- Location
- ZA
- Type
- Full-time
- Department
- Security
- Seniority
- Lead
- Experience
- 3+ years
- Closing date
- Today
- Source
- Vincere
Description
This is a leadership role for a hands-on SOC and incident-response professional. The challenge is to move beyond reactive alert handling into a more mature detection and response capability: better correlation rules, stronger playbooks, clearer metrics, more effective automation, stronger incident command and a team that improves with every major event.
Profile for Success
- Demonstrated experience leading SOC or incident-response teams, not only operating as an individual senior analyst.
- Proven history managing complex, multi-stage cyber incidents and coordinating cross-functional response.
- Hands-on experience configuring and operating SIEM, SOAR, EDR or XDR platforms.
- Evidence of developing detection content, tuning correlation rules, building playbooks or using scripting/analytics to improve SOC efficiency.
- Strong knowledge of MITRE ATT&CK, NIST SP 800-61, Cyber Kill Chain and incident-management standards.
- Minimum requirements: NQF Level 6 qualification in IT, Computer Science, Cybersecurity or related field; CySA+, CEH, GCIH or similar; valid driver’s licence; 7–10 years cybersecurity operations experience with at least 3 years leading SOC or IR teams.
- Advantageous: GCIA, GCFA, Microsoft SC-200, CISM, CISSP, CCSP, AWS Security Specialty, ISO 27001 Lead Implementer/Auditor, cloud incident response, DLP, UEBA or red/blue/purple team leadership.