Senior SOC Analyst (SOC L4)
Location: Johannesburg
Employment type: Permanent
Work model: Hybrid, normally three days on-site and two days remote
About Redherd
Redherd is a specialist technical cybersecurity recruitment company supporting organisations across South Africa and international markets. We connect experienced security professionals with technically challenging opportunities across security operations, incident response, offensive security, engineering and security leadership.
About the Client
Our client is an established South African cybersecurity and managed services provider supporting complex enterprise and regulated environments. Its services include security operations, incident response, threat hunting, penetration testing, security engineering and network services.
The company operates within a highly ethical, security-focused environment and places strong emphasis on professional development, technical training and recognised industry certifications. It is ISO 27001 certified and offers employees opportunities to develop their careers across different cybersecurity disciplines.
Role Overview
The Senior SOC Analyst will take technical ownership of complex security incidents, threat-hunting activities and the continued development of security detection and response capabilities.
This is a senior hands-on position for someone capable of managing incidents from initial detection and classification through containment, remediation, recovery and lessons learned.
The role also includes proactive threat hunting, threat modelling, playbook development, detection validation, security reporting and providing technical guidance to other analysts.
Key Responsibilities
- Investigate and respond to complex security alerts and incidents.
- Manage cyber incidents from initial detection through containment, remediation, recovery and post-incident review.
- Classify incidents and determine the appropriate response and escalation path.
- Correlate security events and incidents with threat intelligence.
- Identify likely threat actors, attack methods and affected systems or data.
- Define and execute appropriate containment and remediation strategies.
- Conduct proactive threat hunts to identify malicious or anomalous activity that may not be detected by automated controls.
- Develop threat-hunting hypotheses and document activities, findings and recommendations.
- Create threat models for relevant systems, environments and attack scenarios.
- Analyse incident trends and ensure incidents are accurately documented and reported.
- Maintain an up-to-date understanding of emerging threats, vulnerabilities and attacker techniques.
- Develop and improve incident-response playbooks and operational procedures.
- Plan and participate in tabletop exercises and security simulations.
- Support red-team activities and detection assessments.
- Assess whether simulated attack activity generated the appropriate security alerts.
- Recommend new detection rules and security use cases based on investigations and threat-hunting findings.
- Coordinate investigations with security engineers, detection teams and other stakeholders.
- Develop dashboards covering incident activity and SOC performance.
- Produce monthly key risk indicator reports.
- Provide technical guidance and coaching to other SOC analysts.
Minimum Requirements
- A relevant three-year diploma or degree.
- At least five years of relevant cybersecurity or SOC experience.
- Strong hands-on security incident investigation and response experience.
- Experience managing incidents through containment, remediation and recovery.
- Practical threat-hunting experience.
- Experience correlating security events with threat intelligence.
- Expert understanding of network technologies, protocols, architecture and access controls.
- Knowledge of endpoint, network and cloud security technologies.
- Strong understanding of enterprise IT infrastructure.
- Practical experience using SIEM and SOAR technologies.
- Hands-on experience with Microsoft Sentinel.
- Strong technical analysis, investigation and problem-solving abilities.
- Experience documenting incidents and presenting findings to technical and non-technical stakeholders.
Advantageous Experience
- Threat modelling.
- Detection engineering.
- Security use-case development.
- Incident-response playbook development.
- Tabletop exercises and attack simulations.
- Red-team or purple-team detection validation.
- Microsoft Azure security environments.
- Security dashboard development.
- KRI and operational security reporting.
- Coaching or mentoring SOC analysts.
Personal Attributes
- High levels of honesty, integrity and professional ethics.
- Comfortable handling sensitive information.
- Customer-focused and professional in stakeholder interactions.
- Able to prioritise and manage multiple investigations.
- Self-motivated and capable of working with limited supervision.
- Able to apply technical knowledge to complex problems.
- Willing to guide and coach other technical team members.
- Dependable, professional and punctual.
Work Arrangement
The position is based in Johannesburg and ordinarily requires three days per week on-site. Increased on-site attendance may be required during onboarding, major incidents or when operational requirements demand it.
Candidates must therefore be based in Johannesburg or able to commute reliably to the required work location.
Background Verification
The successful candidate must be willing to complete the background, employment, qualification and related verification checks required for work within sensitive and regulated environments.
Benefits and Development
The employment package includes:
- Medical aid.
- Gap cover.
- Provident fund covering retirement and risk benefits.
- 18 days of annual leave.
- Annual leave increasing to 21 days after three years.
- One birthday leave day during the employee’s birthday month.
- Employer-supported professional development.
- Funding for relevant training, certifications and qualifications.