
Junior Systems Engineers
- Midrand, Johannesburg
- Permanent
- Full-time
- Constantly monitor security tools, such as SIEM (Security Information and Event Management), antivirus systems, and DLP (Data Loss Prevention) systems for security alerts.
- Respond to basic security events (e.g., failed login attempts, suspicious network traffic) by following pre-defined response procedures. Investigating and managing alerts to determine if there is a high risk or a security incident.
- Analysing details such as "who," "what," "where," and "why" of security events.
- Identifying indicators of compromise (IOCs), threat types, severity, and ATTCK stages of incidents.
- Determining if further actions are required and whether there are repeat detections.
- Setting up and monitoring compromised credential solutions and related processes.
- Perform initial incident triage, including prioritizing security alerts, determining false positives, and escalating more complex incidents to L2 analysts.
- Responding to incidents. Initiating the incident response process when a security event is confirmed. Handling remedial actions and initiating containment steps when threats are detected.
- Log incidents and maintain incident reports using ticketing systems (Manage Engine), ensuring that each incident is correctly recorded.
- Managing requests, approvals, and change control processes.
- Managing and updating documents and tickets, ensuring response SLAs are met.
- Logging tickets to the appropriate teams or levels (e.g., L2 analyst).
- Conducting SLA violation reviews when response or resolution times are breached.
- Stay informed about current security threats by researching new vulnerabilities and attack methods and applying the knowledge to daily monitoring tasks.
- Assist in internal security audits and compliance checks (e.g., ensuring security patches are applied.
- Assist senior team members with ad-hoc tasks related to incident response, documentation, and security tool updates. Reviewing SLA violation incidents and ensuring post-incident analysis is done.
- Ensure that all stakeholders are always kept up to ensure no events are left unattended. Engage with L2 and L3 to enrich understanding of the environment and management thereof
- Utilize the supported monitoring system to identify problematic remediation services.
- Ensure all escalations are actioned and production is returned to a normal state within the SLA time frame.
- Limit the number of recurring/reopened calls to ensure that the user is satisfied with the service provision.
- Managing and remediating calls within the client-defined SLA.
- Basic IT Knowledge: Fundamental understanding of operating systems (Windows, Linux), networking concepts (IP, DNS, TCP/IP), and common security protocols.
- Tools Proficiency: Basic hands-on experience with Technologies:
- SIEM
- EPP +EDR
- Secure Web Gateways
- Mail Web Gateways
- Security detection and response
- Vulnerability Management
- SASE
- Attention to Detail: Ability to spot anomalies and patterns in data that might indicate a security incident.
- Communication Skills: Must be able to explain security findings to non-technical stakeholders and escalate issues clearly to senior (L2/L3) analysts.
- Problem Solving: Ability to think critically and react quickly to potential threats while following protocol.
- Work environment: Familiar with working in a SOC.
- Excellent Customer Interaction with clear, concise, and effective communication skills.
- Effectively collaborate with the team to achieve common goals.
- Identify and resolve issues effectively.
- National Senior Certificate/ Matric/ N3/ Grade 12
- Microsoft 365 Certification
- A+, N+
- ITIL 4 - exposure or accreditation
- Pass typical recruitment checks (reference, criminal checks, etc.)
- Bachelor’s degree in IT, Computer Science, or equivalent practical experience.
- Certifications such as CompTIA Security+, CYSA+, or CCNA Security are advantageous.
- Qualifications preferred:
- ManageEngine AD Manager/Audit Plus will be an advantage
- SIEM Toolset - LogPoint
- Symantec +EDR, WithSecure +EDR, Trend Micro +EDR
- WithSecure Vulnerability Management
- Permanent Position
- Location: Midrand
- Work environment: 24x7 Shift Work - Onsite
- Physical Demands: Bending, Sitting, Lifting, Walking
- Travel: Own Transport
ExecutivePlacements.com