Cyber Security Incident Responder
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Cyber Security Incident Responders to identify, investigate, contain, eradicate and support recovery from cybersecurity incidents across complex enterprise IT environments.
The successful candidates will play a critical role in protecting organisational systems, networks, applications and sensitive information by responding to cybersecurity threats, conducting technical investigations and coordinating incident remediation activities.
This position requires strong hands-on experience in cybersecurity incident response, digital forensics, security event analysis, threat investigation and enterprise security technologies.
The ideal candidates will have proven experience managing security incidents involving malware, ransomware, phishing, compromised accounts, unauthorised access, network intrusions and other cybersecurity threats.
Candidates must demonstrate the ability to investigate security incidents, determine their scope and impact, implement appropriate containment measures and support the restoration of affected systems while maintaining accurate incident documentation.
Key Responsibilities
Cybersecurity Incident Detection and Response
- Identify, investigate and respond to cybersecurity incidents affecting enterprise systems, networks, endpoints, applications and cloud environments.
- Conduct incident triage and determine the severity, scope and potential business impact of security incidents.
- Investigate suspicious activities, security alerts and indicators of compromise.
- Execute incident response procedures covering identification, containment, eradication, recovery and post-incident review.
- Coordinate immediate containment activities to minimise the impact of cybersecurity incidents.
- Investigate malware infections, ransomware attacks, phishing incidents, compromised credentials and unauthorised access.
- Analyse security alerts and correlate information from multiple security technologies.
- Escalate critical incidents in accordance with established incident response procedures.
- Maintain accurate incident timelines, investigation records and technical findings.
- Collaborate with SOC analysts, threat hunters, security engineers and infrastructure teams during incident investigations.
Digital Forensics and Technical Investigations
- Conduct technical investigations to determine the origin, scope and impact of cybersecurity incidents.
- Collect, preserve and analyse relevant digital evidence.
- Perform endpoint, operating system and network forensic investigations.
- Analyse system logs, security events, network traffic and endpoint telemetry.
- Investigate suspicious processes, persistence mechanisms and malicious system changes.
- Identify indicators of compromise and attacker tactics, techniques and procedures.
- Support forensic analysis of compromised Windows and Linux systems.
- Conduct memory, disk and artefact analysis where required.
- Maintain appropriate evidence handling procedures and chain-of-custody records.
- Prepare forensic investigation findings and technical reports.
Malware and Ransomware Incident Response
- Investigate malware infections, ransomware incidents and other malicious activities.
- Analyse suspicious files, processes and system behaviour.
- Identify malware execution mechanisms, persistence techniques and potential lateral movement.
- Support the isolation and containment of compromised systems.
- Coordinate malware eradication and remediation activities.
- Investigate potential data compromise or unauthorised information access.
- Support system recovery and restoration following cybersecurity incidents.
- Recommend improvements to endpoint protection and malware prevention controls.
- Collaborate with relevant technical teams to prevent recurrence.
Security Monitoring and Threat Analysis
- Analyse security events generated by SIEM, EDR, XDR, firewalls, intrusion detection systems and cloud security platforms.
- Correlate security logs and threat intelligence to identify malicious activities.
- Investigate indicators of compromise across enterprise environments.
- Use the MITRE ATT&CK framework to understand and classify attacker behaviour.
- Identify suspicious authentication events, privilege escalation and lateral movement.
- Analyse network traffic to identify potential command-and-control activity or unauthorised communications.
- Support threat hunting activities and proactive security investigations.
- Recommend improvements to security detection rules and monitoring capabilities.
- Collaborate with security operations teams to improve incident detection and response effectiveness.
Incident Containment, Eradication and Recovery
- Develop and execute incident containment strategies in collaboration with relevant technical teams.
- Isolate compromised endpoints, servers or accounts where authorised.
- Coordinate credential resets, access restrictions and other containment measures.
- Support the removal of malicious files, processes and unauthorised persistence mechanisms.
- Validate that identified threats have been eradicated.
- Coordinate secure restoration of affected systems and services.
- Monitor recovered environments for signs of recurring compromise.
- Support business continuity and disaster recovery activities following major cybersecurity incidents.
- Document recovery actions and recommend improvements to incident response procedures.
Incident Response Planning and Readiness
- Develop, review and maintain cybersecurity incident response plans, playbooks and procedures.
- Create incident response playbooks for common attack scenarios.
- Participate in cybersecurity tabletop exercises, simulations and incident response drills.
- Identify weaknesses in incident response processes and recommend improvements.
- Support the implementation of incident response automation and orchestration technologies.
- Maintain incident response tools, investigation procedures and operational documentation.
- Assist with defining incident severity classifications and escalation processes.
- Collaborate with relevant stakeholders to improve organisational incident readiness.
- Support continuous improvement of cybersecurity response capabilities.
Reporting, Governance and Compliance
- Prepare detailed cybersecurity incident investigation reports.
- Document incident timelines, root causes, affected systems and remediation activities.
- Conduct post-incident reviews and lessons-learned sessions.
- Recommend improvements to security controls, monitoring and response processes.
- Maintain incident registers, investigation evidence and remediation records.
- Support cybersecurity audits and compliance assessments.
- Ensure incident response activities align with organisational policies and recognised security frameworks.
- Support the assessment of potential data protection and regulatory reporting obligations.
- Assist with stakeholder communication and incident escalation where required.
- Maintain confidentiality and integrity throughout cybersecurity investigations.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Information Security, Digital Forensics or a related discipline.
- Typically 3–5 years of relevant hands-on experience in cybersecurity incident response, security operations, digital forensics or threat investigation.
- Proven practical experience investigating and responding to cybersecurity incidents within enterprise environments.
- Strong understanding of the cybersecurity incident response lifecycle.
- Experience investigating malware, ransomware, phishing, compromised accounts and network intrusions.
- Practical experience with SIEM, EDR or XDR technologies.
- Strong knowledge of Windows and Linux operating systems.
- Experience analysing security logs, endpoint telemetry and network traffic.
- Understanding of digital forensic investigation principles and evidence handling.
- Familiarity with the MITRE ATT&CK framework and common attacker tactics, techniques and procedures.
- Knowledge of enterprise networking, TCP/IP, DNS, HTTP/HTTPS and authentication protocols.
- Experience with incident containment, remediation and recovery activities.
- Understanding of Active Directory and identity-related security incidents.
- Familiarity with cloud security incidents and Microsoft Azure, AWS or equivalent environments.
- Strong technical troubleshooting, analytical and incident reporting skills.
- Ability to work effectively under pressure and manage time-sensitive security incidents.
Technical Skills and Competencies
Cybersecurity Incident Response
- Security incident identification and triage
- Incident severity classification
- Incident investigation and escalation
- Incident containment
- Threat eradication
- System recovery and restoration
- Root cause analysis
- Post-incident reviews
- Incident response playbooks
- Cybersecurity crisis management
- Security incident reporting
- Incident response coordination
Security Monitoring and Detection
- Security Information and Event Management (SIEM)
- Endpoint Detection and Response (EDR)
- Extended Detection and Response (XDR)
- Network Detection and Response (NDR)
- Security event correlation
- Threat intelligence integration
- Log analysis
- Security alert investigation
- Indicators of Compromise (IOCs)
- Indicators of Attack (IOAs)
- Detection engineering fundamentals
- Security Operations Centre procedures
Experience with platforms such as:
- Microsoft Sentinel
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Splunk
- IBM QRadar
- Elastic Security
- CrowdStrike Falcon
- SentinelOne
- Palo Alto Cortex XDR
- Other enterprise security monitoring and incident response platforms
Digital Forensics and Investigation
- Digital evidence collection and preservation
- Windows forensic analysis
- Linux forensic analysis
- Endpoint forensic investigations
- Disk and memory analysis
- Log and artefact analysis
- Network forensic analysis
- Timeline reconstruction
- Chain-of-custody procedures
- Forensic investigation reporting
Experience with tools such as:
- Autopsy
- FTK
- EnCase
- Volatility
- KAPE
- Velociraptor
- Wireshark
- Other recognised digital forensic and investigation tools
Malware and Threat Investigation
- Malware incident investigation
- Ransomware response
- Phishing investigation
- Suspicious file analysis
- Malware persistence analysis
- Credential compromise investigation
- Privilege escalation detection
- Lateral movement investigation
- Command-and-control detection
- Threat intelligence analysis
- MITRE ATT&CK mapping
- Threat hunting fundamentals
Enterprise Infrastructure and Network Security
- Windows Server
- Linux
- Microsoft Active Directory
- Microsoft Entra ID
- TCP/IP networking
- DNS and DHCP
- Firewalls
- Intrusion Detection and Prevention Systems (IDS/IPS)
- VPN security
- Network traffic analysis
- Endpoint security
- Identity and access management
- Enterprise authentication systems
Cloud Security Incident Response
- Microsoft Azure security monitoring
- Microsoft Entra ID security investigations
- Microsoft 365 security incidents
- AWS security monitoring
- Cloud identity compromise investigations
- Cloud audit logs
- Cloud workload security
- Cloud incident containment and remediation
- Hybrid infrastructure investigations
Scripting and Automation
- PowerShell
- Python
- Bash
- Security investigation scripting
- Log parsing and analysis
- Incident response automation
- Security Orchestration, Automation and Response (SOAR)
- Automated evidence collection
- API integration
Cybersecurity Frameworks and Standards
- NIST SP 800-61 – Incident Response
- NIST Cybersecurity Framework
- MITRE ATT&CK
- ISO/IEC 27001
- ISO/IEC 27035 – Information Security Incident Management
- SANS Incident Response Methodology
- Cyber Kill Chain
- Digital forensic investigation principles
- POPIA and applicable data protection requirements
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Forensic Examiner (GCFE)
- GIAC Reverse Engineering Malware (GREM)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Network Forensic Analyst (GNFA)
- CompTIA CySA+
- CompTIA Security+
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Cybersecurity Architect Expert
- Relevant digital forensics, incident response or threat hunting certifications
Key Personal Attributes
- Excellent analytical and investigative abilities.
- Strong technical troubleshooting and problem-solving skills.
- Ability to remain calm and focused during critical cybersecurity incidents.
- Strong attention to detail and technical accuracy.
- Ability to make informed decisions under pressure.
- Excellent communication and stakeholder engagement skills.
- Ability to collaborate effectively with SOC, infrastructure, cloud and cybersecurity teams.
- Strong technical reporting and documentation abilities.
- Proactive approach to cybersecurity threats and incident prevention.
- Ability to manage multiple security investigations and competing priorities.
- High levels of confidentiality, accountability and professional integrity.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their practical cybersecurity incident response, threat investigation and digital forensic experience, together with copies of relevant academic qualifications and professional certifications.
Candidates should specifically highlight:
- Types of cybersecurity incidents they have personally investigated and resolved.
- Experience responding to ransomware, malware, phishing, credential compromise or network intrusion incidents.
- Practical experience with incident containment, eradication and recovery.
- SIEM, EDR, XDR and other security investigation platforms used.
- Digital forensic investigation and evidence collection experience.
- Windows, Linux, Active Directory and cloud security incident investigations.
- Experience using MITRE ATT&CK during investigations.
- Incident response playbooks, procedures and automation they have developed or implemented.
- Examples of complex cybersecurity incidents handled and their responsibilities.
- Experience preparing incident investigation reports and root cause analyses.
- Relevant cybersecurity incident response and digital forensic certifications.
Important: This is a specialist Cyber Security Incident Responder opportunity requiring demonstrable hands-on experience investigating and responding to real cybersecurity incidents. General IT support, security administration or basic SOC monitoring experience without substantial incident investigation and response responsibilities will not be sufficient.
Please note: Specific project requirements, remuneration, employment arrangements, on-call expectations and working conditions will be confirmed during the recruitment process.