Senior Cyber Security Analyst
- Function
- Information technology
- Facility
- Life Head Office, Dunkeld
- Position
- Senior Cyber Security Analyst
- Introduction
-
Job Title: Senior Cyber Security Analyst
Location: Group Information Security Office (Head Office)
Reporting Line: Head: Cyber SecurityJob Summary:
A vacancy exists for a Senior Cyber Security Analyst based at Life Healthcare Head Office reporting to the Head: Cyber Security. The successful incumbent will be responsible for identifying, assessing, and mitigating cybersecurity risks across the organisation’s network, systems, and applications. This role focuses on vulnerability management, penetration testing, and network security, ensuring proactive threat detection and robust defense mechanisms and being proactive within incident response.
- Critical Outputs
-
- Vulnerability Management
- Lead and support the enterprise vulnerability management programme across infrastructure, endpoints, applications, databases, cloud environments and internet-facing assets.
- Conduct regular vulnerability scanning using tools such as Qualys, Tenable, Rapid7 or similar platforms.
- Analyse vulnerability scan results and prioritise remediation based on severity, exploitability, asset criticality, exposure, business impact and active threat activity.
- Validate vulnerabilities to reduce false positives and confirm actual risk to the organisation.
- Collaborate with infrastructure, endpoint, network, application and cloud teams to ensure timely remediation of identified vulnerabilities.
- Track remediation progress against agreed service levels and escalate overdue or high-risk vulnerabilities where required.
- Validate patching and remediation effectiveness through rescans and evidence review.
- Maintain vulnerability dashboards, remediation trackers, risk exception registers and executive-level reporting.
- Identify recurring vulnerabilities, root causes and systemic control weaknesses requiring long-term remediation.
- Web Application and API Security Scanning
- Perform or coordinate web application and API vulnerability scanning using Qualys WAS or similar approved application security scanning platforms.
- Analyse web application scanning results to identify valid findings, false positives, duplicate findings and recurring weaknesses.
- Assess web application and API findings against common security risks such as the OWASP Top 10.
- Work with application owners, developers and third-party providers to clarify findings and support remediation.
- Track application security findings from identification through to closure.
- Validate remediation evidence for web application and API security findings.
- Identify recurring application security weaknesses and recommend improvements to secure development practices, configuration standards and control design.
- Penetration Testing Governance and Third-Party Coordination
- Act as the internal cyber security custodian for penetration testing and security assessment activities.
- Coordinate third-party penetration testing engagements, including scope definition, rules of engagement, asset confirmation, timelines, evidence requirements and reporting expectations.
- Ensure penetration testing activities are properly authorised, risk-managed and aligned with business, operational and change management requirements.
- Review third-party penetration testing reports in detail and interpret the technical findings, exploitability, business impact and remediation requirements.
- Engage with external testers to clarify, challenge or negotiate findings where required, including severity ratings, false positives, duplicate findings, compensating controls and practical remediation options.
- Translate penetration testing findings into clear remediation actions for infrastructure, network, application, cloud and system owners.
- Track penetration testing findings through to closure and provide regular progress updates to management.
- Validate remediation actions and supporting evidence before closing findings.
- Prepare management reporting on penetration testing outcomes, recurring themes, overdue findings, remediation progress and residual risk.
- Network and Infrastructure Security Assessment
- Assess security weaknesses across network infrastructure, servers, cloud services, firewalls, remote access, wireless, segmentation and internet-facing services.
- Review exposed services, insecure configurations, weak protocols, missing patches and unnecessary attack surface.
- Support security reviews of network architecture, firewall rules, segmentation and access controls from a vulnerability and exposure perspective.
- Work with network and infrastructure teams to reduce unnecessary exposure and improve secure configuration.
- Support initiatives relating to secure baselines, hardening standards, patch compliance and attack surface reduction
- Identify technical control gaps that increase vulnerability exposure or remediation complexity.
- Provide practical recommendations to reduce risk across infrastructure and network environments.
- Risk Management, Exceptions and Governance
- Align vulnerability management and penetration testing processes with recognised frameworks and standards such as ISO 27001, NIST, CIS Controls and internal cyber security policies.
- Support cyber risk assessments by providing vulnerability data, remediation status, exposure information and technical context.
- Maintain records of accepted risks, remediation exceptions, compensating controls and overdue findings.
- Ensure exceptions are documented, time-bound, justified and reviewed periodically.
- Provide vulnerability and remediation evidence for audits, compliance reviews and governance reporting.
- Assist with the development and maintenance of vulnerability management standards, procedures, reporting templates and operational processes.
- Identify control weaknesses and recommend practical improvements to reduce cyber risk.
- Incident and Threat Exposure Support
- Provide vulnerability and exposure context during security incidents or investigations where required.
- Assist in determining whether known vulnerabilities, exposed services, weak configurations or missed remediation activities may have contributed to an incident.
- Support root cause analysis by identifying relevant vulnerability history, asset exposure and remediation gaps.
- Recommend corrective actions to reduce the likelihood of repeat incidents.
- Support lessons learned activities where vulnerability management, patching, configuration or exposure issues are identified.
- Stakeholder Engagement & Reporting
- Communicate vulnerability and penetration testing findings clearly to technical and non-technical stakeholders.
- Prepare regular operational, management and executive reports covering vulnerability exposure, remediation progress, penetration testing outcomes, overdue items and key risk themes.
- Work closely with infrastructure, network, application, cloud, endpoint, risk and governance teams to drive remediation.
- Provide clear remediation guidance to asset owners and technical teams.
- Build strong working relationships across IT and business teams to ensure cyber security risks are understood and addressed.
- Provide technical leadership and guidance to junior analysts where required.
- Requirements
-
- Diploma or Degree in Computer Science, Cybersecurity, Information Technology, or related field.
- Minimum 4 to 6 years of experience in cyber security, with practical experience in vulnerability management, infrastructure security, application security, network security or security assurance.
- Certifications such as CompTIA Security+, CompTIA CySA+, CEH , Microsoft security certifications and IC2 certifications.
- Hands-on experience with vulnerability management platforms such as Qualys VMDR, Tenable, Rapid7 or similar.
- Experience with web application vulnerability scanning tools such as Burp Suite, OWASP ZAP or similar would be advantageous.
- Practical understanding of infrastructure, endpoint, network, cloud, web application and API vulnerabilities.
- Experience with Threat Modelling.
- Strong understanding of operating systems, networking, TCP/IP, firewalls, Active Directory, cloud platforms, web applications and common enterprise technologies.
- Ability to interpret vulnerability scan results, penetration testing reports and remediation evidence.
- Experience coordinating or supporting third-party penetration testing engagements.
- Ability to engage confidently with external penetration testers, technical teams and management.
- Knowledge of patch management, secure configuration, hardening standards, asset ownership and remediation tracking.
- Ability to write clear technical reports, executive summaries and remediation guidance.
- Good understanding of vulnerability prioritisation, exploitability, business impact, compensating controls and remediation options.
- Strong communication skills with the ability to explain technical risk to non-technical stakeholders.
- Competencies
-
- Strong analytical and investigative mindset with excellent attention to detail..
- Ability to assess technical findings and translate them into business-relevant risk.
- Strong problem-solving skills and a practical approach to remediation.
- Ability to prioritise high volumes of vulnerability data based on actual risk.
- Ability to work under pressure and manage multiple remediation streams.
- Good relationship-building skills across technical and non-technical teams.
- Ability to influence remediation without always having direct authority over the responsible teams.
- Strong report-writing and presentation skills.
- Resilience, adaptability and professionalism.
- Commitment to continuous learning and staying current with vulnerabilities, exploit trends, threat activity and security technologies.
- careers@lifehealthcare.co.za
- Closing date
- Thursday, August 20, 2026
Internal applicants - Before making an application, you are requested to discuss your application with your line manager. External candidates will also be considered.
Explore our vacancies and find the right opportunity for you. Download the application form and email to the relevant contact person specified in the job advertisement.
Life Healthcare is an Equal Opportunity Employer.
Thank you for your interest in this opportunity. Kindly note that only shortlisted candidates will be contacted. Applicants who have not been contacted within two weeks of the closing date of this advert, should consider their application as unsuccessful.