified SOC Analyst (CSA) 
  • Blue Team / SOC Level 1 or 2 (CyberDefenders or THM)  

 

Preferred qualifications and experience 

  • Experience with Security Orchestration, Automation and Response (SOAR) platforms. 
  • Exposure to cloud security monitoring, particularly Microsoft Azure and Microsoft 365.  
  • Previous experience supporting managed security services (MSSP/MDR) environments or multiple clients 
  • Experience developing detection rules, SIEM use cases, and security playbooks. 
  • Knowledge of threat intelligence feeds and MITRE ATT&CK framework mapping.  

 

Successful candidates are also likely to show the following skills and competencies:  

  • Strong analytical and critical thinking skills 
  • Attention to detail and accuracy 
  • Effective decision-making under pressure 
  • Strong verbal and written communication skills 
  • Ability to work independently and within a team environment 
  • Time management and prioritisation skills 
  • Continuous learning mindset and adaptability 
  • Customer service and stakeholder engagement skills 
  • Professional integrity and confidentiality 
  • Ability to work shifts and participate in on-call rotations when required 
  • Strong organisational and investigative skills 
  • Resilience and the ability to perform in a fast-paced operational environment 

 

The successful candidate must have permission to work in South Africa by the start of their employment.   

 

OUR BENEFITS 

We offer thoughtful, balanced rewards and support to help our people do their best work and live their lives outside it, this includes but is not exhaustive of:   

  • Holiday – 23 days per year increasing to 28 days (+1 day for every year you worked at S-RM, up to a maximum of 5 days) in addition to bank holidays  
  • Gap Cover policy – allowing you to bridge the gap between your medical bills and your medical aid cover. 
  • Life insurance – 4x annual salary 
  • Private pension – up to 7% contribution matched by the company 
  • Formalised Recognition programme 
  • Hybrid working and flexible working hours 

 

Parental support: 

  • Fertility treatment leave – 5 days of leave per cycle of treatment per year  
  • Maternity leave – 26 weeks of full pay followed by 13 weeks of half pay (after 1 year at the company on the “qualifying week” = 15 weeks before a due date) 
  • Paternity leave – 6 weeks of full pay (after 1 year at the company on the “qualifying week” = 15 weeks before a due date) 

 

Various Health and Medical Benefits including:  

  • Medical aid with Discovery Health for employee, partner, and children up to the cost of the Classic 
    Saver plan(taxable benefit) for you and your family;  
  • EAP (Employee Assistance Programme) for employees and immediate family, including counselling sessions 
  • Free access to the world-famous mindfulness app Headspace. 
  • Seasonal flu vaccination 
  • Eye tests and glasses reimbursement up to certain cost on an annual basis 

 

To apply for this role, please submit an up-to-date CV through this link: Job Application for SOC Analyst at S-RM

Create a Job Alert

Interested in building your career at S-RM? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Demographic Questions (South Africa)

As an employer operating in South Africa, we are required under the Employment Equity Act, 1998 to collect and report demographic information relating to applicants and employees. The demographic categories below are prescribed by legislation and are used for statutory reporting and monitoring purposes.

We are firmly committed to fair and equitable recruitment practices and to building a diverse and inclusive workforce. Participation is voluntary, and all responses are treated in confidence. Should you have any questions about how we use this data, please contact privacy@s-rminform.com

Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in S-RM’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...