Security Operations Analyst
The Security Operations Analyst will play a key part in delivering a world-class security monitoring, detection and incident response capability that keeps Super Group and its brands safe. The role involves hands-on monitoring and triaging of security alerts, investigating and responding to incidents, and working across SIEM, EDR, cloud and network security tooling.
The analyst's drive and ideas will help Super Group move faster, improve smarter, and stay ahead of the game.
- Monitor and triage security threats in real time.
- Keep watch over alerts from our SIEM, EDR/XDR, firewall, cloud and identity platforms, working the queue and separating real threats from the noise.
- Carry out first-line analysis of security events and escalate confirmed incidents quickly and accurately to the right people.
- Investigate and respond to security incidents.
- Dig into suspected compromises – from phishing and malware to identity and endpoint alerts – to work out what happened and contain the impact fast.
- Capture clear incident records covering timelines, root cause and remediation, in line with our incident response process.
- Proactively hunt for indicators of compromise and suspicious activity across the environment, finding what automated tools might miss.
- Consume and apply threat intelligence to sharpen detection rules and stay ahead of emerging attack techniques.
- Run and interpret vulnerability scans, track remediation and help prioritise fixes based on real risk to the business.
- Tune detection rules, maintain security tooling and recommend improvements that make monitoring and response faster and smarter.
- Manage and fulfil security-related service requests and operational tickets through Jira, ensuring timely triage, implementation, escalation and resolution in line with agreed service levels.
- Review and action requests relating to access management, firewall and network rule changes, cloud and server connectivity, email security, password management and other security services, while maintaining appropriate security controls, approvals and audit records.
- Maintain accurate security documentation, standard operating procedures and audit trails aligned to ISO 27001, POPIA and our regulatory obligations.
- Produce clear reports and metrics for stakeholders and support our external SOC partner and shift-based coverage.
- Clear, confident communication (written and verbal), and the ability to breakdown complex ideas (required)
- A collaborative mindset, working smoothly with cross-functional teams to hit shared goals (required)
- Strong organisational skills and the ability to manage multiple projects without dropping the ball (required)
- Exceptional attention to detail and a commitment to high-quality work (required)
- Adaptability – you stay sharp, productive and positive in fast-moving environments (required)
- A solid grounding in security operations – attack detection, incident response, vulnerability management and threat hunting – with a real understanding of vulnerabilities, threats, attack methods and infection vectors (required)
- Hands-on experience with core security tooling: SIEM, EDR/XDR and next-generation firewalls (Palo Alto preferred), with the ability to investigate alerts end to end (required)
- Strong working knowledge of Microsoft security across M365, Microsoft Defender and Entra ID / Conditional Access (required)
- A good understanding of networking principles (TCP/IP and the OSI model) and common attack and defence techniques (required)
- Scripting ability in PowerShell, Python or Bash to automate and speed up investigation and analysis (required)
- Active Directory administration and enterprise identity management experience (required)
- In-depth knowledge of sports betting markets, including odds calculation, betting types and market trends (nice-to-have)
- Previous experience in the online gaming or casino industry, with a strong understanding of player behaviour and industry regulations (nice-to-have)
- Familiarity with gambling regulations and compliance requirements in various jurisdictions, ensuring adherence to legal standards (nice-to-have)
- Experience in developing and executing customer retention strategies (nice-to-have)
- Awareness of POPIA, GDPR, ISO 27001, PCI DSS and sound Information Security Management System (ISMS) practices (nice-to-have)
- Experience with Microsoft cloud security (Microsoft Sentinel, Defender for Cloud, Defender XDR, Intune security policies, Entra ID Protection) (nice-to-have)
- Data Loss Prevention (DLP) and CASB concepts and administration (for example Netskope, or Microsoft Purview / Defender for Cloud Apps) (nice-to-have)
- SIEM – query and detection-rule development experience (nice-to-have)
- Linux administration and vulnerability scanning experience (for example Nessus) (nice-to-have)
- Progress towards a recognised security certification such as CompTIA Security+, Blue Team Level 1 (BTL1), CySA+, CEH or OSCP (nice-to-have)
- Supergrowth is real here. Our learning and development programmes give you the tools, training and opportunities to level up fast.
- Your progress matters. Our Performance tool ensures you get meaningful feedback to support your development and superdrive your career.
- Support that has your back. Our Employee Assistance Programme offers resources for you and your family.
- Group Life Cover
- Funeral Fund Benefit
- Income Continuation Benefit
- Medical Aid Subsidy
- Retirement Annuity Subsidy
DigiOutsource is a global iGaming technology and services company and part of Super Group (SGHC), the holding company behind the Betway and Spin brands. Headquartered in Cape Town, South Africa, with offices in London and Portugal, it provides software development, digital marketing, business intelligence, design and communications services that power leading online gaming brands. The company employs around 1,200 people across multiple continents. DigiOutsource was formed from the merger of the ForwardSlash and SpeakUp Communications businesses and operates as a key technology hub within Super Group.
