Cyber Security Detection Engineer

 

Recruiter:

The Vocation Station

Job Ref:

cyber_detection

Date posted:

Thursday, April 28, 2022

Location:

CapeTown, South Africa

Salary:

Commensurate dep on Experience


SUMMARY:
bring your inquisitive nature & passion for cyber security!

JOB DESCRIPTION:

Cybersecurity Detection Engineer


Please note that we will consider candidates residing in other provinces, i.e Gauteng


This role entails technical and research abilities!
Detection Engineers are responsible for improving the detection within the Nview MDR service and are the escalation point for when Response Engineers require assistance in terms of case investigations. Detection Engineers create new detectors and design threathunts, but also develop new methods of performing detection, whether that is with the current technology that may be in place or designing new systems that allow for improved detection. Detection Engineers keep informed of the latest vulnerabilities, exploits, attacker tactics and detection methods in order to use this knowledge to develop better detection within Nview MDR. Beyond detection, they also have an overall and in-depth understanding of the technology and processes that make up the Nview MDR service, from the underlying software to the individual response procedures.


Experience
• You have several years’ experience performing system and/or network administration and have some practical work experience on Active Directory and Windows Server. You have also worked on Linux platforms and are comfortable at the command line. Even if you have not worked in a cyber security specific role, you performed some cyber security functions as part of your role and you most certainly keep up to date with threats and cyber security news and trends.


About You
• You may have some interest or experience in offensive security, but your passion lies in defending against attackers and working in a blue team.
• You have a deep desire to get to root cause and leave no stone unturned in any investigation/research you do.
• You are a technical person and have broad knowledge in systems and networks.
• You enjoy building things (tools and procedures) and prefer using them to other tools that may not work as well.
• You have an immense desire to learn and are always researching and investigating new solutions and ideas.
• You have experience in both Linux and Windows OS, and good exposure to Active Directory.
• You work well in a small team and also enjoy engaging outside your team occasionally.

Responsibilities
• Threat Research – Keep updated in terms of the latest tools and techniques being used by attackers. Be aware of high-profile vulnerabilities and understand how they may affect Nview clients. Understand how Nview can be used to detect these threats and attacks, not only with its current technology stack but with applying new detection technologies or methods. Utilise this gained knowledge by informing clients when they are at risk, alternatively engage with CSM to communicate this.
• Build and Maintain Threathunts – Develop new threathunts based on gaps in detection or to provide better overall detection. These threathunts need to be documented in CyberFire. Review threathunts on a regular basis to ensure they remain accurate with the view of migrating them to detectors.
• Detection Innovation – Based on current threats, vulnerabilities or known defence trends, develop detectors including documentation for these detectors. Work with response to improve detectors which may not be effective or which may generate excessive false positives. Ensure detectors do not break by implementing regular testing of individual detectors.
• Manage Threat Intelligence – Regularly review threat feeds to determine their effectiveness. Ineffective feeds should be discarded. Research and be aware of new threat feeds that can be tested and introduced. Monitor internal threat intelligence and ensure it is evolving and continuously improving.
• Incident Investigation Support – Be an escalation point for when Response Engineers require assistance in terms of incident investigations, particularly for critical incidents.

To apply, please send your CV to

 

While we would really like to respond to every application, should you not be contacted for this position within 15 working days please consider your application unsuccessful this time around.

 

 

NB! This job is now closed. You can apply for other jobs by uploading your CV.



 

 

 

Similar jobs you might be interested in:

Cyber Security Engineer
Location: Cape Town
Salary:
As guardians of digital fortresses, cyber security engineers play a critical role in designing, implementing, and maintaining robust security measures to protect against a wide array of cyber threats. They are responsible for ensuring the confidentiality, integrity, and availability of information systems and data. This involves not only protecting against external threats but also addressing inte...
21 days ago


Cyber Security Lead – Permanent – Cape Town – Hybrid– Up to R1.2mil per annum
Location: Capetown
Salary: 1200000
cyber security Lead – Permanent – Cape Town – Hybrid– Up to R1.2mil per annum
21 days ago


Senior Engineering Lead - Contract Opportunity
Location: Cape Town
Salary:
12 days ago


Accountant
Location: Cape Town
Salary: 620000 Annually
Step into the future of finance today!
14 days ago


Junior Developer
Location: Cape Town
Salary: 15000 Monthly
Junior Developer Cape TownR15k - R25k P/M
14 days ago


ZMA 14275 - Mid-Senior Systems Engineer – CPT / JHB (HYBRID)
Location: Capetown
Salary: R480000 – R720000 Per Annum CTC
Mid-Senior Systems engineer – CPT / JHB (HYBRID)
19 days ago


Network Infrastructure Sales Representative
Location: Cape Town
Salary: 20000
Network Infrastructure Sales ExecutiveLocation : Western Cape, Northern SuburbsOur client is a leading service provider of network infrastructure solutions in South Africa.Our core services include design and installation of structured cabling systems, managed networks, and wireless connectivity solutions. In addition to our core services, we also provide IP security and surveillance solutions, ne...
20 days ago


Cyber Engineer
Location: Cape Town
Salary:
We are looking for an energetic cyber engineer to join our client's team in the International Defense Industry. This role has AMAZING room for career growth.Our client is a very well-established international defense agency who are growing rapidly and are looking for hard energetic individuals to be a part of their amazing team.Cape Town | Permanent | On-site | Market Related Salary
11 days ago


Sales Engineer- Cape Town
Location: Bellville
Salary: Negotiable
The sales representative’s role (based in Cape Town) is to manage and develop the sales of the Company’s products in the Western Cape, Eastern Cape, parts of the Northern Cape and Namibia by selling to an existing customer base and developing new customer sales.This will include regular travel to and within the regions.As an external sales representative, you will be the face of the Co...
6 days ago


Site Reliability Engineering Manager
Location: Cape Town
Salary:
About Us:We are revolutionizing the human capital development industry, empowering organizations to unlock the full potential of their workforce. We are driven by our mission to enhance skills, foster growth, and enable individuals and teams to achieve greater success. Our innovative technology platforms and learning solutions are transforming how businesses develop their talent and thrive in a ra...
13 days ago


Create a free job alert for Cyber Security Detection Engineer in CapeTown

Enter your email address below and we will email you similar jobs when they become available:

You can cancel at any time. We will not spam you.
By giving us your email address your agree to our Terms and Conditions