
SOC Engineer - L3 Cyber Security Specialist
- Johannesburg, Gauteng
- Permanent
- Full-time
- Lead Level 3 escalation and incident response efforts
- Enrich threat intelligence and validate detection hypotheses
- Author and execute advanced threat hunting strategies
- Serve as CSIRT Secretary for complex investigations
- Conduct deep technical analysis of security events across network, endpoint, and log sources
- Mentor Detection and QA layers, driving R&D enhancements
- Maintain and optimize IRPs and SLAs for MDR services
- Collaborate with cross-functional teams and third-party vendors
- Enhance defence playbooks and partner training modules
- Degree or Diploma in Computer Science
- Proven experience in SOC operations (Defensive & Offensive)
- Strong knowledge of:
- SIEM platforms and detection engineering
- Network architecture and system administration
- Endpoint security (EDR/XDR), IAM, and cloud services (IaaS/SaaS)
- Threat analysis, risk triage, and attacker tradecraft
- Familiarity with ISO27001, NIST, CIS, Mitre ATT&CK (beneficial)
- Scripting skills (Python, Bash, PowerShell - advantageous)
- Industry certifications (CISSP preferred or in progress)
- Valid driver's license or reliable transport (beneficial