Cyberfire Operations Engineer
Job description
About the role
As a , you will play a crucial role in enhancing our cybersecurity operations. This position is designed for individuals who are passionate about protecting digital assets and ensuring the integrity of our systems. You will be part of a dynamic team that focuses on identifying, analyzing, and mitigating cyber threats. Your expertise will help us maintain a robust security posture and respond effectively to incidents, ensuring the safety of our clients' information and infrastructure.
Key facts
What you'll do
- Monitor and analyze security events and alerts from various sources, including SIEM tools, to identify potential threats and vulnerabilities.
- Conduct thorough investigations of security incidents, documenting findings and recommending remediation steps to mitigate risks.
- Collaborate with cross-functional teams to develop and implement security policies, procedures, and best practices that align with industry standards.
- Participate in the design and implementation of security solutions, ensuring they are effective and scalable to meet the organization's needs.
- Provide real-time incident response support, including containment, eradication, and recovery efforts following security breaches.
- Maintain up-to-date knowledge of the latest cybersecurity trends, threats, and technologies to enhance the organization's security posture.
- Assist in conducting vulnerability assessments and penetration testing to identify weaknesses in systems and applications.
- Prepare and present reports on security incidents, trends, and recommendations to senior management and stakeholders.
- Engage in continuous improvement initiatives to enhance the efficiency and effectiveness of the cybersecurity operations team.
- Mentor junior team members, providing guidance and support in their professional development within the cybersecurity field.
- Collaborate with external partners and vendors to ensure the organization is leveraging the best tools and services available for cybersecurity.
- Participate in security awareness training for employees to promote a culture of security within the organization.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 3 years of experience in cybersecurity operations or a related role.
- Strong understanding of security frameworks, such as NIST, ISO 27001, or CIS Controls.
- Experience with security information and event management (SIEM) tools and incident response methodologies.
- Proficiency in network security concepts, including firewalls, intrusion detection/prevention systems, and VPNs.
- Familiarity with scripting languages (e.g., Python, PowerShell) for automation and analysis tasks.
- Relevant cybersecurity certifications (e.g., CISSP, CEH, CISM, or similar) are highly desirable.
- Excellent analytical and problem-solving skills, with a keen attention to detail.
- Strong communication skills, both written and verbal, to effectively convey technical information to non-technical stakeholders.
- Ability to work independently and as part of a team in a fast-paced environment.
Nice to have
- Experience with cloud security practices and tools, particularly in AWS or Azure environments.
- Knowledge of compliance regulations such as GDPR, PCI-DSS, or HIPAA.
- Familiarity with threat intelligence platforms and methodologies.
- Experience in conducting security training and awareness programs.
- Understanding of DevSecOps principles and practices.
Skills & tools
- Proficient in using security tools such as firewalls, intrusion detection systems, antivirus software, and vulnerability scanners.
- Familiarity with programming and scripting languages for automation and analysis, including Python and Bash.
- Experience with SIEM platforms like Splunk, ArcSight, or similar tools.
- Knowledge of endpoint protection solutions and security orchestration automation and response (SOAR) tools.
- Understanding of network protocols and architectures, including TCP/IP, DNS, and HTTP.
Practical notes
- This position is based in Cape Town, Western Cape, and may require occasional on-call support outside of regular business hours.
- Candidates must be eligible to work in South Africa; visa sponsorship is available for qualified applicants.
- Integrity360 is committed to fostering a diverse and inclusive workplace, encouraging applications from individuals of all backgrounds.
Join us at Integrity360 and become an integral part of our mission to safeguard digital environments. If you are driven by a passion for cybersecurity and possess the skills and experience we are looking for, we invite you to apply for the Cyberfire Operations Engineer position today.