Cybersecurity Operations Specialist About the Role We are seeking a hands-on Cybersecurity Operations Specialist to strengthen our security operations capability by proactively monitoring, detecting, investigating and responding to cybersecurity threats across the enterprise. This role is ideal for a cybersecurity professional with strong operational experience in security monitoring, incident response, vulnerability management and endpoint security technologies. You will work closely with internal IT teams and security vendors to ensure the organisation maintains a robust security posture while continuously improving security operations. Key Responsibilities Security Operations & Incident Response Monitor enterprise security platforms and investigate security alerts, suspicious activities and potential threats. Perform daily security event triage, analysis and escalation of incidents based on severity. Support incident response activities including investigation, containment, eradication and recovery. Analyse logs and security telemetry from multiple security solutions to identify malicious activities and recommend remediation. Coordinate with internal IT teams and managed security service providers (MSSPs) to resolve security incidents promptly. Produce operational security metrics, threat reports and incident summaries. Vulnerability & Threat Management Perform continuous vulnerability monitoring across servers, endpoints and infrastructure. Prioritise vulnerabilities based on business risk and coordinate remediation activities with infrastructure and application teams. Validate remediation efforts and track outstanding vulnerabilities until closure. Assist in conducting vulnerability assessments and penetration testing remediation activities. Endpoint & Identity Security Administer and support endpoint security platforms such as Endpoint Detection & Response (EDR) solutions. Monitor endpoint health, investigate endpoint detections and fine-tune security policies where required. Support identity security through Microsoft Entra ID and related identity protection capabilities. Perform security reviews on privileged accounts and endpoint security configurations. Security Platforms Administration Support daily operations of enterprise security technologies including:Endpoint Detection & Response (CrowdStrike or equivalent)Microsoft Entra IDSecure Email GatewaySecure Web GatewayData Loss Prevention (DLP)Firewall and network security technologies Troubleshoot security platform issues and optimise security policies to improve detection accuracy and reduce false positives. Assist with deployment, configuration and maintenance of cybersecurity solutions. Phishing Defence & Security Awareness Execute phishing simulation campaigns and analyse campaign effectiveness. Investigate phishing reports submitted by users and coordinate appropriate response actions. Conduct cybersecurity awareness initiatives to strengthen organisational security culture. Prepare operational reports on phishing trends and emerging attack techniques. Cybersecurity Projects & Continuous Improvement Support implementation and enhancement of cybersecurity technologies and operational processes. Participate in security tool deployments, upgrades and operational improvement initiatives. Coordinate testing, validation and rollout of new security capabilities. Maintain accurate operational documentation, playbooks and technical procedures. Requirements Required Qualifications Bachelor's Degree in Information Security, Computer Science, Information Technology or a related discipline. 3–5 years of hands-on experience in Cybersecurity Operations, Security Engineering, SOC or Incident Response. Experience investigating and responding to security alerts and incidents. Strong understanding of endpoint protection, identity security and vulnerability management. Experience working with SIEM, EDR and enterprise security monitoring platforms. Familiarity with Windows Server, Active Directory, Microsoft 365 and networking fundamentals. Ability to analyse security logs, identify threats and recommend remediation actions. Strong troubleshooting and analytical skills with a proactive approach to problem solving. Preferred Skills Experience with one or more of the following technologies: CrowdStrike Falcon Microsoft Defender Suite Microsoft Entra ID ManageEngine SIEM platforms (Microsoft Sentinel, Splunk, QRadar or equivalent) Secure Email Gateway solutions Secure Web …