Incident management: log, report and escalate issues appropriately
Perform health-checks and audits on customers’ security solutions
Perform remote implementations/installations and post-installation tasks for security solutions
Administer and maintain customers’ security products for on-prem and cloud solutions
Support product management, upgrades and reporting
Recommend and implement security policies and procedures based on threat research
Develop technical security standards and assist in creating security monitoring and incident investigation procedures
Work as part of the Security Operations Centre team in South Africa
Requirements
At least 3 years’ experience in similar roles
Hands-on practical experience with endpoint security platforms like CrowdStrike, SentinelOne and Trellix (management, monitoring, upgrades, policy configurations)
Solid understanding of networking fundamentals and ability to troubleshoot network-level issues
Excellent command of both spoken and written English
Good knowledge of major operating system security (Windows, Mac OS, Linux/Unix), mainframe, web server security, and network security
Good knowledge of major security systems and functions: Firewalls, IDS/IPS, EDR, SIEM, Incident Response, Threat Prevention, Web/Application Control Filtering, Email Filtering, Netflow Analysis, Endpoint Security, Configuration and Change Management, File Integrity Monitoring, and DLP
Experience with identification and eradication of malware (Viruses, Rootkits, Spyware, Trojans) considered a strong advantage
Relevant vendor certifications (Trellix, CrowdStrike, Microsoft Defender, SentinelOne) considered a strong advantage
Legal authorization to work in South Africa (application asks if authorized)