Jobs Career Advice Post Job
X

Send this job to a friend

X

Did you notice an error or suspect this job is scam? Tell us.

  • Posted: Sep 16, 2026
    Deadline: Not specified
    • @gmail.com
    • @yahoo.com
    • @outlook.com
  • Datafin was established in 1999 due to the need for a specialized IT recruitment solution. We offer a personalized and flexible recruitment service, specializing in providing both client and candidate with the perfect fit. We pride ourselves on the fact that we have established relationships with industry leaders and a vast majority of our business is repeat...

     

    L2 SOC Analyst / Cybersecurity Analyst (Microsoft Sentinel & KQL) (CPT Onsite)

    ENVIRONMENT:

    • An innovative, End-to-end Cybersecurity firm based in Cape Town is seeking a strong technical L2 SOC Analyst / Cybersecurity Analyst to join its Cybersecurity team and support multiple client environments within its MSP/MSSP operation.
    • This role will go beyond basic SOC alert monitoring. The successful candidate will independently investigate security alerts and incidents, analyse security telemetry, perform threat hunting, contribute to SIEM and detection improvements, and support a range of cybersecurity projects across the client base.
    • You must be comfortable working across multiple technologies, clients and competing priorities and should be capable of working independently with limited supervision.
    • Applicants will require Certifications such as Microsoft SC-200/Microsoft AZ-500/Microsoft SC-100/CompTIA Security+ with 2–4 years' practical cybersecurity / SOC experience & proficiency with Microsoft Sentinel, KQL, SIEM, EDR/XDR & a solid understanding of MITRE ATT&CK.

    DUTIES:

    • Investigate and analyse security alerts and incidents across multiple client environments.
    • Perform L2 SOC investigations and determine the nature, severity and potential impact of security events.
    • Work with Microsoft Sentinel and KQL for incident investigation, log analysis, threat hunting and detection development.
    • Review, tune and improve SIEM detection rules and identify detection gaps.
    • Contribute to MITRE ATT&CK mapping and detection coverage assessments.
    • Conduct proactive threat hunting and contribute to monthly threat-hunting reporting.
    • Analyse EDR/XDR alerts and endpoint security events.
    • Investigate Microsoft 365, Entra ID, endpoint, email and network security events.
    • Assist with vulnerability management, security hardening and remediation activities.
    • Support SIEM onboarding, optimisation and cybersecurity projects.
    • Produce technical and client-facing security reports and recommendations.
    • Work across multiple clients and technologies while prioritising incidents and tasks according to risk and business impact.
    • Maintain accurate technical documentation and investigation records.

    Candidate Profile

    The ideal candidate should be able to operate beyond:

    • Alert → Basic Investigation → Escalation and instead demonstrate:
    • Alert → Investigation → Correlation → Analysis → Risk Assessment → Response → Documentation → Improvement

    They should be able to independently determine:

    • What happened?
    • Why did it happen?
    • What is affected?
    • What is the security risk?
    • What should be done?
    • Does the detection need to be improved?

    REQUIREMENTS:

    Qualifications –

    Relevant certifications are a MUST but hands-on technical experience will carry greater weight. Examples include:

    • Microsoft SC-200
    • Microsoft AZ-500
    • Microsoft SC-100
    • CompTIA Security+
    • CompTIA Network+
    • Fortinet certifications
    • Relevant SIEM, SOC, threat-hunting or incident-response certifications

    Experience/Skills –

    • 2–4 Years' practical cybersecurity / SOC experience.
    • Experience working in an MSP, MSSP or multi-client environment.
    • Strong hands-on experience with Microsoft Sentinel.
    • Practical KQL experience.
    • SIEM alert investigation and incident response experience.
    • EDR/XDR experience.
    • Strong understanding of security monitoring and log analysis.
    • Understanding of MITRE ATT&CK.
    • Good understanding of networking, Windows and Microsoft security technologies.
    • Strong analytical, problem-solving and documentation skills.

    Advantageous –

    • Microsoft Defender XDR / Defender for Endpoint.
    • Sentinel detection engineering and Content Hub.
    • Threat hunting.
    • Detection rule development and optimisation.
    • Power BI / Cybersecurity dashboards.
    • Microsoft Entra ID security.
    • Vulnerability Management / Tenable.
    • Fortinet / FortiGate.
    • Cisco security technologies.
    • SentinelOne / Sophos.
    • Security assessments and hardening.
    • Experience with additional SIEM platforms.

    ATTRIBUTES:

    • Self-motivated and able to work independently.
    • Strong analytical and investigative mindset.
    • Comfortable troubleshooting unfamiliar security issues.
    • Strong prioritisation and decision-making skills.
    • Able to manage multiple clients and competing priorities.
    • Strong written and verbal communication.
    • Able to explain technical security issues clearly.
    • Detail-oriented and methodical.
    • Willing to continuously develop technical skills.
    • Comfortable working under pressure.
    • Takes ownership rather than relying on constant escalation.

    Check how your CV aligns with this job

    Method of Application

    Interested and qualified? Go to Datafin Recruitment on datafin.com to apply

    Build your CV for free. Download in different templates.

  • Get new ICT / Computer jobs like this on Telegram.Subscribe on Telegram
  • Send your application

    Back To Home

Career Advice

View All Career Advice
 

Subscribe to Job Alert

 

Join our happy subscribers

 
 
Send your application through

GmailGmail YahoomailYahoomail