Security Defence & Operations Lead
Salix Recruitment · Gauteng
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Join a global organisation with a diverse and complex technology environment, where cybersecurity is critical to protecting the business and enabling its continued growth.
This is a key role within Group Information Security, responsible for ensuring that cyber threats are identified, contained and remediated quickly, while strengthening the organisation's security controls and reducing overall cyber risk.
You'll work closely with the SOC, IT Infrastructure & Operations, Service Desk, DevSecOps, Risk & Compliance teams and external security providers to ensure the organisation remains protected against an evolving threat landscape.
You are a decisive, analytical and hands-on security professional who stays calm under pressure and takes ownership when incidents occur.
You can translate technical security requirements into practical action, collaborate effectively with both technical and non-technical stakeholders, and continuously look for ways to improve security operations and response capabilities.
Why this opportunity?
This is an opportunity to play a critical role in protecting a large enterprise environment, leading security defence and operations while helping shape stronger incident response, vulnerability management and security controls.
If you have the technical depth, operational leadership and cyber resilience mindset to take ownership of an organisation's security defence - we want to hear from you.
Apply now or contact us for a confidential discussion about the opportunity.
Duties
• Lead the remediation and recovery of security incidents identified by the virtual Security Operations Centre (SOC). • Coordinate vulnerability management and remediation across IT and infrastructure teams. • Drive patch management and ensure vulnerabilities are tracked, prioritised and resolved. • Maintain and optimise Endpoint Detection & Response (EDR) and network segmentation controls. • Review security incidents, patching activity and remediation effectiveness. • Optimise SOC alert handoffs, workflows and reporting to improve response times and reduce false positives. • Develop and maintain practical incident response playbooks and operational procedures. • Manage and monitor third-party SOC, vulnerability management and security service providers against agreed SLAs. • Support continuous improvement of the organisation's security controls, processes and operational resilience. • Ensure security operations align with relevant security baselines, frameworks and compliance requirements. Job Experience & Skills Required: Qualifications:
- Matric (Grade 12)
- Bachelor's degree in Information Security, Computer Science, Information Technology or a related field.
- CISSP, GCIH, CEH, CompTIA Security+/CySA+ or relevant Microsoft security certifications are highly relevant.
- Microsoft SC-200, SC-300 and SC-900, together with experience using Microsoft Defender for Endpoint, Microsoft Sentinel and Microsoft 365 security tools.
Experience
• 6 - 10 years of progressive experience in cybersecurity operations, including hands-on incident response and threat remediation. Skills & Competencies:
- Incident Response & Threat Remediation
- SOC Operations & Threat Detection
- Vulnerability Management & Remediation
- Patch Management
- Endpoint Detection & Response (EDR)
- Security Controls & Network Segmentation
- Cybersecurity Frameworks – NIST & MITRE ATT&CK
- Stakeholder & Third-Party Security Provider Management
If you have not had any response in two weeks, please consider the vacancy application unsuccessful. Your profile will be kept on our database for any other suitable roles / positions.