Logo-of-Redherd.io-hiring-for-jobs-in-South-Africa-on-GrabJobs

Senior SOC Analyst (SOC L4)

Job Description - Senior SOC Analyst (SOC L4)

Senior SOC Analyst (SOC L4)


Location: Johannesburg

Employment type: Permanent

Work model: Hybrid, normally three days on-site and two days remote


About Redherd


Redherd is a specialist technical cybersecurity recruitment company supporting organisations across South Africa and international markets. We connect experienced security professionals with technically challenging opportunities across security operations, incident response, offensive security, engineering and security leadership.


About the Client


Our client is an established South African cybersecurity and managed services provider supporting complex enterprise and regulated environments. Its services include security operations, incident response, threat hunting, penetration testing, security engineering and network services.


The company operates within a highly ethical, security-focused environment and places strong emphasis on professional development, technical training and recognised industry certifications. It is ISO 27001 certified and offers employees opportunities to develop their careers across different cybersecurity disciplines.


Role Overview


The Senior SOC Analyst will take technical ownership of complex security incidents, threat-hunting activities and the continued development of security detection and response capabilities.


This is a senior hands-on position for someone capable of managing incidents from initial detection and classification through containment, remediation, recovery and lessons learned.


The role also includes proactive threat hunting, threat modelling, playbook development, detection validation, security reporting and providing technical guidance to other analysts.


Key Responsibilities



  • Investigate and respond to complex security alerts and incidents.

  • Manage cyber incidents from initial detection through containment, remediation, recovery and post-incident review.

  • Classify incidents and determine the appropriate response and escalation path.

  • Correlate security events and incidents with threat intelligence.

  • Identify likely threat actors, attack methods and affected systems or data.

  • Define and execute appropriate containment and remediation strategies.

  • Conduct proactive threat hunts to identify malicious or anomalous activity that may not be detected by automated controls.

  • Develop threat-hunting hypotheses and document activities, findings and recommendations.

  • Create threat models for relevant systems, environments and attack scenarios.

  • Analyse incident trends and ensure incidents are accurately documented and reported.

  • Maintain an up-to-date understanding of emerging threats, vulnerabilities and attacker techniques.

  • Develop and improve incident-response playbooks and operational procedures.

  • Plan and participate in tabletop exercises and security simulations.

  • Support red-team activities and detection assessments.

  • Assess whether simulated attack activity generated the appropriate security alerts.

  • Recommend new detection rules and security use cases based on investigations and threat-hunting findings.

  • Coordinate investigations with security engineers, detection teams and other stakeholders.

  • Develop dashboards covering incident activity and SOC performance.

  • Produce monthly key risk indicator reports.

  • Provide technical guidance and coaching to other SOC analysts.


Minimum Requirements



  • A relevant three-year diploma or degree.

  • At least five years of relevant cybersecurity or SOC experience.

  • Strong hands-on security incident investigation and response experience.

  • Experience managing incidents through containment, remediation and recovery.

  • Practical threat-hunting experience.

  • Experience correlating security events with threat intelligence.

  • Expert understanding of network technologies, protocols, architecture and access controls.

  • Knowledge of endpoint, network and cloud security technologies.

  • Strong understanding of enterprise IT infrastructure.

  • Practical experience using SIEM and SOAR technologies.

  • Hands-on experience with Microsoft Sentinel.

  • Strong technical analysis, investigation and problem-solving abilities.

  • Experience documenting incidents and presenting findings to technical and non-technical stakeholders.


Advantageous Experience



  • Threat modelling.

  • Detection engineering.

  • Security use-case development.

  • Incident-response playbook development.

  • Tabletop exercises and attack simulations.

  • Red-team or purple-team detection validation.

  • Microsoft Azure security environments.

  • Security dashboard development.

  • KRI and operational security reporting.

  • Coaching or mentoring SOC analysts.


Personal Attributes



  • High levels of honesty, integrity and professional ethics.

  • Comfortable handling sensitive information.

  • Customer-focused and professional in stakeholder interactions.

  • Able to prioritise and manage multiple investigations.

  • Self-motivated and capable of working with limited supervision.

  • Able to apply technical knowledge to complex problems.

  • Willing to guide and coach other technical team members.

  • Dependable, professional and punctual.


Work Arrangement


The position is based in Johannesburg and ordinarily requires three days per week on-site. Increased on-site attendance may be required during onboarding, major incidents or when operational requirements demand it.


Candidates must therefore be based in Johannesburg or able to commute reliably to the required work location.


Background Verification


The successful candidate must be willing to complete the background, employment, qualification and related verification checks required for work within sensitive and regulated environments.


Benefits and Development


The employment package includes:



  • Medical aid.

  • Gap cover.

  • Provident fund covering retirement and risk benefits.

  • 18 days of annual leave.

  • Annual leave increasing to 21 days after three years.

  • One birthday leave day during the employee’s birthday month.

  • Employer-supported professional development.

  • Funding for relevant training, certifications and qualifications.

Original job Senior SOC Analyst (SOC L4) posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar Senior SOC Analyst Jobs in South Africa

GrabJobs is the no1 job portal in South Africa, connecting you to thousands of jobs fast! Find the best jobs in South Africa, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.